VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-55585High· 8.8
1mo ago

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

▾ Twilightqwed · qwedEPSS 0.78%via OSV
CVE-2026-55546Critical· 9.8
1mo ago

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

▾ Midnightqwed-mcp · qwed-mcpEPSS 0.73%via OSV
CVE-2026-76836High· 8.8
1mo ago

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them

AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-76841High· 8.8
1mo ago

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it

Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional de…

▾ TwilightEPSS 1.0%via NVD
CVE-2026-40877High· 8.7
1mo ago

Combodo iTop is a web-based IT service management tool

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

▾ TwilightEPSS 0.53%via NVD
CVE-2026-39975None
1mo ago

Combodo iTop is a web-based IT service management tool

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from …

▾ SunlitEPSS 0.59%via NVD
CVE-2026-52490Critical· 9.8⚖ disputed
1mo ago

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

▾ MidnightRed Hat · Red Hat Enterprise Linux 8EPSS 0.51%via NVD
CVE-2026-77992None
1mo ago

Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

▾ SunlitEPSS 0.44%via NVD
CVE-2026-76605None
1mo ago

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.

▾ SunlitEPSS 0.70%via NVD
CVE-2026-76604None
1mo ago

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.3 - The PHP form element is vulnerable to the execution of user provided codes.

▾ SunlitEPSS 0.70%via NVD
CVE-2026-3424Medium· 5.3
1mo ago

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an act…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-77806Critical· 9.8⚠ ExploitedPoC
1mo ago

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resul…

▾ AbyssalEPSS 4.5%via NVD
CVE-2026-62675High· 8.8
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated user's agent bundle and omnigent/server/bundles.py validate_agent_bundle…

▾ Twilightomnigent · omnigentEPSS 0.65%via NVD
CVE-2026-62674Critical· 9.0
1mo ago

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template ag…

▾ Midnightomnigent · omnigentEPSS 0.51%via NVD
CVE-2026-59989Critical
1mo ago

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)

▾ Midnightphalcon · phalcon/cphalconEPSS 0.54%via GHSA
CVE-2026-77413Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An…

▾ Midnightjsonata · jsonataEPSS 0.72%via NVD
CVE-2026-68508High· 7.8
1mo ago

Hydra is a framework for elegantly configuring complex applications

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instanti…

▾ Twilighthydra-core · hydra-coreEPSS 0.46%via NVD
CVE-2026-77414Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, protot…

▾ Midnightjsonata · jsonataEPSS 0.57%via NVD
CVE-2026-77415Critical· 9.8
1mo ago

JSONata is a JSON query and transformation language

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects thro…

▾ Midnightjsonata · jsonataEPSS 0.89%via NVD
CVE-2026-77647Critical· 9.8⚠ ExploitedPoC
1mo ago

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases suc…

▾ AbyssalEPSS 2.5%via NVD
CVE-2026-43961High· 7.8
1mo ago

A flaw was found in Vim's netrw plugin

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be levera…

▾ Twilightvim · vimEPSS 0.22%via NVD
CVE-2026-53451Critical· 9.8
1mo ago

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled sn…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-75149High· 8.8
1mo ago

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value emb…

marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value emb…

▾ TwilightEPSS 0.96%via NVD
CVE-2026-45272Critical· 9.4
1mo ago

MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook

MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_AUTH key names without validating quo…

▾ MidnightPoxenStudio · talebookEPSS 0.50%via NVD
CVE-2026-63187Medium· 6.3
1mo ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's in…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-76224High· 8.8
1mo ago

ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine

ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) contains a remote code execution vulnerability in its Gremlin query engine. Although the engine defaults to the documented-secure java (gremlin-lang) engine, ArcadeGremlin.exe…

▾ TwilightEPSS 0.85%via NVD
CVE-2026-18874Medium· 6.2
1mo ago

A flaw was found in volsync-addon-controller

A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper esc…

▾ SunlitRed Hat · rhacm2/acm-volsync-addon-controller-rhel9EPSS 0.54%via NVD
CVE-2026-62682Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUr…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-62681Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch,…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71864Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schem…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CWE-94 vulnerabilities (CVEs) — page 10 · VulnSea