VulnSea

CWE-829

CVEs classified under CWE-829, newest first.

60 CVEsRSS

CVE-2026-93993High· 8.8PoC
2d ago

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes…

Midnightmistralai · mistral-vibeEPSS 0.60%via NVD
CVE-2026-81305Medium· 6.8
3d ago

CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity

CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary cod…

SunlitCareCam · HMT.CM2507 FirmwareEPSS 0.20%via NVD
CVE-2026-54916High· 8.8
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests dire…

Twilightnetbox-community · devicetype-libraryEPSS 0.41%via NVD
CVE-2026-54918Medium· 5.3
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant th…

Sunlitnetbox-community · devicetype-libraryEPSS 0.30%via NVD
CVE-2026-54752Critical· 9.6
4d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…

Midnightnetbox-community · devicetype-libraryEPSS 0.35%via NVD
CVE-2026-89332Medium· 5.5
1w ago

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation

Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation. Craf…

Sunlitamazon · kiro_ideEPSS 0.17%via NVD
CVE-2026-0303Low· 2.4PoC
1w ago

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

TwilightPalo Alto Networks · Checkov by Prisma CloudEPSS 0.13%via NVD
CVE-2026-59176High· 7.8
1w ago

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

Twilightfunctype-mcp-server · functype-mcp-servervia GHSA
CVE-2026-59172High· 7.8
1w ago

Joker linter executed project-local .jokerd/linter.* files during linting

Joker linter executed project-local .jokerd/linter.* files during linting

Twilightcandid82 · github.com/candid82/jokervia OSV
CVE-2026-79721High· 8.6
1w ago

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

Twilightmlflow · mlflowEPSS 0.29%via NVD
CVE-2026-86504High· 7.8
2w ago

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution

TwilightJetBrains · IntelliJ IDEAEPSS 0.13%via NVD
CVE-2026-86169High· 8.8
2w ago

Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed

Axolotl before 0.19.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the security guard to be bypassed. Attackers can execute arbitrary Python…

Twilightaxolotl-ai-cloud · axolotlEPSS 0.49%via NVD
CVE-2026-82525Medium· 5.5
2w ago

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled …

Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled …

SunlitExterro · FTK ImagerEPSS 0.14%via NVD
GHSA-ghvf-qf6h-g8x5High
1mo ago

NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution

NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution

Twilightnocobase · @nocobase/servervia GHSA
CVE-2026-45272Critical· 9.4
1mo ago

MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook

MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_AUTH key names without validating quo…

MidnightPoxenStudio · talebookEPSS 0.37%via NVD
CVE-2026-76139High· 8.0
1mo ago

A flaw was found in acm-operator-bundle

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its authenticity or integrity. This script gains access to sensitive credentials, such as Gi…

TwilightRed Hat · rhacm2/acm-operator-bundleEPSS 0.45%via NVD
CVE-2026-62680High· 7.1
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. P…

Twilightorval · orvalEPSS 0.31%via NVD
CVE-2026-73073High· 7.3
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgrep command using an insufficiently escaped typeref: or typename: value from a tags file,…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.15%via NVD
CVE-2026-73851None
1mo ago

Kiota is an OpenAPI based HTTP Client code generator

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (…

SunlitEPSS 1.5%via NVD
CVE-2026-49986High
1mo ago

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project director…

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project director…

Twilightneuro-cortex-memory · neuro-cortex-memoryEPSS 0.17%via NVD
CVE-2026-6464High· 8.1
1mo ago

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection

Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server in…

Twilightpostgresql · postgresqlEPSS 0.36%via NVD
CVE-2026-18408High· 8.8
1mo ago

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \re…

Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \re…

Twilightpostgresql · postgresqlEPSS 0.36%via NVD
CVE-2026-71471Critical· 9.0
1mo ago

Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` fie…

MidnightRed Hat · rhacm2/acm-search-v2-rhel9EPSS 1.0%via CVEORG
CVE-2026-15560High· 8.1
1mo ago

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

TwilightRed Hat · eap7-activemq-artemisEPSS 0.46%via NVD
CVE-2026-73076High· 8.4
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimb…

Twilightvim · vimEPSS 0.13%via NVD
CVE-2026-54981High· 7.8
1mo ago

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a security feature locally.

Twilightmicrosoft · pythonEPSS 0.39%via NVD
CVE-2026-62902Medium· 6.5
1mo ago

.NET Information Disclosure Vulnerability

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network.

SunlitMicrosoft · .NET 8.0EPSS 0.78%via CVEORG
CVE-2026-55522High· 7.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…

Twilightpraisonaiagents · praisonaiagentsEPSS 0.15%via NVD
CVE-2026-47781High
1mo ago

PDM is a Python package and dependency manager

PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrust…

Twilightpdm · pdmEPSS 0.13%via NVD
CVE-2026-59864Critical
1mo ago

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

MidnightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.3%via GHSA
CWE-829 vulnerabilities (CVEs) · VulnSea