VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-17603High· 8.8
1mo ago

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property …

▾ Twilightsonatype · nexus_repository_managerEPSS 0.48%via NVD
CVE-2026-46409Critical· 9.6
1mo ago

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:<random port>` (commonly 19141) without ser…

▾ MidnightEPSS 0.28%via NVD
CVE-2026-19207Low· 2.4
1mo ago

A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0

A security vulnerability has been detected in PHPGurukul Company Visitor Management System 1.0. This issue affects some unknown processing of the file /manage-newvisitors.php. The manipulation of the argument fullname leads to cross site…

▾ SunlitEPSS 0.37%via NVD
GHSA-9rj7-rf2p-w77rHigh· 7.5
1mo ago

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-67531None
1mo ago

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a n…

▾ SunlitEPSS 0.73%via NVD
CVE-2026-50159Medium
1mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied …

▾ Sunlitmermaid · mermaidEPSS 0.60%via NVD
CVE-2026-45572Medium· 4.8
1mo ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, an administrator with landing-page editing privileges can store arbitrary HTML and JavaScript in an HTML con…

▾ Sunlitdecidim-core · decidim-coreEPSS 0.25%via NVD
CVE-2026-48054High· 8.8
1mo ago

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `op…

▾ TwilightOpenZeppelin · contracts-wizardEPSS 0.64%via NVD
CVE-2026-55522High· 7.8
1mo ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicit…

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.22%via NVD
CVE-2026-71235High· 8.8
1mo ago

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads danger…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.52%via NVD
CVE-2026-71232High· 7.2
1mo ago

MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, registe…

MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, registe…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-71319Critical· 9.6
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the…

▾ Midnightnuxt · @nuxt/devtoolsEPSS 0.63%via NVD
CVE-2026-71320High· 8.1
1mo ago

Nuxt is an open-source web development framework for Vue.js

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, ca…

▾ Twilightnuxt · nuxtEPSS 0.71%via NVD
CVE-2026-70609Medium· 5.7
1mo ago

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the…

▾ Sunlitelectron · electronEPSS 0.55%via NVD
CVE-2026-69100High· 8.8
1mo ago

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions…

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions…

▾ TwilightEPSS 1.0%via NVD
CVE-2026-70477Critical· 9.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypass…

▾ Midnightflowiseai · flowiseEPSS 0.81%via NVD
CVE-2026-69264Critical· 9.8
1mo ago

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to gl…

▾ Midnightflowiseai · flowiseEPSS 1.1%via NVD
CVE-2026-69255High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').po…

▾ Twilightflowiseai · flowiseEPSS 0.72%via NVD
CVE-2026-69256High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Pytho…

▾ Twilightflowiseai · flowiseEPSS 1.0%via NVD
CVE-2026-69259High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-c…

▾ Twilightflowiseai · flowiseEPSS 0.82%via NVD
CVE-2026-69254High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages…

▾ Twilightflowiseai · flowiseEPSS 0.69%via NVD
CVE-2026-69251High· 8.8PoC
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig…

▾ Midnightflowiseai · flowiseEPSS 2.7%via NVD
CVE-2026-47781High
1mo ago

PDM is a Python package and dependency manager

PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrust…

▾ Twilightpdm · pdmEPSS 0.19%via NVD
GHSA-vj8j-973f-r65jHigh· 8.1
1mo ago

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Duplicate Advisory: Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

▾ Twilightgetgrav · getgrav/gravvia GHSA
CVE-2026-61523High· 7.2
1mo ago

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is…

WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arbitrary PHP code by submitting malicious content through the droplet Code field, which is…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-65804Medium· 6.1
1mo ago

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ SunlitMicrosoft · Microsoft Edge (Chromium-based)EPSS 0.41%via CVEORG
CVE-2026-67340High· 7.2PoC
1mo ago

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor adds java.lang.* to the allowed packages. An authenticated user with UPDATE_SCHEMA permi…

▾ MidnightEPSS 0.92%via NVD
CVE-2026-16144High· 8.1
1mo ago

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.4.20 via the _save_data function. This is due to insufficient validation of the 'th…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-68770Critical· 9.8PoC
1mo ago

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, wher…

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sentence_transformers/util/misc.py, wher…

▾ AbyssalHugging Face · sentence-transformersEPSS 0.91%via NVD
CVE-2026-53510High· 8.1
1mo ago

Savon is a Ruby SOAP client

Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL operation names into Ruby source passed to module_eval, allowing Ruby code execution in the application process. Thi…

▾ Twilightsavon · savonEPSS 0.69%via NVD
CWE-94 vulnerabilities (CVEs) — page 13 · VulnSea