VulnSea

CWE-77

CVEs classified under CWE-77, newest first.

271 CVEsRSS

GHSA-jf24-8g2h-2wg7Medium
1mo ago

LibreNMS Vulnerable to Remote Code Execution via AboutController

LibreNMS Vulnerable to Remote Code Execution via AboutController

▾ Sunlitlibrenms · librenms/librenmsvia GHSA
CVE-2026-53533Medium
1mo ago

aiosmtplib is an asynchronous SMTP client for use with asyncio

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is…

▾ Sunlitaiosmtplib · aiosmtplibEPSS 0.53%via NVD
CVE-2026-75004Medium· 4.3
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypass via a crafted rule name in a Sieve script. This issue only affects Roundcube instances using …

▾ Sunlitroundcube · webmailEPSS 0.37%via NVD
CVE-2026-75002High· 7.1
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search and LITERAL+ byte-count desynchronization could lead to information disclosure or privilege escalation via IMAP command injection.

▾ Twilightroundcube · webmailEPSS 2.3%via NVD
CVE-2026-75007Medium· 5.4
1mo ago

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitution, which may lead to information disclosure or privilege escalation.

▾ Sunlitroundcube · webmailEPSS 0.50%via NVD
CVE-2026-50523High· 7.8
1mo ago

Microsoft PowerShell Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

▾ TwilightMicrosoft · PowerShell 7.4EPSS 0.32%via CVEORG
CVE-2026-73078High· 8.6
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating at…

▾ Twilightvim · vimEPSS 0.34%via NVD
CVE-2026-73250None
1mo ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory `$INSTDIR` from PowerEditor/installer/nppSetup.nsi into a Powe…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-47299High· 7.2
1mo ago

Azure Monitor Agent Elevation of Privilege Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.

▾ TwilightMicrosoft · Azure Monitor Agent Linux ExtensionEPSS 1.0%via CVEORG
CVE-2026-65656High· 7.8
1mo ago

Microsoft Office Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauthorized attacker to execute code locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.46%via CVEORG
CVE-2026-68792High· 7.8
1mo ago

Microsoft Office Elevation of Privilege Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.32%via CVEORG
CVE-2026-47285Medium· 6.5
1mo ago

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · visual_studio_codeEPSS 0.92%via NVD
CVE-2026-11814Medium· 6.8
1mo ago

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of …

A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of …

▾ Sunlitnetgear · be9300_firmwareEPSS 0.91%via NVD
CVE-2026-49179High· 8.8PoC
1mo ago

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to execute code over a network.

▾ Midnightmicrosoft · windows_10_1607EPSS 0.86%via NVD
CVE-2026-72904None
1mo ago

Firecrawl turns entire websites into LLM-ready markdown or structured data

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-72913High· 7.8
1mo ago

Kitty is a cross-platform GPU based terminal

Kitty is a cross-platform GPU based terminal. Prior to 0.48.2, the @kitty-echo and @kitty-ssh DCS handlers in kitty/window.py write unauthenticated data to the child shell's stdin, where handle_remote_echo accepts printable shell command…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via NVD
CVE-2026-72869Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, wher…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-72736Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy passes user-controlled values directly into shell commands via unquoted template literal interpolation in the registry credential testing and Docker…

▾ MidnightEPSS 0.63%via NVD
CVE-2026-72735Critical· 9.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, writeTraefikConfigRemote in packages/server/src/utils/traefik/application.ts serializes user-controlled Traefik configuration with yaml.stringify and interp…

▾ MidnightEPSS 0.92%via NVD
CVE-2026-19379High· 7.3
1mo ago

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be ini…

▾ TwilightEPSS 2.7%via NVD
CVE-2026-19348Critical· 9.8
1mo ago

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a

A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipul…

▾ MidnightEPSS 3.6%via NVD
CVE-2026-19346High· 8.8
1mo ago

A vulnerability was determined in Tenda CH22 1.0.0.1

A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This manipulation of the argument Name causes command injection. The attack can be initiated…

▾ TwilightEPSS 2.7%via NVD
CVE-2026-19334Medium· 5.3
1mo ago

A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9

A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of the argument name/modelfile/source/destination causes command injec…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19333Medium· 5.3
1mo ago

A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66

A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by this issue is some unknown functionality of the component generate_types. The manipulat…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19332Medium· 5.3
1mo ago

A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0

A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_openlane/view_waveform. The manipulation of the argument design_name/vcd_file leads to c…

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19329Medium· 5.3
1mo ago

A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390

A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the file src/codex-process-simple.ts of the component ask MCP Tool. The manipulation of the …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19284Medium· 5.3
1mo ago

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/projects.ts of the component Projects Endpoint. The manipulation leads to command injection. …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19282Medium· 5.3
1mo ago

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of the file src/autolearn/GitHooksManager.ts of the component llm_memory_mcp. Executing a …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19281Medium· 5.3
1mo ago

A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0

A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/generateAssets.ts of the component generateAssets Tool. Performing a manipulation of the …

▾ SunlitEPSS 1.1%via NVD
CVE-2026-19279Medium· 5.3
1mo ago

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipulation of the argument pdfPath/sessionId leads to command injection. The attack can only …

▾ SunlitEPSS 1.1%via NVD
CWE-77 vulnerabilities (CVEs) — page 4 · VulnSea