VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

559 CVEsRSS

CVE-2026-93603Critical· 10.0
3d ago

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.…

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.…

Midnightpatriksimek · vm2EPSS 0.43%via NVD
CVE-2026-84738Critical· 9.1
3d ago

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, le…

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, le…

MidnightEPSS 0.56%via NVD
CVE-2026-54612High· 8.8
4d ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file …

Twilightgivanz · VvvebEPSS 0.49%via NVD
CVE-2026-77281Medium· 6.5
4d ago

Caddy is an extensible server platform that uses TLS by default

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…

Sunlitcaddyserver · caddyEPSS 0.36%via NVD
CVE-2026-15815High· 8.8
4d ago

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary fi…

TwilightGrafana · Grafana OSSEPSS 0.87%via NVD
CVE-2026-54237Critical· 9.3
4d ago

Wavelog is web-based amateur radio logging software

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanit…

Midnightwavelog · wavelogEPSS 0.56%via NVD
CVE-2026-45140Critical· 9.8PoC
4d ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

Abyssalchamilo · chamilo-lmsEPSS 0.98%via NVD
CVE-2026-69088High· 8.1
4d ago

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure

Twilightgetgrav · getgrav/gravEPSS 0.23%via GHSA
CVE-2026-92937Critical· 10.0PoC
4d ago

vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process

vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target w…

Abyssalpatriksimek · vm2EPSS 0.79%via NVD
CVE-2026-62104Critical· 10.0
4d ago

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Midnightsuperweby · migratico-liteEPSS 0.59%via NVD
CVE-2026-86320High· 7.8PoC
4d ago

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on…

MidnightRed Hat · flatpak-builderEPSS 0.22%via NVD
CVE-2026-88795Critical· 9.0
4d ago

The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to valida…

The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to valida…

MidnightEPSS 0.48%via NVD
CVE-2026-47252Critical· 9.0PoC
4d ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brav…

Abyssaljulien040 · anyqueryEPSS 0.45%via NVD
CVE-2026-92593High· 8.8
5d ago

Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle…

Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle…

Twilightcraftcms · cmsEPSS 0.41%via NVD
CVE-2026-92784High· 7.5
5d ago

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that …

Twilightrefinedev · @refinedev/inferencerEPSS 0.44%via NVD
CVE-2026-89083Critical· 9.3
5d ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

MidnightHP Inc · HP AC Print & ScanEPSS 0.51%via NVD
CVE-2026-89082Critical· 9.3
5d ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

MidnightHP Inc · HP AC Print & ScanEPSS 0.51%via NVD
CVE-2026-63325High· 7.8
5d ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descript…

TwilightRedocly · redocly-cliEPSS 0.21%via NVD
CVE-2026-92418Low· 3.5PoC
5d ago

A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects unknown code of the file src/main/resources/public/js/customerServe/customer.serve.js of the component Save Endp…

TwilightChangeWeDer · crmEPSS 0.33%via NVD
CVE-2026-91097Critical· 9.8⚖ disputed
5d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.67%via NVD
CVE-2026-73456Critical· 10.0
5d ago

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting a…

Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting a…

MidnightArista Networks · EOSEPSS 0.75%via NVD
CVE-2026-51990Critical· 9.8PoC
5d ago

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

AbyssalEPSS 1.00%via NVD
CVE-2026-92385Low· 2.4
5d ago

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site s…

SunlitSourceCodester · Online Food Ordering SystemEPSS 0.36%via NVD
CVE-2026-90999Critical· 9.8
5d ago

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can su…

MidnightFunctional Software, Inc. · Sentry SeerEPSS 0.51%via NVD
CVE-2026-92381Low· 3.5PoC
5d ago

A weakness has been identified in PbootCMS up to 3.2.22

A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title…

TwilightEPSS 0.33%via NVD
CVE-2026-84858High· 8.8
5d ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supp…

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supp…

TwilightScada-LTS · Scada-LTSEPSS 0.68%via NVD
CVE-2026-92127High· 8.0
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through …

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when a user with Overall/Administer permission copies the item, or updates that configuration through …

Twilightjenkins · script_securityEPSS 0.47%via NVD
CVE-2026-92125High· 8.8
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitra…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attackers with permission to define and run sandboxed scripts, including Pipelines, to run an arbitra…

Twilightjenkins · script_securityEPSS 0.51%via NVD
CVE-2026-73170High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated…

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated…

TwilightAdvantech · EKI-1242IEIMSEPSS 0.51%via NVD
CVE-2026-73166High· 8.6
5d ago

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

TwilightAdvantech · EKI-1242IEIMSEPSS 0.67%via NVD
CWE-94 vulnerabilities (CVEs) — page 2 · VulnSea