VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-73166High· 8.6
1w ago

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.70%via NVD
CVE-2026-73453Critical· 10.0
1w ago

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime

An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime …

▾ MidnightArista Networks · EOSEPSS 0.69%via NVD
CVE-2026-73464High· 8.8
1w ago

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbi…

On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted request could allow a malicious authenticated client with gRPC Network Management Interface (gNMI) access to execute arbi…

▾ TwilightArista Networks · EOSEPSS 0.64%via NVD
CVE-2026-76551High· 7.2
1w ago

The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they contro…

The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exported field values, allowing users granted its export permission to have arbitrary functions invoked on values they contro…

▾ TwilightEPSS 0.82%via NVD
CVE-2026-76550High· 7.2
1w ago

The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on …

The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing export files, allowing users granted its export permission to write files with arbitrary names to arbitrary locations on …

▾ TwilightEPSS 0.82%via NVD
CVE-2026-92214Low· 3.5
1w ago

A flaw has been found in a2ui-project a2ui up to 0.10.7

A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-c…

▾ Sunlita2ui-project · a2uiEPSS 0.35%via NVD
CVE-2026-83408High· 8.1
1w ago

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle …

▾ TwilightOracle Corporation · Oracle GraalVM for JDK, Oracle GraalVMEPSS 0.42%via NVD
CVE-2026-91719High· 8.1⚖ disputed
1w ago

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

▾ Twilightgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91854Medium· 4.3PoC
1w ago

A vulnerability was identified in code-projects Record Management System 1.0

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remo…

▾ Twilightcode-projects · Record Management SystemEPSS 0.47%via NVD
CVE-2026-57141Critical· 9.8
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklis…

▾ MidnightMervinPraison · PraisonAIEPSS 0.74%via NVD
CVE-2026-90850Low· 2.4PoC
1w ago

A vulnerability was detected in PHPGurukul Hostel Management System 3.0

A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be lau…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90848Medium· 4.3
1w ago

A weakness has been identified in Governikus AusweisApp up to 2.5.4

A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The…

▾ SunlitGovernikus · AusweisAppEPSS 0.45%via NVD
CVE-2026-90845Low· 3.5PoC
1w ago

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. …

▾ TwilightPHPGurukul · Daily Expense Tracker SystemEPSS 0.35%via NVD
CVE-2026-53710Critical· 10.0
1w ago

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw geta…

▾ MidnightIBM · mcp-context-forgeEPSS 1.1%via NVD
CVE-2026-62379Critical· 9.8
1w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUti…

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 1.1%via NVD
CVE-2026-90835Low· 3.5PoC
1w ago

A flaw has been found in michaelliao itranswarp up to 2.19

A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack…

▾ Twilightmichaelliao · itranswarpEPSS 0.35%via NVD
CVE-2026-16428High· 8.8
1w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitrary code due to improper configuration of the XSLT transformation engine.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.54%via NVD
CVE-2026-57583Low· 3.3
1w ago

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6…

▾ SunlitOpenZeppelin · contracts-wizardEPSS 0.19%via NVD
CVE-2026-90795Medium· 4.3PoC
1w ago

A vulnerability was determined in itsourcecode Loan Management System 1.0

A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible…

▾ Twilightitsourcecode · Loan Management SystemEPSS 0.47%via NVD
CVE-2026-90604Low· 3.5PoC
1w ago

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046

A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is …

▾ TwilightTotolink · A3002MUEPSS 0.35%via NVD
CVE-2026-90615Medium· 4.3PoC
1w ago

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The atta…

▾ TwilightSourceCodester · Class and Exam Timetabling SystemEPSS 0.47%via NVD
CVE-2026-90695Low· 3.5PoC
1w ago

A vulnerability was found in SourceCodester Inventory Management System 1.0

A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation re…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-90694Low· 3.5PoC
1w ago

A vulnerability has been found in SourceCodester Inventory Management System 1.0

A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Custo…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-85192Critical· 9.4
1w ago

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions…

▾ Midnightregularlabs.com · plg_system_conditionalcontentEPSS 0.67%via NVD
CVE-2026-90709Medium· 4.7PoC
1w ago

A security vulnerability has been detected in Yot CMS up to 3.3.1

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code inje…

▾ TwilightYot · CMSEPSS 0.41%via NVD
CVE-2026-90696Low· 3.5PoC
1w ago

A vulnerability was determined in SourceCodester Inventory Management System 1.0

A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /api/products_handler.php of the component Product Management Module. Executing a manipula…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-77147Medium· 6.5
1w ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their Co…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their Co…

▾ SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.45%via NVD
CVE-2026-57131Critical· 9.8PoC
1w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.create_router under /api/v1/runs without authentication or per-job authorization. Network clients can submit attacker…

▾ AbyssalMervinPraison · PraisonAIEPSS 0.97%via NVD
CVE-2026-90497Low· 3.5PoC
2w ago

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11

A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulati…

▾ TwilightFengoffice · Feng OfficeEPSS 0.33%via NVD
CVE-2026-90491Medium· 6.3PoC
2w ago

A weakness has been identified in sanjevirau gsubs up to 1.0.3

A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code inj…

▾ Twilightsanjevirau · gsubsEPSS 0.42%via NVD
CWE-94 vulnerabilities (CVEs) — page 5 · VulnSea