VulnSea

CWE-915

CVEs classified under CWE-915, newest first.

70 CVEsRSS

CVE-2026-18617High· 8.8
1mo ago

A flaw was found in the Data Science Pipelines Operator (DSPO)

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams field, which allows for the injection of dangerous parameters into the MySQL Data Sourc…

▾ TwilightRed Hat · rhoai/odh-data-science-pipelines-operator-controller-rhel9EPSS 0.73%via NVD
CVE-2026-17598Medium· 4.9
1mo ago

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least…

▾ Sunlitsonatype · nexus_repository_managerEPSS 0.23%via NVD
GHSA-265m-7826-wjqmHigh
1mo ago

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-69258Critical· 9.1
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into intern…

▾ Midnightflowiseai · flowiseEPSS 0.67%via NVD
CVE-2026-67320High· 7.4
1mo ago

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configuration by creating a null-prototype object, but request interceptors run after the merge; a…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.52%via NVD
CVE-2026-67314High· 7.4
1mo ago

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js)

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpers/resolveConfig.js). When an application is already affected by a separate prototype-po…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.41%via NVD
CVE-2026-59889Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: Jackson-databind: Privilege escalation via improper handling of @JsonUnwrapped properties (CVE…

A flaw was found in jackson-databind. The UnwrappedPropertyHandler.processUnwrapped() method, responsible for handling @JsonUnwrapped properties, replays buffered JSON without properly checking the active view. This allows an attacker to w…

▾ SunlitRed Hat · Red Hat JBoss EAP 7.4 ELS for RHEL 8EPSS 0.39%via CSAF
CVE-2026-59888Medium· 6.5
2mo ago

com.fasterxml.jackson.core/jackson-databind: tools.jackson.core/jackson-databind: jackson-databind: @JsonIgnore bypass in Java Records (CVE…

A flaw was found in jackson-databind. When Java Records use a PropertyNamingStrategy, an attacker can bypass the @JsonIgnore annotation during deserialization. This allows a renamed JSON key to be assigned to a Record constructor parameter…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
CVE-2026-55810None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.

▾ SunlitEPSS 0.43%via NVD
CVE-2026-55809None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2.

▾ SunlitEPSS 0.43%via NVD
CVE-2026-55804None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-55803None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-15083None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal ECA: Event - Condition - Action allows Object Injection. This issue affects ECA: Event - Condition - Action versions: from 0.0.0 to 2.…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-13244None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0.

▾ SunlitEPSS 0.43%via NVD
CVE-2026-12535None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.

▾ SunlitEPSS 0.56%via NVD
CVE-2026-9726None
2mo ago

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection

Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0…

▾ SunlitEPSS 0.56%via NVD
GHSA-7jvp-hj45-2f2mHigh
2mo ago

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

Scriban: Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal` Setter Bypass)

▾ TwilightScriban · Scribanvia GHSA
CVE-2026-50281High
2mo ago

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

▾ Twilightcraftcms · craftcms/cmsEPSS 0.43%via GHSA
CVE-2026-48943Medium· 6.5
3mo ago

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`

K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by including the field `K2UserForm=1` in a standard `com_users` `profile.save` POST, can write arbitrary values into the `n…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-54515Medium· 5.3PoC
3mo ago

jackson-databind: jackson-databind: Ignored properties can be unexpectedly modified (CVE-2026-54515)

A flaw was found in jackson-databind. This vulnerability occurs in the data-binding functionality where properties intended to be ignored are incorrectly restored and become writable again. An attacker could potentially exploit this by pro…

▾ TwilightRed Hat · Red Hat JBoss EAP 8.1 for RHEL 8EPSS 0.44%via CSAF
CVE-2026-54516Medium· 5.3
3mo ago

jackson-databind: jackson-databind: Security bypass due to improper handling of renamed properties (CVE-2026-54516)

A flaw was found in jackson-databind. This vulnerability allows a remote attacker to bypass security controls by exploiting an issue in how properties are handled when both @JsonProperty (for renaming) and @JsonIgnore (for ignoring) annota…

▾ SunlitRed Hat · Red Hat Satellite 6EPSS 0.45%via CSAF
CVE-2026-54351High· 8.2
3mo ago

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override

▾ Twilightbudibase · @budibase/serverEPSS 0.46%via GHSA
GHSA-2jx3-65f3-xr8rMedium
3mo ago

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

▾ Sunlitspomky-labs · spomky-labs/otphpvia GHSA
CVE-2026-48150Critical· 9.0
3mo ago

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign

▾ Midnightbudibase · @budibase/serverEPSS 0.47%via GHSA
CVE-2026-44495High· 7.0PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process h…

▾ Midnightaxios · axiosEPSS 1.0%via NVD
CVE-2026-44494High· 8.7PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depen…

▾ Midnightaxios · axiosEPSS 0.93%via NVD
CVE-2026-46625High· 7.5PoC
3mo ago

JavaScript Cookie is a JavaScript API for handling cookies, client-side

JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, t…

▾ Midnightjs-cookie · javascript_cookieEPSS 0.99%via NVD
CVE-2026-47102High· 8.8PoC
4mo ago

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user…

▾ Midnightlitellm · litellmEPSS 0.82%via NVD
CVE-2026-42264High· 7.4PoC
4mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the HTTP adapter are read via d…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-42044Medium· 6.5PoC
5mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the application's depend…

▾ Twilightaxios · axiosEPSS 0.86%via NVD
CWE-915 vulnerabilities (CVEs) — page 2 · VulnSea