VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

662 CVEsRSS

CVE-2026-66065High
3mo ago

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

▾ Twilightouroboros-ai · ouroboros-aiEPSS 0.24%via OSV
CVE-2026-55773High· 8.8
3mo ago

CedarJava has policy injection vulnerability

CedarJava has policy injection vulnerability

▾ Twilightcedarpolicy · com.cedarpolicy:cedar-javaEPSS 0.52%via GHSA
GHSA-jv2h-4p9v-wf5wHigh
3mo ago

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

▾ Twilightouroboros-ai · ouroboros-aivia GHSA
GHSA-9wxg-vf3r-56hcLow· 3.3
3mo ago

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

OpenZeppelin Contracts Wizard: Line terminators in info.securityContact / info.license can inject lines into generated source

▾ Sunlitopenzeppelin · @openzeppelin/wizardvia GHSA
CVE-2026-54074High· 7.8
3mo ago

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

▾ Twilighttinacms · @tinacms/cliEPSS 0.25%via GHSA
CVE-2026-55388High· 8.1
3mo ago

piscina: Prototype Pollution Gadget → RCE via inherited options.filename

piscina: Prototype Pollution Gadget → RCE via inherited options.filename

▾ Twilightpiscina · piscinaEPSS 0.45%via GHSA
GHSA-fq2m-6wqh-x44gCritical· 9.8
3mo ago

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

PraisonAI: Jobs API exposes agent-execution endpoints with no authentication

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-p69m-4f92-2v84Critical· 9.8
3mo ago

PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool

PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-7qw2-w5rc-37x2High· 7.8
3mo ago

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-r253-r9jw-qg44Critical· 10.0
3mo ago

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

▾ Midnightcrawl4ai · crawl4aivia GHSA
CVE-2026-25470Critical· 10.0
3mo ago

Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.

Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.

▾ MidnightACPT · ACPT (Pro) - Custom Post Types Plugin for WordPressEPSS 0.86%via NVD
CVE-2026-46851High· 8.1
3mo ago

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security)

Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker wit…

▾ Twilightoracle · peoplesoft_enterprise_campus_software_campus_communityEPSS 0.44%via NVD
CVE-2026-48519Critical· 9.6PoC
3mo ago

Langflow: Unauthenticated RCE in Shareable Playgrounds

Langflow: Unauthenticated RCE in Shareable Playgrounds

▾ Abyssallangflow · langflowEPSS 0.78%via GHSA
CVE-2026-53753Critical· 9.8PoC
3mo ago

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

▾ Abyssalcrawl4ai · crawl4aiEPSS 2.9%via GHSA
CVE-2026-56266Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.48%via GHSA
CVE-2026-12208Medium· 5.3
3mo ago

jsonata: Function Binding Prototype Pollution via hasOwnProperty Override

jsonata: Function Binding Prototype Pollution via hasOwnProperty Override

▾ Sunlitjsonata · jsonataEPSS 0.31%via GHSA
CVE-2026-54271High· 8.2
3mo ago

protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names

protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names

▾ Twilightprotobufjs-cli · protobufjs-cliEPSS 0.30%via GHSA
CVE-2026-30120Critical· 9.8
3mo ago

Remotion: remote code execution (RCE) vulnerability

Remotion: remote code execution (RCE) vulnerability

▾ Midnightremotion · remotionEPSS 0.87%via GHSA
CVE-2026-54133Critical· 9.8
3mo ago

jmespath.php: jmespath.php has CompilerRuntime code injection via unescaped function names (CVE-2026-54133)

A flaw was found in jmespath.php, a library for processing JSON documents in PHP applications. This vulnerability allows a remote attacker to execute arbitrary code by crafting a malicious JMESPath expression. The `JmesPath\CompilerRuntime…

▾ MidnightRed Hat · mtdowling/jmespath.phpEPSS 0.56%via CSAF
CVE-2026-52860High· 7.8
3mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as part of populating the completion dicti…

▾ Twilightvim · vimEPSS 0.42%via NVD
CVE-2026-47162High· 8.8
3mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exists in s:NetrwBookHistSave() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/netrw.vim) when serializing br…

▾ Twilightvim · vimEPSS 0.26%via NVD
CVE-2026-44495High· 7.0PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process h…

▾ Midnightaxios · axiosEPSS 1.0%via NVD
CVE-2026-47292High· 7.8
3mo ago

Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability

Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · Visual Studio Code - MSSQL ExtensionEPSS 0.46%via CVEORG
CVE-2026-45583High· 7.5
3mo ago

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · exchange_serverEPSS 0.70%via NVD
CVE-2026-8467CriticalPoC
3mo ago

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

PhoenixStorybook: Unauthenticated remote code execution via HEEx template injection in phoenix_storybook playground

▾ Abyssalphoenix_storybook · phoenix_storybookEPSS 2.1%via GHSA
CVE-2026-42890Medium
3mo ago

actual Allows Electron to Run As Node

actual Allows Electron to Run As Node

▾ Sunlitactual · actualEPSS 0.18%via GHSA
CVE-2026-47722High
3mo ago

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml

▾ Twilightjuev · github.com/juev/nebula-meshEPSS 0.47%via GHSA
CVE-2026-9311Critical· 9.0
3mo ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

▾ Midnightibm · websphere_application_serverEPSS 0.64%via NVD
CVE-2026-48962High· 7.3PoC
4mo ago

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the par…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-41149None
4mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML injection under the default configurat…

▾ SunlitEPSS 0.52%via NVD
CWE-94 vulnerabilities (CVEs) — page 17 · VulnSea