VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

662 CVEsRSS

CVE-2026-41148None
4mo ago

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 are vulnerable to CSS injection through improper sanitizatio…

▾ SunlitEPSS 0.60%via NVD
CVE-2026-22314High· 7.9
4mo ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher C…

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other users' systems. This issue affects Meona Client Launcher C…

▾ TwilightMesalvo · Meona Client Launcher ComponentEPSS 0.28%via NVD
CVE-2026-2586Critical· 9.1PoC
4mo ago

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of arbitrary operating system commands wi…

▾ AbyssalEPSS 0.83%via NVD
CVE-2026-8838Critical· 9.8PoC
4mo ago

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary code on the client. To remediate t…

▾ Abyssalredshift-connector · redshift-connectorEPSS 0.80%via NVD
CVE-2026-45829Critical· 10.0PoC
4mo ago

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…

▾ AbyssalEPSS 1.0%via NVD
CVE-2026-44513High· 8.8
4mo ago

Diffusers is the a library for pretrained diffusion models

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omi…

▾ Twilighthuggingface · diffusersEPSS 0.89%via NVD
CVE-2026-44006Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.

▾ Midnightvm2_project · vm2EPSS 0.77%via NVD
CVE-2026-44005Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() an…

▾ Midnightvm2_project · vm2EPSS 0.83%via NVD
CVE-2026-43997Critical· 10.0
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to…

▾ Midnightvm2_project · vm2EPSS 0.77%via NVD
CVE-2026-0236High· 7.8
4mo ago

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to …

A code injection vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly restrict access to its AppleScript interface allowing a locally authenticated non-admin user to leverage this exposed Apple Event handler to …

▾ Twilightpaloaltonetworks · prisma_browserEPSS 0.16%via NVD
CVE-2026-44293High· 8.8
4mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe expression derived from a schema-controlled bytes field de…

▾ Twilightprotobufjs_project · protobufjsEPSS 0.73%via NVD
CVE-2026-8256Low· 2.4
4mo ago

A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0

A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to cross site scripting. The attack can be launched remotely…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-8255Low· 2.4
4mo ago

A weakness has been identified in Devs Palace ERP Online up to 4.0.0

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scripting. The attack can be initiated remotely. The exploit …

▾ SunlitEPSS 0.35%via NVD
CVE-2026-8254Low· 2.4
4mo ago

A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0

A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting. It is possible to launch…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-8253Low· 2.4
4mo ago

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipulation leads to cross site scripting. It is possible to init…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-8262Low· 2.4
4mo ago

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploi…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-8221Low· 2.4
4mo ago

A flaw has been found in Devs Palace ERP Online up to 4.0.0

A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-8220Low· 2.4
4mo ago

A vulnerability was detected in Devs Palace ERP Online up to 4.0.0

A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-8094Critical· 9.8
4mo ago

Other issue in the WebRTC component

Other issue in the WebRTC component. This vulnerability was fixed in Firefox ESR 140.10.2 and Thunderbird 140.10.2.

▾ Midnightmozilla · firefoxEPSS 0.63%via NVD
CVE-2026-24781Critical· 9.8
4mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can escape from the VM2 sandbox and execute …

▾ Midnightvm2_project · vm2EPSS 1.2%via NVD
CVE-2025-14576High· 7.8
5mo ago

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution is typically more restricted than nat…

▾ Twilightqt · qtdeclarativeEPSS 0.22%via NVD
CVE-2026-6357Medium· 5.8
5mo ago

pip: pip: Arbitrary code execution or information disclosure via malicious wheel package installation (CVE-2026-6357)

A flaw was found in pip. Prior to version 26.1, pip's self-update check functionality would execute after installing wheel packages. This process involved importing newly installed Python modules. A malicious actor could craft a specially …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.17%via CSAF
CVE-2026-6951Critical· 9.8PoC
5mo ago

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

Versions of the package simple-git before 3.36.0 are vulnerable to Remote Code Execution (RCE) due to an incomplete fix for [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221) that blocks the -c option but not the e…

▾ Abyssalsimple-git_project · simple-gitEPSS 1.0%via NVD
CVE-2026-39087Medium· 6.4
5mo ago

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.

ntfy before 2.22.0 allows SSRF because of an unanchored regular expression for web push endpoint URLs.

▾ SunlitEPSS 0.48%via NVD
CVE-2026-41134High· 7.8
5mo ago

Kiota is an OpenAPI based HTTP Client code generator

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/q…

▾ Twilightmicrosoft · kiotaEPSS 0.35%via NVD
CVE-2026-41242Critical· 9.8PoC
5mo ago

protobufjs compiles protobuf definitions into JavaScript (JS) functions

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will then execute during object decodi…

▾ Abyssalprotobufjs_project · protobufjsEPSS 0.99%via NVD
CVE-2026-25125Medium· 4.9
5mo ago

October is a Content Management System (CMS) and web platform

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a server-side information disclosure vulnerability in the INI settings parser. Because PHP's parse_ini_string() function supports …

▾ Sunlitoctobercms · octoberEPSS 0.33%via NVD
CVE-2026-5834Low· 2.4
5mo ago

A vulnerability was detected in code-projects Online Shoe Store 1.0

A vulnerability was detected in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /admin/admin_running.php. Performing a manipulation of the argument product_name results in cross site scripting. It is poss…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-1516Medium· 5.7
5mo ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of user…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.0.0 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that in Code Quality reports could have allowed an authenticated user to leak IP addresses of user…

▾ Sunlitgitlab · gitlabEPSS 0.43%via NVD
CVE-2026-25776Critical· 9.8
5mo ago

Movable Type provided by Six Apart Ltd

Movable Type provided by Six Apart Ltd. contains a code injection vulnerability which may allow an attacker to execute arbitrary Perl script.

▾ Midnightsixapart · movable_typeEPSS 0.73%via NVD
CWE-94 vulnerabilities (CVEs) — page 18 · VulnSea