Skip to main content

CWE archive

CWE-913 CVEs

Programmatic archive

92 CVEs tagged with CWE-91331 Critical, 25 High, 28 Medium, 8 Low, 0 Unrated.

CVE-2026-53753

Published Jun 23, 2026

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator that only…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
16.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2026-48775

Published Jun 16, 2026

LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In versions 4.1.0 and prior, the JsonPlusSe…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-47210

Published Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbitrary code execution in the host process when untrusted cod…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-47208

Published Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-47137

Published Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) introduced a check in nodevm.js line 263 that blocks the co…

CVSS 10.0 · Critical
evidence mentions
5
Buzz score
22.9

CVE-2026-47131

Published Jun 12, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__, Buffer, "__proto__"), Buffer.call.call({}.__lookupSetter_…

CVSS 10.0 · Critical
evidence mentions
3
Buzz score
18.9

CVE-2026-48700

Published May 22, 2026

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus metho…

CVSS 9.3 · Critical
evidence mentions
4
Buzz score
22.6

CVE-2026-44336

Published May 8, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by defau…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-7381

Published Apr 29, 2026

Plack::Middleware::XSendfile versions through 1.0053 for Perl can allow client-controlled path rewriting. Plack::Middleware::XSendfile allows the variation setting (sendfile type…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-5251

Published Apr 1, 2026

A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the file /server/routes/user.js of the component User Update Endpoint. Such manipulatio…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-5248

Published Apr 1, 2026

A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the file gougucms-master\app\home\controller\Login.php of the component User Registrati…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-34156

Published Mar 31, 2026

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes…

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-33286

Published Mar 24, 2026

Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability t…

CVSS 9.1 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-69219

Published Mar 9, 2026

A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag A…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2026-25049

Published Feb 4, 2026

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted e…

CVSS 9.4 · Critical
evidence mentions
6
Buzz score
36.0
Vendor/product tagsBeta · best-effort

CVE-2026-1770

Published Feb 2, 2026

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Byp…

CVSS 4.5 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-23830

Published Jan 28, 2026

SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The libr…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-22709

Published Jan 26, 2026

vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.9
Vendor/product tagsBeta · best-effort

CVE-2025-66398

Published Jan 1, 2026

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath…

CVSS 9.6 · Critical
Buzz score
5.5
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-68613

Published Dec 19, 2025

n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulner…

CVSS 9.9 · Critical
evidence mentions
7
Buzz score
58.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-14695

Published Dec 15, 2025

A vulnerability was determined in SamuNatsu HaloBot up to 026b01d4a896d93eaaf9d5163a287dc9f267515b. Affected is the function html_renderer of the file plugins/html_renderer/index.…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2025-13659

Published Dec 9, 2025

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-13426

Published Dec 5, 2025

A vulnerability exists in Google Apigee's JavaCallout policy https://docs.apigee.com/api-platform/reference/policies/java-callout-policy that allows for remote code execution.…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-14085

Published Dec 5, 2025

A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. This impacts an unknown function of the file /app-api/v1/orders/. The manipulation of the argument orderId le…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-14051

Published Dec 4, 2025

A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing ma…

CVSS 2.1 · Low
evidence mentions
7
Buzz score
31.8
Public PoC observed
Vendor/product tagsBeta · best-effort
Showing 1-25 of 92 CVEsPage 1 of 4