VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

664 CVEsRSS

CVE-2026-25755High· 8.1PoC
7mo ago

jsPDF is a library to generate PDFs in JavaScript

jsPDF is a library to generate PDFs in JavaScript. Prior to 4.2.0, user control of the argument of the `addJS` method allows an attacker to inject arbitrary PDF objects into the generated document. By crafting a payload that escapes the …

▾ Midnightparall · jspdfEPSS 0.80%via NVD
CVE-2025-14009High· 8.8
7mo ago

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions

A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This a…

▾ Twilightnltk · nltkEPSS 0.95%via NVD
CVE-2025-33240High· 7.8
7mo ago

NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection

NVIDIA Megatron Bridge contains a vulnerability in a data shuffling tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informat…

▾ Twilightnvidia · nemo_megatron_bridgeEPSS 0.21%via NVD
CVE-2025-33239High· 7.8
7mo ago

NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection

NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, informatio…

▾ Twilightnvidia · nemo_megatron_bridgeEPSS 0.21%via NVD
CVE-2025-69872Critical· 9.8
7mo ago

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default

DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

▾ Midnightdiskcache · diskcacheEPSS 0.53%via NVD
CVE-2026-1615Critical· 9.8
7mo ago

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions

Versions of the package jsonpath before 1.3.0 are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. The library relies on the static-eval module to process JSON Path input, which is not …

▾ MidnightEPSS 1.1%via NVD
CVE-2025-61732High· 8.6
7mo ago

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.

▾ Twilightgolang · goEPSS 0.49%via NVD
CVE-2026-25153High· 7.7
8mo ago

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs

Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when Tec…

▾ Twilightlinuxfoundation · backstageEPSS 0.57%via NVD
CVE-2025-24293High· 8.1PoC
8mo ago

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three me…

▾ MidnightEPSS 5.4%via NVD
CVE-2025-57283High· 7.8
8mo ago

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability

The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.

▾ Twilightbrowserstack · browserstack-localEPSS 0.81%via NVD
CVE-2026-24747High· 8.8
8mo ago

PyTorch is a Python package that provides tensor computation

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.l…

▾ Twilightlinuxfoundation · pytorchEPSS 0.81%via NVD
CVE-2026-22807High· 8.8PoC
8mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.14.0, vLLM loads Hugging Face `auto_map` dynamic modules during model resolution without gating on `trust_remote_…

▾ Midnightvllm · vllmEPSS 0.83%via NVD
CVE-2026-22771High· 8.8
8mo ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's …

▾ Twilightenvoyproxy · gatewayEPSS 0.63%via NVD
CVE-2026-22244High· 7.2
8mo ago

OpenMetadata is a unified metadata platform

OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges t…

▾ Twilightopen-metadata · openmetadataEPSS 1.3%via NVD
CVE-2025-69262High· 7.5
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environme…

▾ TwilightRed HatEPSS 1.1%via NVD
CVE-2025-15437Low· 3.5
8mo ago

A vulnerability was found in LigeroSmart up to 6.1.24

A vulnerability was found in LigeroSmart up to 6.1.24. This affects an unknown part of the component Environment Variable Handler. Performing a manipulation of the argument REQUEST_URI results in cross site scripting. The attack may be i…

▾ Sunlitligerosmart · ligerosmartEPSS 0.28%via NVD
CVE-2025-15394Medium· 4.7
9mo ago

A vulnerability was detected in iCMS up to 8.0.0

A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The atta…

▾ Sunlitidreamsoft · icmsEPSS 0.48%via NVD
CVE-2025-15393Medium· 6.3
9mo ago

A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135

A security vulnerability has been detected in Kohana KodiCMS up to 13.82.135. This impacts the function Save of the file cms/modules/kodicms/classes/kodicms/model/file.php of the component Layout API Endpoint. The manipulation of the arg…

▾ Sunlitkodicms-kohana · kodicmsEPSS 0.44%via NVD
CVE-2025-71365High· 8.1
9mo ago

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

▾ Twilightpicklescan · picklescanEPSS 0.43%via OSV
CVE-2025-68278High· 8.8
9mo ago

Tina is a headless content management system

Tina is a headless content management system. In tinacms prior to version 3.1.1, tinacms uses the gray-matter package in an insecure way allowing attackers that can control the content of the processed markdown files, e.g., blog posts, t…

▾ Twilightssw · tinacmsEPSS 0.48%via NVD
CVE-2024-58284High· 7.2
9mo ago

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint

PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to cr…

▾ Twilightpopojicms · popojicmsEPSS 1.1%via NVD
CVE-2025-67509High· 8.2
9mo ago

Neuron is a PHP framework for creating and orchestrating AI Agents

Neuron is a PHP framework for creating and orchestrating AI Agents. Versions 2.8.11 and below use MySQLSelectTool, which is vulnerable to Read-Only Bypass. MySQLSelectTool is intended to be a read-only SQL tool (e.g., for LLM agent quer…

▾ Twilightneuron-ai · neuronEPSS 0.29%via NVD
CVE-2025-66474High· 8.8
9mo ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Versions 16.10.9 and below, 17.0.0-rc-1 through 17.4.2 and 17.5.0-rc-1 through 17.5.0 …

▾ Twilightxwiki · xwiki-renderingEPSS 1.0%via NVD
CVE-2025-65294Critical· 9.8
9mo ago

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

▾ Midnightaqara · hub_m2_firmwareEPSS 0.98%via NVD
CVE-2025-66562Critical· 9.6
9mo ago

TUUI is a desktop MCP client designed as a tool unitary utility integration

TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Execution (RCE) vulnerability exists in Tuui due to an unsafe Cross-Site Scripting (XSS) flaw in the Markdown rendering c…

▾ Midnightaiql · tuuiEPSS 0.52%via NVD
CVE-2025-14007Low· 2.0
9mo ago

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1

A vulnerability was detected in dayrui XunRuiCMS up to 4.7.1. This affects an unknown part of the file /admin79f2ec220c7e.php?c=api&m=demo&name=mobile of the component Domain Name Binding Page. The manipulation results in cross site scri…

▾ Sunlitxunruicms · xunruicmsEPSS 0.27%via NVD
CVE-2025-14006Low· 3.5
9mo ago

A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1

A security vulnerability has been detected in dayrui XunRuiCMS up to 4.7.1. Affected by this issue is some unknown functionality of the file /admind45f74adbd95.php?c=field&m=add&rname=site&rid=1&page=1 of the component Add Data Validatio…

▾ Sunlitxunruicms · xunruicmsEPSS 0.27%via NVD
CVE-2024-32641Critical· 9.8
9mo ago

Masa CMS is an open source Enterprise Content Management platform

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input v…

▾ Midnightmasacms · masacmsEPSS 12%via NVD
CVE-2024-39148High· 8.1
10mo ago

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network

The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated remote attacker to execute arbitrary OS commands as root when the service is reachable over network. Typically, the s…

▾ Twilightkerlink · kerosEPSS 0.52%via NVD
CVE-2025-66299High· 8.8
10mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, Grav CMS is vulnerable to a Server-Side Template Injection (SSTI) that allows any authenticated user with editor permissions to execute arbitrary code on the remote server, bypas…

▾ Twilightgetgrav · gravEPSS 0.60%via NVD
CWE-94 vulnerabilities (CVEs) — page 20 · VulnSea