VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

662 CVEsRSS

CVE-2026-15505Low· 3.5
2mo ago

A weakness has been identified in vnotex vnote up to 3.20.1

A weakness has been identified in vnotex vnote up to 3.20.1. Impacted is an unknown function of the file /src/data/extra/web/js/markdownit.js of the component YAML Frontmatter. This manipulation of the argument p_metaData causes cross si…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15497High· 7.3
2mo ago

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2

A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JW…

▾ TwilightEPSS 0.67%via NVD
CVE-2026-15493Low· 3.5
2mo ago

A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee

A vulnerability was detected in Akpali9 Attendance-Management-System up to 70b91fe38f4195b701a45f0edcd4f42d5f64aeee. This issue affects some unknown processing of the file absent.php. Performing a manipulation of the argument export_date…

▾ SunlitEPSS 0.33%via NVD
CVE-2026-15492Medium· 4.3
2mo ago

A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6

A security vulnerability has been detected in igweze wizgrade up to b1d55f22b90cd7e7a6e5002f006d7c649e8086d6. This vulnerability affects unknown code of the file dashboard/studentConductManager.php. Such manipulation leads to cross site …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-61447Critical· 10.0PoC
2mo ago

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement

PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without AST validation, import restrictions, or sandbox enforcement. Attackers can influence LL…

▾ AbyssalEPSS 2.5%via NVD
CVE-2026-13353High· 8.8
2mo ago

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter

The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missin…

▾ TwilightEPSS 1.1%via NVD
CVE-2026-61444Critical· 9.1
2mo ago

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that exec…

▾ MidnightEPSS 0.57%via NVD
CVE-2026-15187Medium· 4.3
2mo ago

A security flaw has been discovered in enquirer up to 2.4.1

A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Public Package API. The manipulation of the argument question.name results in improperly controlled modification of objec…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-59216High· 7.7
2mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the…

▾ Twilightopenwebui · open_webuiEPSS 0.45%via NVD
CVE-2026-52778Critical· 9.8
2mo ago

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

▾ Midnightyeswiki · yeswiki/yeswikiEPSS 0.94%via GHSA
GHSA-86vw-x4ww-x467High
2mo ago

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

▾ Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-35211Medium· 6.5
2mo ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260401.0, the OpenCTI GraphQL API exposes a script filter operator in its FilterOperator enum that allows any authenticated u…

▾ Sunlitciteum · openctiEPSS 0.52%via NVD
CVE-2026-59821High· 7.2
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by th…

▾ Twilightlitellm · litellmEPSS 0.90%via NVD
CVE-2026-27823Critical
2mo ago

EGroupware has a Remote Code Execution Vulnerability

EGroupware has a Remote Code Execution Vulnerability

▾ Midnightegroupware · egroupware/egroupwareEPSS 0.97%via GHSA
CVE-2026-55794High
2mo ago

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

▾ Twilightcraftcms · craftcms/cmsEPSS 0.41%via GHSA
CVE-2026-54769Critical· 10.0
2mo ago

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent

▾ Midnightlangroid · langroidEPSS 0.91%via GHSA
CVE-2026-12252High· 7.8
2mo ago

In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution.…

In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR code execution.…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-11778Medium· 5.4
2mo ago

The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.2.14

The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.2.14. This is due to the software allowing users to …

▾ SunlitEPSS 0.42%via NVD
CVE-2026-53810High· 8.8
2mo ago

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

OpenClaw's marketplace runtime extension metadata could point at unscanned payloads

▾ Twilightopenclaw · openclawEPSS 0.62%via GHSA
CVE-2026-14407High· 8.8
2mo ago

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.44%via NVD
CVE-2026-14383High· 8.8
2mo ago

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

▾ Twilightgoogle · chromeEPSS 0.44%via NVD
CVE-2026-13536Medium· 4.3
3mo ago

A vulnerability has been found in GotoHTTP up to 10.2

A vulnerability has been found in GotoHTTP up to 10.2. This issue affects some unknown processing of the file /reg.12x. The manipulation of the argument sn leads to cross site scripting. The attack may be initiated remotely. The exploit …

▾ SunlitEPSS 0.45%via NVD
CVE-2026-13504Low· 3.5
3mo ago

A vulnerability has been found in code-projects Project Management System 1.0

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation leads to cross site scripting. The attack …

▾ SunlitEPSS 0.35%via NVD
CVE-2026-13500High· 7.3
3mo ago

A weakness has been identified in antlr ANTLR4 up to 4.13.2

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-13499Medium· 4.3
3mo ago

A security flaw has been discovered in yashpokharna2555 restaurent-management-system

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing a manipulation of the argument Userna…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-44024Critical· 9.8PoC
3mo ago

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder

▾ Abyssalfluentd · fluentdEPSS 1.1%via GHSA
CVE-2026-12866Critical· 9.8
3mo ago

expr-eval vulnerable to Code Execution

expr-eval vulnerable to Code Execution

▾ Midnightexpr-eval · expr-evalEPSS 0.87%via GHSA
CVE-2026-55441High· 8.6
3mo ago

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

Mise vulnerable to arbitrary command execution via task-include files in an untrusted, config-less repository

▾ Twilightmise · miseEPSS 0.18%via GHSA
CVE-2026-41523High· 7.5
3mo ago

vllm: vLLM: Arbitrary code execution via malicious HuggingFace model (CVE-2026-41523)

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace mo…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.91%via CSAF
GHSA-5w6g-rc45-wvv9Critical· 9.8
3mo ago

Duplicate Advisory: Flowise OverrideConfig security vulnerability

Duplicate Advisory: Flowise OverrideConfig security vulnerability

▾ Midnightflowise · flowisevia GHSA
CWE-94 vulnerabilities (CVEs) — page 16 · VulnSea