VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

664 CVEsRSS

CVE-2025-3248Critical· 9.8CISA KEVPoC
1y ago

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint

Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.

▾ Hadallangflow · langflowEPSS 100%via NVD
CVE-2024-54448High· 7.2
1y ago

The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system

The Automation Scripting functionality can be exploited by attackers to run arbitrary system commands on the underlying operating system. An account with administrator privileges or that has been explicitly granted access to use Automati…

▾ Twilightlogicaldoc · logicaldocEPSS 0.56%via NVD
CVE-2024-56326High· 7.8
1y ago

Jinja has a sandbox breakout through indirect reference to format method

Jinja has a sandbox breakout through indirect reference to format method

▾ Twilightjinja2 · jinja2EPSS 0.52%via OSV
CVE-2024-53920High· 7.8PoC
1y ago

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrar…

▾ Midnightgnu · emacsEPSS 0.60%via NVD
CVE-2024-51330Medium· 5.1
1y ago

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing…

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing…

▾ Sunlitultimaker · ultimaker_curaEPSS 0.20%via NVD
CVE-2024-21537High· 8.8
1y ago

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious i…

▾ TwilightEPSS 1.1%via NVD
CVE-2024-50492High· 8.3PoC
1y ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.

▾ Midnightwpplugin · scottcartEPSS 1.4%via NVD
CVE-2024-9050High· 7.8
1y ago

A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configuration from the local unprivileged user

A flaw was found in the libreswan client plugin for NetworkManager (NetkworkManager-libreswan), where it fails to properly sanitize the VPN configuration from the local unprivileged user. In this configuration, composed by a key-value fo…

▾ TwilightEPSS 0.46%via NVD
CVE-2024-5751Critical· 9.8PoC
2y ago

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution

BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and ass…

▾ Abyssallitellm · litellmEPSS 0.88%via NVD
CVE-2024-23692Critical· 9.8CISA KEVPoC
2y ago

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability

Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending…

▾ Hadalrejetto · http_file_serverEPSS 99%via NVD
CVE-2024-31823Critical· 9.8
2y ago

An issue in Ecommerce-CodeIgniter-Bootstrap commit v

An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.

▾ Midnightecommerce-codeigniter-bootstrap_project · ecommerce-codeigniter-bootstrapEPSS 1.7%via NVD
CVE-2024-1015Critical· 9.8
2y ago

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher

Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of th…

▾ Midnightse-elektronic · e-ddc3.3_firmwareEPSS 1.8%via NVD
CVE-2023-52251High· 8.8PoC
2y ago

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages

An issue discovered in provectus kafka-ui 0.4.0 through 0.7.2 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages. No fixed release is available; the project has had no com…

▾ Midnightprovectus · uiEPSS 87%via NVD
CVE-2023-5578Low· 3.5
2y ago

A vulnerability was detected in Portábilis i-Educar up to 2.7.5

A vulnerability was detected in Portábilis i-Educar up to 2.7.5. Affected is an unknown function of the file \intranet\agenda_imprimir.php of the component HTTP GET Request Handler. The manipulation of the argument cod_agenda with the in…

▾ Sunlitportabilis · i-educarEPSS 0.42%via NVD
CVE-2023-4547Low· 3.5PoC
3y ago

A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3

A flaw has been found in SPA-Cart eCommerce CMS 1.9.0.3. The affected element is an unknown function of the file /search. This manipulation of the argument filter[brandid]/filter[price] causes cross site scripting. The attack is possible…

▾ Twilightspa-cart · ecommerce_cmsEPSS 60%via NVD
CVE-2023-3519Critical· 9.8CISA KEV0dayPoC
3y ago

Unauthenticated remote code execution

Unauthenticated remote code execution

▾ Hadalcitrix · netscaler_application_delivery_controllerEPSS 100%via NVD
CVE-2022-37053Critical· 9.8
4y ago

TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.

TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.

▾ Midnighttrendnet · tew733gr_firmwareEPSS 2.3%via NVD
CVE-2022-36262Critical· 9.8
4y ago

An issue was discovered in taocms 3.0.2

An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.

▾ Midnighttaogogo · taocmsEPSS 1.8%via NVD
CVE-2022-34821High· 7.6
4y ago

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE …

A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE …

▾ Twilightsiemens · simatic_cp_1242-7_v2_firmwareEPSS 2.4%via NVD
CVE-2021-40219High· 8.8
4y ago

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution

Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.

▾ Twilightbolt · bolt_cmsEPSS 3.4%via NVD
CVE-2022-25578Critical· 9.8
4y ago

taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.

taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.

▾ Midnighttaogogo · taocmsEPSS 1.8%via NVD
CVE-2022-25018High· 8.8PoC
4y ago

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

▾ Midnightpluxml · pluxmlEPSS 2.7%via NVD
CVE-2021-46114High· 8.8
4y ago

jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail

jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

▾ Twilightjpress · jpressEPSS 1.3%via NVD
CVE-2021-46118High· 7.2
4y ago

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

▾ Twilightjpress · jpressEPSS 2.3%via NVD
CVE-2021-46117High· 7.2
4y ago

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail

jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

▾ Twilightjpress · jpressEPSS 2.8%via NVD
CVE-2021-45806High· 8.8
4y ago

jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.

jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.

▾ Twilightjpress · jpressEPSS 1.4%via NVD
CVE-2021-44529Critical· 9.8CISA KEVPoC
4y ago

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

▾ Hadalivanti · endpoint_manager_cloud_services_applianceEPSS 99%via NVD
CVE-2021-41653Critical· 9.8⚠ ExploitedPoC
4y ago

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.

▾ Abyssaltp-link · tl-wr840n_firmwareEPSS 76%via NVD
CVE-2021-25877High· 7.2
4y ago

AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write

AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.

▾ Twilightyouphptube · youphptubeEPSS 1.6%via NVD
CVE-2021-22205Critical· 10.0CISA KEVPoC
5y ago

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9

An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

▾ Hadalgitlab · gitlabEPSS 100%via NVD
CWE-94 vulnerabilities (CVEs) — page 22 · VulnSea