VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

GHSA-6p8h-3wgx-97gfHigh· 7.5
2mo ago

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-r9mr-m37c-5fr3High· 8.8
2mo ago

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-55607High
2mo ago

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution

▾ Twilightanthropic-ai · @anthropic-ai/claude-codeEPSS 0.69%via GHSA
GHSA-4v35-78jc-648rMedium
2mo ago

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows

▾ Sunlitn8n · @n8n/computer-usevia GHSA
GHSA-rcv6-pvrj-4xcgHigh
2mo ago

n8n: Authenticated code execution in the n8n Git node

n8n: Authenticated code execution in the n8n Git node

▾ Twilightn8n · n8nvia GHSA
CVE-2026-65590Medium
2mo ago

n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows

n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows

▾ Sunlitn8n · n8nEPSS 0.58%via GHSA
CVE-2026-16445High· 7.5
2mo ago

A flaw was found in dracut

A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP options, such as a malicious root-path, next-server, or bootfile name, to a system using dracut's Ne…

▾ TwilightRed Hat · dracutEPSS 1.1%via NVD
CVE-2026-13760High· 7.3
2mo ago

aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling

aws-cdk-lib: OS Command Injection in NodejsFunction Docker Bundling

▾ Twilightaws-cdk-lib · aws-cdk-libEPSS 1.2%via GHSA
GHSA-v396-v7q4-x2qjHigh
2mo ago

GitPython unsafe clone option gate bypass through joined short options

GitPython unsafe clone option gate bypass through joined short options

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-2f96-g7mh-g2hxHigh· 8.8
2mo ago

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2023-49900Critical· 9.8
2mo ago

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

▾ MidnightEPSS 0.96%via NVD
CVE-2026-54540High· 8.8
2mo ago

Pheditor has an authenticated terminal command whitelist bypass

Pheditor has an authenticated terminal command whitelist bypass

▾ Twilightpheditor · pheditor/pheditorEPSS 0.73%via GHSA
CVE-2026-55578High· 8.8
2mo ago

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection

▾ Twilightpheditor · pheditor/pheditorEPSS 0.67%via GHSA
GHSA-x9f9-r4m8-9xc2High
2mo ago

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

ArcadeDB: Trigger scripts run with java.lang.* allowed, enabling OS command execution (RCE)

▾ Twilightarcadedb · com.arcadedb:arcadedb-enginevia GHSA
CVE-2026-55576None
2mo ago

MaaAssistantArknights is a one-click tool for daily Arknights tasks

MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during t…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-52891Critical· 9.9
2mo ago

Wekan is open source kanban built with Meteor

Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/…

▾ MidnightEPSS 0.78%via NVD
CVE-2026-55410Medium· 6.7
2mo ago

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.1.19, NocoBase @nocobase/plugin-backups restored PostgreSQL backups by interpolating the database.schema value fr…

▾ SunlitEPSS 0.72%via NVD
CVE-2026-50289High
2mo ago

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

▾ Twilightsysteminformation · systeminformationEPSS 3.6%via GHSA
CVE-2026-3014Critical· 9.1
2mo ago

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be ab…

Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be ab…

▾ MidnightEPSS 0.78%via NVD
CVE-2026-61498Critical· 9.8
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters i…

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters i…

▾ Midnightvitec · flamingoEPSS 4.0%via NVD
CVE-2026-60121Critical· 9.8PoC
2mo ago

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument …

▾ Abyssalvitec · flamingoEPSS 3.3%via NVD
CVE-2026-15547Medium· 6.3
2mo ago

A weakness has been identified in Shibby Tomato up to 1.28.0000

A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a manipulation of the argument cifs1/cifs2 can lead to os command injection. The attack c…

▾ SunlitEPSS 1.8%via NVD
CVE-2026-15546Medium· 6.3
2mo ago

A security flaw has been discovered in Shibby Tomato up to 1.28.0000

A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. Performing a manipulation of the argument jffs2_exec results in os command injection. Re…

▾ SunlitEPSS 1.8%via NVD
CVE-2026-15513Medium· 6.3
2mo ago

A security flaw has been discovered in Wavlink WL-NU516U1 260515

A security flaw has been discovered in Wavlink WL-NU516U1 260515. This affects the function wlink_uci_set_value of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument lan_ip results in os command injection. The attack ca…

▾ SunlitEPSS 1.8%via NVD
CVE-2026-15511Critical· 9.8
2mo ago

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of the file /usr/bin/webmgnt of the component FastCGI Backend. This manipulation of the argum…

▾ MidnightEPSS 4.7%via NVD
CVE-2026-15496Medium· 6.3
2mo ago

A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2

A vulnerability was found in SonicCloudOrg sonic-agent up to 2.7.2. The impacted element is the function evalIsFailed of the file sonic-agent/src/main/java/org/cloud/sonic/agent/tests/script/GroovyScriptImpl.java of the component Groovy …

▾ SunlitEPSS 2.0%via NVD
CVE-2026-15495Medium· 6.3
2mo ago

A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2

A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads …

▾ SunlitEPSS 2.7%via NVD
CVE-2026-15487Medium· 6.3
2mo ago

A vulnerability was found in TRENDnet TEW-821DAP 1.11B03

A vulnerability was found in TRENDnet TEW-821DAP 1.11B03. This impacts the function sub_41FBD0 of the file /goform/system_ntp of the component Firmware Update Handler. Performing a manipulation of the argument Hostname results in os comm…

▾ SunlitEPSS 1.8%via NVD
CVE-2026-15486Medium· 6.3
2mo ago

A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03

A vulnerability has been found in TRENDnet TEW-821DAP 1.11B03. This affects the function sub_42026C of the file /goform/tools_ddns of the component Firmware Update Handler. Such manipulation of the argument hostname/username/password lea…

▾ SunlitEPSS 1.8%via NVD
CVE-2026-15485Medium· 6.3
2mo ago

A flaw has been found in TRENDnet TEW-821DAP 1.11B03

A flaw has been found in TRENDnet TEW-821DAP 1.11B03. The impacted element is the function sub_43F2C4 of the file /goform/tools_nslookup of the component DNS Lookup Handler. This manipulation of the argument nslookup_target/dns_server ca…

▾ SunlitEPSS 1.8%via NVD
CWE-78 vulnerabilities (CVEs) — page 16 · VulnSea