VulnSea

CWE-74

CVEs classified under CWE-74, newest first.

438 CVEsRSS

CVE-2026-11311High· 8.1
3mo ago

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric

When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Re…

▾ Twilightf5 · nginx_gateway_fabricEPSS 0.57%via NVD
CVE-2026-50574High· 8.3
3mo ago

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

▾ Twilightyt-dlp · yt-dlpEPSS 0.46%via GHSA
CVE-2026-54231Medium· 5.5
3mo ago

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport

A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump…

▾ Sunlitredhat · automatic_bug_reporting_toolEPSS 0.19%via NVD
CVE-2026-47162High· 8.8
3mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing br…

▾ Twilightvim · vimEPSS 0.26%via NVD
CVE-2025-27511High· 7.2
3mo ago

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection

▾ Twilightgeoserver · org.geoserver.extension:gs-db2EPSS 1.1%via GHSA
CVE-2026-42835High· 8.1
3mo ago

Microsoft Teams for Android Information Disclosure Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft Teams for AndroidEPSS 1.2%via CVEORG
CVE-2026-47634High· 7.3
3mo ago

Microsoft SharePoint Server Spoofing Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Server 2019EPSS 0.53%via CVEORG
CVE-2026-47767Medium
3mo ago

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

▾ Sunlitsymfony · symfony/runtimeEPSS 0.72%via GHSA
CVE-2026-47644Medium· 6.5
3mo ago

Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

▾ SunlitMicrosoft · Copilot Chat (Microsoft Edge)EPSS 0.92%via CVEORG
CVE-2026-10290High· 7.3PoC
3mo ago

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0

A weakness has been identified in code-projects Hotel and Tourism Reservation System 1.0. The affected element is an unknown function of the file tour.php of the component GET Parameter Handler. Executing a manipulation of the argument t…

▾ MidnightEPSS 0.32%via NVD
CVE-2026-7770High· 8.8
3mo ago

IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.

IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.

▾ TwilightEPSS 0.81%via NVD
CVE-2026-20199Medium· 4.7
4mo ago

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due t…

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due t…

▾ Sunlitcisco · thousandeyes_virtual_applianceEPSS 0.44%via NVD
CVE-2026-41109High· 8.8
4mo ago

GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.

▾ TwilightMicrosoft · Visual Studio CodeEPSS 0.86%via CVEORG
CVE-2026-8231Medium· 6.3
4mo ago

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0

A vulnerability has been found in CodeAstro Online Catering Ordering System 1.0. This affects an unknown function of the file /deleteorder.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carr…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-5833Medium· 5.3
5mo ago

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1

A security vulnerability has been detected in awwaiid mcp-server-taskwarrior up to 1.0.1. This impacts the function server.setRequestHandler of the file index.ts. Such manipulation of the argument Identifier leads to command injection. T…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-5739High· 7.3
5mo ago

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2

A security flaw has been discovered in PowerJob 5.1.0/5.1.1/5.1.2. The affected element is the function GroovyEvaluator.evaluate of the file /openApi/addWorkflowNode of the component OpenAPI Endpoint. The manipulation of the argument nod…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-5736High· 7.3
5mo ago

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2

A vulnerability was identified in PowerJob 5.1.0/5.1.1/5.1.2. Impacted is an unknown function of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/InstanceController.java of the component …

▾ TwilightEPSS 0.43%via NVD
CVE-2026-5719Medium· 6.3
5mo ago

A flaw has been found in itsourcecode Construction Management System 1.0

A flaw has been found in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /borrowedtool.php. Executing a manipulation of the argument code can lead to sql injection. It is possible to launch t…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-5681Medium· 6.3
5mo ago

A flaw has been found in itsourcecode sanitize or validate this input 1.0

A flaw has been found in itsourcecode sanitize or validate this input 1.0. This impacts an unknown function of the file /borrowedequip.php of the component Parameter Handler. This manipulation of the argument emp_id causes sql injection.…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-5675Medium· 6.3
5mo ago

A vulnerability was found in itsourcecode Construction Management System 1.0

A vulnerability was found in itsourcecode Construction Management System 1.0. This affects an unknown part of the file /borrowed_tool.php of the component Parameter Handler. The manipulation of the argument emp results in sql injection. …

▾ SunlitEPSS 0.32%via NVD
CVE-2026-5672High· 7.3
5mo ago

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0

A vulnerability has been found in code-projects Simple IT Discussion Forum 1.0. Affected by this issue is some unknown functionality of the file /edit-category.php of the component Parameter Handler. The manipulation of the argument cat_…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-5636Medium· 6.3
5mo ago

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1

A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This affects an unknown part of the file /cancelorder.php of the component Parameter Handler. This manipulation of the argument oid causes sql injection. Th…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-5635Medium· 6.3
5mo ago

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1

A security flaw has been discovered in PHPGurukul Online Shopping Portal Project 2.1. Affected by this issue is some unknown functionality of the file /categorywise-products.php of the component Parameter Handler. The manipulation of the…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-5631High· 7.3
5mo ago

A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3

A vulnerability has been found in assafelovic gpt-researcher up to 3.4.3. This affects the function extract_command_data of the file backend/server/server_utils.py of the component ws Endpoint. Such manipulation of the argument args lead…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-5620Medium· 6.3
5mo ago

A vulnerability has been found in itsourcecode Construction Management System 1.0

A vulnerability has been found in itsourcecode Construction Management System 1.0. Affected is an unknown function of the file /borrowed_equip_report.php of the component Parameter Handler. The manipulation of the argument Home leads to …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-5565High· 7.3
5mo ago

A security vulnerability has been detected in code-projects Simple Laundry System 1.0

A security vulnerability has been detected in code-projects Simple Laundry System 1.0. Affected by this issue is some unknown functionality of the file /delmemberinfo.php of the component Parameter Handler. Such manipulation of the argum…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-5198High· 7.3
6mo ago

A vulnerability was determined in code-projects Student Membership System 1.0

A vulnerability was determined in code-projects Student Membership System 1.0. The impacted element is an unknown function of the file /admin/index.php of the component Admin Login. This manipulation of the argument username/password cau…

▾ TwilightEPSS 0.41%via NVD
CVE-2025-13462Low· 3.3
6mo ago

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK

The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi-block member such as GNUTYPE_LONGNAME or GNUTYPE_LONGLINK. This could result in a crafted tar archive being misinter…

▾ Sunlitpython · pythonEPSS 0.16%via NVD
CVE-2026-27727Critical· 9.8PoC
7mo ago

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked…

▾ Abyssalmchange · mchange_commons_javaEPSS 1.6%via NVD
CVE-2025-15394Medium· 4.7
9mo ago

A vulnerability was detected in iCMS up to 8.0.0

A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The atta…

▾ Sunlitidreamsoft · icmsEPSS 0.48%via NVD
CWE-74 vulnerabilities (CVEs) — page 12 · VulnSea