VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-80352Critical· 9.8
2w ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentia…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentia…

▾ Midnightapache · camelEPSS 0.84%via NVD
CVE-2026-81803High· 7.5
2w ago

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

▾ TwilightAteeq Rafeeq · computer-repair-shopEPSS 0.58%via NVD
CVE-2026-52098Critical· 9.8
2w ago

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

▾ Midnightflowiseai · flowiseEPSS 1.1%via NVD
CVE-2026-66632Medium· 6.5
2w ago

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

▾ SunlitElliot Sowers/ RelyWP · simple-cloudflare-turnstileEPSS 0.28%via NVD
CVE-2026-87926Medium· 4.3PoC
2w ago

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the a…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.47%via NVD
CVE-2026-87923Medium· 4.3PoC
2w ago

Rizwan17 inventory-management-system List DBOperation.php cross site scripting

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handle…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.47%via CVEORG
CVE-2026-41870High· 8.8
2w ago

Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in…

▾ TwilightApache Software Foundation · Apache NutchEPSS 0.66%via CVEORG
CVE-2026-85978Critical· 9.8
2w ago

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to …

▾ MidnightPerforce · AkanaEPSS 1.4%via NVD
CVE-2026-87817High· 8.8
2w ago

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD

GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…

▾ Twilightgitpython_project · gitpythonEPSS 0.40%via NVD
CVE-2026-86083High· 8.8
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and inter…

▾ Twilightn8n · n8nEPSS 0.66%via NVD
CVE-2026-86076High· 8.8
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __s…

▾ Twilightn8n · n8nEPSS 0.79%via NVD
CVE-2026-85983High· 7.8
2w ago

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configur…

▾ TwilightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.20%via NVD
CVE-2026-78971Medium· 4.6PoC
2w ago

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

▾ TwilightEPSS 0.24%via NVD
CVE-2026-78834High· 8.8
2w ago

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing cra…

▾ TwilightEPSS 0.67%via NVD
CVE-2026-78625Medium· 6.7
2w ago

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the pri…

▾ Sunlitokta · access_gatewayEPSS 0.23%via NVD
CVE-2026-78545Medium· 6.6
2w ago

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file

The Okta Access Gateway does not sanitize the application label field before including it in the generated nginx configuration file. The unsanitized value is interpolated into an nginx server block directive, resulting in execution of in…

▾ SunlitOkta · Okta Access GatewayEPSS 0.49%via NVD
CVE-2026-78463High· 8.8
2w ago

Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · remote_desktop_clientEPSS 0.86%via NVD
CVE-2026-77908High· 8.8
2w ago

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft Dynamics 365 Customer Engagement V9.1EPSS 0.99%via NVD
CVE-2026-76191High· 8.2
2w ago

Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Animate is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerabilit…

▾ Twilightadobe · animateEPSS 0.33%via NVD
CVE-2026-69806High· 7.0
2w ago

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

Exposure of sensitive information to an unauthorized actor in .NET allows an authorized attacker to elevate privileges locally.

▾ TwilightMicrosoft · .NET 10.0EPSS 1.9%via NVD
CVE-2026-86668Medium· 4.3PoC
2w ago

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15

A security vulnerability has been detected in aircheng-org iWebShop-5 up to 5.15. The impacted element is the function uploadFile of the file controllers/pic.php. Such manipulation of the argument outerSrc/selectPhoto leads to cross site…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.47%via NVD
CVE-2026-54611Medium· 5.5PoC
2w ago

InstantCMS is a free and open source content management system

InstantCMS is a free and open source content management system. Versions prior to 2.18.2 have a Remote Code Execution (RCE) issue that allows remote authenticated attackers to execute any PHP code via the component installer. It is possi…

▾ Twilightinstantsoft · icms2EPSS 0.66%via NVD
CVE-2026-18021Medium· 6.5
2w ago

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1

The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.10.3.1. This is due to the software allowing users to execute…

▾ Sunlitbeaverbuilder · Beaver Builder Page Builder – Drag and Drop Website BuilderEPSS 0.27%via NVD
CVE-2026-79574Critical· 9.8PoC
2w ago

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

▾ AbyssalEPSS 0.69%via NVD
CVE-2026-86732High· 8.8
2w ago

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject…

▾ Twilightcraftcms · cmsEPSS 0.85%via NVD
CVE-2026-86730High· 8.8
2w ago

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab element…

▾ Twilightcraftcms · cmsEPSS 0.71%via NVD
CVE-2026-86644Low· 3.5PoC
2w ago

A vulnerability was determined in star7th showdoc up to 3.9.1

A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API Page Save Endpoint. Executing a manipulation can lead to cross s…

▾ Twilightstar7th · showdocEPSS 0.36%via NVD
CVE-2026-34223High· 8.2
2w ago

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All vers…

A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All vers…

▾ TwilightSiemens · Desigo CC ClickOnce Client V6EPSS 0.19%via NVD
CVE-2026-12757Medium· 6.5
2w ago

The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27

The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.9.27. This is due…

▾ Sunliticegram · Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPressEPSS 0.33%via NVD
CVE-2026-86301Low· 3.5PoC
2w ago

A vulnerability has been found in code-projects Hospital Information System 1.0

A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID lead…

▾ Twilightcode-projects · Hospital Information SystemEPSS 0.35%via NVD
CWE-94 vulnerabilities (CVEs) — page 7 · VulnSea