VulnSea

CWE-94

CVEs classified under CWE-94, newest first.

661 CVEsRSS

CVE-2026-49832High· 8.0
3w ago

DSpace open source software is a repository application which provides durable access to digital resources

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible …

▾ Twilightdspace · org.dspace:dspace-apiEPSS 0.87%via NVD
CVE-2026-51974High· 8.8
3w ago

An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via a crafted styles payload in the EXIF metadata o…

An eval() injection vulnerability in the get_list function in modules/meta_parser.py in lllyasviel Fooocus 2.1.854 through 2.5.5 allows remote attackers to execute arbitrary Python code via a crafted styles payload in the EXIF metadata o…

▾ TwilightEPSS 0.77%via NVD
CVE-2026-82393High· 7.5
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

▾ Twilightpnpm · pnpmEPSS 0.63%via NVD
CVE-2026-82554Medium· 4.3
4w ago

A flaw has been found in SourceCodester Queue Management System 1.0

A flaw has been found in SourceCodester Queue Management System 1.0. This affects an unknown part of the file /api/add_customer.php. This manipulation of the argument Name causes cross site scripting. It is possible to initiate the attac…

▾ SunlitEPSS 0.47%via NVD
CVE-2026-82488Low· 3.5
4w ago

A vulnerability was identified in Beetel 450TC3 01.00.00_01

A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-82483Low· 3.5
4w ago

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28

A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scr…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-82482Low· 3.5
4w ago

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28

A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Bio…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-82278High· 8.8PoC
1mo ago

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code

BISHENG before 2.6.0 contains a remote code execution vulnerability in the workflow run_once endpoint that allows authenticated users to execute arbitrary Python code. Attackers can submit crafted Code node definitions to the POST /api/v…

▾ Midnightdataelement · bishengEPSS 0.74%via NVD
CVE-2026-77939Medium· 6.5
1mo ago

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony Expressi…

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony Expressi…

▾ SunlitEPSS 0.61%via NVD
CVE-2026-55634Critical· 9.9
1mo ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObjec…

▾ Midnightpimcore · pimcore/pimcoreEPSS 0.65%via NVD
CVE-2026-55559Critical· 9.8
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templat…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.78%via NVD
CVE-2026-55565Critical· 9.9
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source c…

▾ Midnightyamcs · org.yamcs:yamcs-coreEPSS 0.65%via NVD
CVE-2026-55511Critical· 9.1PoC
1mo ago

Yamcs is a mission control framework

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fil…

▾ Abyssalyamcs · org.yamcs:yamcs-coreEPSS 0.68%via NVD
CVE-2026-54757High· 7.8
1mo ago

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.36%via OSV
CVE-2026-81096Critical· 10.0
1mo ago

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication

ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source fo…

▾ MidnightEPSS 0.85%via NVD
CVE-2026-53579None
1mo ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book note type, whose content is stored with…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-53578None
1mo ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is sto…

▾ SunlitEPSS 0.30%via NVD
CVE-2026-37003Critical· 9.8
1mo ago

Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection

Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execution sinks including exec(), runpy.run…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-6876None
1mo ago

ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform

ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Platform, potentially leading to more acc…

▾ SunlitEPSS 0.62%via NVD
CVE-2026-48996None
1mo ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view interpolates a marker note's title into …

▾ SunlitEPSS 0.30%via NVD
CVE-2026-47727None
1mo ago

Trilium is an open-source hierarchical note-taking application

Trilium is an open-source hierarchical note-taking application. In versions prior to 0.104.0, the default-on "Safe import" filter fails to neutralize the shareTemplate relation because that relation is not marked as dangerous, allowing a…

▾ SunlitEPSS 0.73%via NVD
CVE-2026-18885None
1mo ago

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow pl…

▾ SunlitEPSS 7.2%via NVD
CVE-2026-54721High· 8.8
1mo ago

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS

Silverstripe UserForms provides a visual form builder for the Silverstripe CMS. From 6.0.0 until 6.4.9, 7.0.7, and 7.1.1, the userform email recipient subject field in the CMS accepts a specially crafted payload that can be interpreted a…

▾ Twilightsilverstripe · silverstripe/userformsEPSS 0.73%via NVD
CVE-2026-58474High· 8.8
1mo ago

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename …

whichllm before 0.5.16 contains a code injection vulnerability in the run and snippet commands that allows a remote attacker who controls a HuggingFace repository to achieve arbitrary code execution by crafting a malicious GGUF filename …

▾ TwilightEPSS 0.86%via NVD
CVE-2026-52103Critical· 9.8
1mo ago

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via s…

A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via s…

▾ MidnightEPSS 1.1%via NVD
CVE-2026-60004Critical· 9.8CISA KEV0dayPoC
1mo ago

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

▾ HadalGitea · GiteaEPSS 24%via CVEORG
CVE-2026-57170High· 7.8
1mo ago

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-par…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.24%via NVD
CVE-2026-56703High· 7.2
1mo ago

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions

Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary fil…

▾ TwilightEPSS 1.2%via NVD
CVE-2026-78676Critical· 9.8
1mo ago

gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlin…

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.78%via CSAF
GHSA-vwf3-4xxj-qg6hHigh
1mo ago

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

▾ Twilightmcp-contextforge-gateway · mcp-contextforge-gatewayvia GHSA
CWE-94 vulnerabilities (CVEs) — page 9 · VulnSea