VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-46439High· 7.8
1mo ago

compliance-trestle is a tooling platform for managing compliance as code

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.27%via NVD
CVE-2026-73651Medium· 5.7
1mo ago

TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases

TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Prior to versions 0.3.31 and 1.1.0, typeorm migration:generate embeds database schema metad…

▾ SunlitEPSS 0.39%via NVD
CVE-2026-73649Critical· 9.8
1mo ago

Velocity.js is a JavaScript implementation of the Apache Velocity template engine

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.t…

▾ MidnightEPSS 0.73%via NVD
CVE-2026-0298High· 8.1⚖ disputed
1mo ago

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbi…

An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbi…

▾ Twilightpaloaltonetworks · globalprotectEPSS 0.33%via NVD
CVE-2026-67986High· 8.4
1mo ago

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep

amazing-print/amazing_print at commit dc890dfafdf07088ea901df53c19c2710e5c5234 contains a Ruby code injection condition in AwesomeMethodArray#grep. A specially named method containing Ruby interpolation syntax can be interpolated into a …

▾ TwilightEPSS 0.26%via NVD
CVE-2026-72676Medium· 6.5
1mo ago

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242)

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via Code Injection (CAPEC-242). Kibana accepted an identifier for an output configuration wi…

▾ Sunlitelastic · kibanaEPSS 0.55%via NVD
CVE-2026-6471High· 7.2PoC
1mo ago

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in …

▾ Midnightpostgresql · postgresqlEPSS 0.53%via NVD
CVE-2026-73505High· 7.8
1mo ago

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer

Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose functi…

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshEPSS 0.21%via NVD
CVE-2026-73291High· 7.1
1mo ago

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache fi…

▾ TwilightEPSS 0.39%via NVD
CVE-2026-73299Critical· 10.0
1mo ago

Prompty is a markdown file format (.prompty) for LLM prompts

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controll…

▾ Midnightmicrosoft · promptyEPSS 1.8%via NVD
CVE-2026-73268Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE)

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the Cre…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.88%via NVD
CVE-2026-65941High· 8.8
1mo ago

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

▾ TwilightEPSS 0.68%via NVD
CVE-2026-13094High· 7.8
1mo ago

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.

▾ TwilightEPSS 0.20%via NVD
CVE-2026-73032Critical· 9.6
1mo ago

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Att…

▾ MidnightEPSS 0.56%via NVD
CVE-2026-45618Critical· 10.0
1mo ago

LiquidJS is a Shopify/GitHub Pages compatible template engine

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

▾ MidnightEPSS 0.82%via NVD
CVE-2026-73076High· 8.4
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimb…

▾ Twilightvim · vimEPSS 0.13%via NVD
CVE-2026-73248None
1mo ago

calibre is an e-book manager

calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inhe…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-73233None
1mo ago

FreeCAD is a free and open-source multiplatform 3D parametric modeler

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp passes the xDisplacementFormula, yDisplacementFormula…

▾ SunlitEPSS 0.20%via NVD
CVE-2026-73084Medium· 6.1
1mo ago

Activepieces is an open source AI workflow automation platform

Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A craf…

▾ SunlitEPSS 0.36%via NVD
CVE-2026-19546High· 8.8
1mo ago

A flaw was found in DBI

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19…

▾ TwilightRed Hat · perl-DBIEPSS 0.35%via NVD
CVE-2026-70338High· 7.8
1mo ago

Microsoft PowerShell Security Feature Bypass Vulnerability

Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

▾ TwilightMicrosoft · PowerShell 7.4EPSS 0.36%via CVEORG
CVE-2026-65660High· 8.8CISA KEVPoC
1mo ago

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ Abyssalmicrosoft · sharepoint_serverEPSS 2.1%via NVD
CVE-2026-18708Medium· 6.4
1mo ago

An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value pr…

An issue in MongoDB Server's JavaScript scripting engine could allow an authenticated user with write privileges to cause code they control to be executed within the query scope of other users, through a specially crafted stored value pr…

▾ Sunlitmongodb · mongodbEPSS 0.38%via NVD
CVE-2026-70336High· 8.8
1mo ago

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · visual_studio_codeEPSS 0.82%via NVD
CVE-2026-72904None
1mo ago

Firecrawl turns entire websites into LLM-ready markdown or structured data

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's extraction functionality due to unsafe schema dereferencing of user-supplied…

▾ SunlitEPSS 0.46%via NVD
CVE-2026-72718None
1mo ago

goose is general-purpose AI agent that runs on your machine

goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review without stripping attacker-controlled Git configuration. A malicious …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-66738High· 8.8
1mo ago

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-typed user input, which bypasses input sanitization and allows the value to break out of an …

▾ TwilightEPSS 0.58%via NVD
CVE-2026-68166High· 7.3
1mo ago

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs

In the Linux kernel, the following vulnerability has been resolved: userfaultfd: prevent registration of special VMAs Vova Tokarev says: userfaultfd allows registration on shadow stack VMAs. With userfaultfd access, you can regis…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.21%via NVD
CVE-2026-66915None
1mo ago

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

▾ SunlitEPSS 0.82%via NVD
CVE-2026-19378Medium· 4.3
1mo ago

A vulnerability was found in code-projects Task Management System 1.0

A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in …

▾ SunlitEPSS 0.47%via NVD
CWE-94 vulnerabilities (CVEs) — page 12 · VulnSea