VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-86294Medium· 4.3PoC
2w ago

A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0

A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. The manipulation of the arg…

▾ TwilightSourceCodester · Simple Traffic Offense SystemEPSS 0.47%via NVD
CVE-2026-86278Medium· 4.3PoC
2w ago

A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content re…

▾ TwilightSourceCodester · Syllabus-Aligned Learning Management & Examination SystemEPSS 0.47%via NVD
CVE-2026-86264Medium· 4.3PoC
2w ago

A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8

A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endpoint. This manipu…

▾ Twilightsfturing · ssm_proEPSS 0.45%via NVD
CVE-2026-86244Medium· 4.3PoC
2w ago

A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta

A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipulation of the argum…

▾ TwilightEPSS 0.47%via NVD
CVE-2026-86238Medium· 4.3PoC
2w ago

A vulnerability was determined in projectworlds Online Examination System 1.0

A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can…

▾ Twilightprojectworlds · Online Examination SystemEPSS 0.45%via NVD
CVE-2026-86226Low· 3.5PoC
3w ago

A security flaw has been discovered in Projectwolds Online Attendance System 1.0

A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site scripting. The a…

▾ TwilightProjectwolds · Online Attendance SystemEPSS 0.33%via NVD
CVE-2026-86216Medium· 4.3PoC
3w ago

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0

A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross site scripting. The …

▾ Twilightcode-projects · Hotel and Tourism Reservation in PHPEPSS 0.47%via NVD
CVE-2026-86242High· 8.1
3w ago

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false)

Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). T…

▾ Twilightmaximhq · github.com/maximhq/bifrost/transportsEPSS 1.1%via NVD
CVE-2026-86181Low· 3.5PoC
3w ago

A vulnerability was found in code-projects Task Management System 1.0

A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the component User Profile Update. The manipulation of the argument ln…

▾ Twilightcode-projects · Task Management SystemEPSS 0.36%via NVD
CVE-2024-11080Critical· 9.8
3w ago

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file

The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it p…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-83627Critical· 9.8
3w ago

The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.ph…

The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.ph…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-85674High· 7.8
3w ago

aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in

aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit),…

▾ TwilightAider-AI · aiderEPSS 0.25%via NVD
CVE-2026-85623High· 8.8
3w ago

goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection

goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe se…

▾ Twilightaaif-goose · gooseEPSS 0.58%via NVD
CVE-2026-85625High· 8.1PoC
3w ago

sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where

sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function …

▾ Midnightcrcn · sift.jsEPSS 0.73%via NVD
CVE-2026-85610High· 8.8
3w ago

OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix…

OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.71%via NVD
CVE-2026-31020Critical· 9.8
3w ago

In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions

In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without…

▾ MidnightEPSS 1.0%via NVD
CVE-2026-19224High· 7.2
3w ago

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the enti…

The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the enti…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-85694High· 8.1PoC
3w ago

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content

LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code throu…

▾ Midnightlavague-ai · LaVagueEPSS 0.94%via NVD
CVE-2026-71624Critical· 9.8PoC
3w ago

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

▾ AbyssalEPSS 0.93%via NVD
CVE-2026-19298High· 8.8
3w ago

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.

▾ Twilightlangflow · langflowEPSS 0.50%via NVD
CVE-2026-85406Low· 3.5PoC
3w ago

A vulnerability has been found in Eleveo Quality Management 9.7.0

A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possibl…

▾ TwilightEleveo · Quality ManagementEPSS 0.33%via NVD
CVE-2026-85604High· 8.8PoC
3w ago

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter

Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|re…

▾ Midnightgetgrav · gravEPSS 0.86%via NVD
CVE-2026-58400Critical· 9.1
3w ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) a…

▾ Midnightgeonetwork · core-geonetworkEPSS 1.2%via NVD
CVE-2026-85169High· 8.8
3w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain an expression sandbox escape in the $fromAI handler. $fromAI resolved a caller-supplied placeholder name without requiring it to be an own property and admitted reserved keys; agai…

▾ Twilightn8n · n8nEPSS 0.88%via NVD
CVE-2026-78593Medium· 4.3
3w ago

An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting…

An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-controlled expressions into a server-side script template, resulting…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-85207Low· 3.5
3w ago

A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0

A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of the file /index.php?q=orderdetails. Such manipulation of the argument location leads to cross site scripting. The atta…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-85137High· 7.3
3w ago

A security vulnerability has been detected in SeaCMS up to 13.6

A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The atta…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-84645High· 8.8PoC
3w ago

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field …

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field …

▾ Midnightjenkins · jenkinsEPSS 0.79%via NVD
CVE-2026-66786Critical· 9.1
3w ago

A flaw was found in submariner

A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a Ca…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-52833High· 8.0
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runti…

▾ Twilightnuclio · github.com/nuclio/nuclioEPSS 0.55%via NVD
CWE-94 vulnerabilities (CVEs) — page 8 · VulnSea