VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-90489Low· 3.5PoC
2w ago

A vulnerability was identified in Xuxueli xxl-job up to 3.5.0

A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed r…

▾ TwilightXuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-90488Medium· 6.3PoC
2w ago

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2

A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.…

▾ TwilightXuxueli · xxl-jobEPSS 0.39%via NVD
CVE-2026-90502Low· 3.5PoC
2w ago

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0

A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site sc…

▾ Twilightstilleshan · ServerStatusEPSS 0.33%via NVD
CVE-2026-90581Medium· 6.3PoC
2w ago

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote explo…

▾ Twilightcym1102 · nginxWebUIEPSS 0.41%via NVD
CVE-2026-90571Medium· 4.3
2w ago

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performi…

▾ SunlitExrick · xmallEPSS 0.47%via NVD
CVE-2026-90570Low· 2.4
2w ago

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Su…

▾ Sunlitlinlinjava · litemallEPSS 0.37%via NVD
CVE-2026-90569Low· 2.4
2w ago

A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0

A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. Th…

▾ Sunlitlinlinjava · litemallEPSS 0.37%via NVD
CVE-2026-90568Low· 3.5
2w ago

A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2

A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of …

▾ Sunlitmoxi624 · Mogu Blog v2EPSS 0.33%via NVD
CVE-2026-90567Low· 3.5
2w ago

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of th…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.35%via NVD
CVE-2026-90564Low· 3.5
2w ago

A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1

A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.35%via NVD
CVE-2026-90563Low· 3.5
2w ago

A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0

A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out rem…

▾ Sunlitmaliangnansheng · bbs-springbootEPSS 0.36%via NVD
CVE-2026-90529Low· 3.5
2w ago

A vulnerability has been found in DataEase up to 2.10.25/2.10.26

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-90528Low· 3.5
2w ago

A flaw has been found in TDuckApp tduck-platform up to 5.3

A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argu…

▾ SunlitTDuckApp · tduck-platformEPSS 0.35%via NVD
CVE-2026-90527Medium· 4.3
2w ago

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.47%via NVD
CVE-2026-90602Low· 3.5
2w ago

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cro…

▾ SunlitAnil-matcha · Open-Generative-AIEPSS 0.36%via NVD
CVE-2026-90583Medium· 4.3PoC
2w ago

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulatio…

▾ Twilightkagisearch · smallwebEPSS 0.49%via NVD
CVE-2026-78159Critical· 9.8PoC
2w ago

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a…

▾ Abyssalstellarwp · The Events CalendarEPSS 1.4%via NVD
CVE-2026-90553High· 7.8
2w ago

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbi…

▾ Twilightvllm · vllmEPSS 0.31%via NVD
CVE-2026-79362High· 8.8
2w ago

Certain Woltlab products are affected by RCE via Cache Poisoning

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-14560Critical· 10.0
2w ago

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitra…

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitra…

▾ MidnightEPSS 0.44%via NVD
CVE-2026-86793Critical· 9.8PoC
2w ago

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

▾ AbyssalSGLang · SGLangEPSS 0.77%via NVD
CVE-2026-81940High· 8.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

▾ Twilightlangflow · langflowEPSS 0.81%via NVD
CVE-2026-81204Critical· 9.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

▾ Midnightlangflow · langflowEPSS 0.86%via NVD
CVE-2026-79742High· 8.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

▾ Twilightlangflow · langflowEPSS 0.81%via NVD
CVE-2026-78571High· 8.8
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.

▾ Twilightlangflow · langflowEPSS 0.81%via NVD
CVE-2026-9176Medium· 6.7
2w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected …

▾ Sunlitibm · websphere_application_serverEPSS 0.16%via NVD
CVE-2026-88033High· 8.3
2w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · java_driverEPSS 0.46%via NVD
CVE-2026-88062Critical· 9.5PoC
2w ago

OmniRoute ACP Custom-Agent Remote Code Execution (RCE)

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand v…

▾ Abyssaldiegosouzapw · OmniRouteEPSS 1.4%via CVEORG
CVE-2026-88024High· 8.3
2w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ TwilightMongoDB · Rust DriverEPSS 0.46%via NVD
CVE-2026-19584High· 7.7
2w ago

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…

▾ TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CWE-94 vulnerabilities (CVEs) — page 6 · VulnSea