VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-61536High· 7.5
1mo ago

Banks generates meaningful LLM prompts using a simple template language

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through impo…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-11393High· 9.0
2mo ago

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping

▾ Twilightaws · @aws/agentcoreEPSS 0.34%via GHSA
CVE-2026-54662High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54661High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54664High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped enum string values

swagger-typescript-api vulnerable to code injection via unescaped enum string values

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54666High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-66748High· 8.8PoC
2mo ago

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-55415High· 7.5
2mo ago

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.49%via OSV
CVE-2026-54656High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.25%via GHSA
CVE-2026-54653High· 8.8
2mo ago

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.71%via OSV
CVE-2026-54654High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVE-2026-54655High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via GHSA
CVE-2026-54621High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVE-2026-55771High· 8.8
2mo ago

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.57%via GHSA
CVE-2026-63720High· 7.5PoC
2mo ago

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded n…

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded n…

▾ MidnightEPSS 0.74%via NVD
CVE-2025-71408High· 7.0
2mo ago

nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module (CVE-2025-71408)

A flaw was found in NLTK (Natural Language Toolkit). This eval injection vulnerability in the `nltk.collocations` module allows a local attacker to execute arbitrary Python code. By manipulating command-line arguments when `collocations.py…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.27%via CSAF
GHSA-6xj8-qv9j-xcjqHigh· 7.8
2mo ago

Oh My Posh: Arbitrary command execution via template injection in the path segment

Oh My Posh: Arbitrary command execution via template injection in the path segment

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshvia GHSA
CVE-2026-59860High
2mo ago

Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection

Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-59861High· 7.5
2mo ago

Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator

Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator

▾ TwilightMicrosoft · Microsoft.OpenAPI.KiotaEPSS 2.0%via GHSA
CVE-2026-59862High· 7.5
2mo ago

Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator

Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator

▾ TwilightMicrosoft · Microsoft.OpenAPI.KiotaEPSS 1.4%via GHSA
CVE-2026-59859High
2mo ago

Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator

Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-59865Critical
2mo ago

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

▾ MidnightMicrosoft · Microsoft.OpenApi.KiotaEPSS 4.4%via GHSA
CVE-2026-59866High
2mo ago

Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
GHSA-7gfh-x38p-prh3Critical· 9.8
2mo ago

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

▾ Midnightvelocityjs · velocityjsvia GHSA
GHSA-w28w-gp39-m4p6Critical· 10.0
2mo ago

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

▾ Midnightprompty · @prompty/corevia GHSA
CVE-2025-13146Medium· 6.5
2mo ago

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does no…

▾ Sunlitsevenspark · DTX – Dynamic Text Extension for Contact Form 7EPSS 0.47%via NVD
GHSA-gv7g-jm28-cr3mHigh
2mo ago

n8n: Expression sandbox escape via arrow-function bodies enabling command execution

n8n: Expression sandbox escape via arrow-function bodies enabling command execution

▾ Twilightn8n · n8nvia GHSA
GHSA-2rp8-mm9q-fp49Medium· 5.7
2mo ago

TypeORM: migration:generate template-literal code injection

TypeORM: migration:generate template-literal code injection

▾ Sunlittypeorm · typeormvia GHSA
CVE-2026-16229Medium· 4.3
2mo ago

A flaw has been found in itsourcecode Courier Management System up to 1.0

A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php. Executing a manipulation of the argument page can lead to cross site scripting.…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-16220Medium· 4.3
2mo ago

A vulnerability has been found in code-projects Online Examination System 1.0

A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability affects unknown code of the file /account.php?q=quiz. Such manipulation of the argument eid/n/t leads to cross site scripting. The attack c…

▾ SunlitEPSS 0.47%via NVD
CWE-94 vulnerabilities (CVEs) — page 14 · VulnSea