Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,682 CVEs tagged with CWE-941,967 Critical, 2,231 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-9302

Published May 23, 2026

A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/index/com…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2026-41149

Published May 22, 2026

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-41148

Published May 22, 2026

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and prior, in addition to 11.0.0-alpha.1 through 11.12.0 ar…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
29.5

CVE-2026-9264

Published May 22, 2026

A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP f…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-42396

Published May 21, 2026

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

CVSS 4.9 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39311

Published May 20, 2026

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Versions 0.102.1 and prior contain a critical security…

CVSS 6.8 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2026-8467

Published May 20, 2026

Code Injection vulnerability in phenixdigital phoenix_storybook allows unauthenticated remote code execution via unsanitized attribute value interpolation in HEEx template generat…

CVSS 9.5 · Critical
evidence mentions
4
Buzz score
27.6

CVE-2026-22314

Published May 20, 2026

Improper Control of Generation of Code ('Code Injection') vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables code execution on other…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-30117

Published May 19, 2026

scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-2586

Published May 19, 2026

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that all…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-51427

Published May 19, 2026

An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet'…

CVSS 7.3 · High
evidence mentions
6
Buzz score
32.5

CVE-2026-46586

Published May 19, 2026

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. T…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-35086

Published May 19, 2026

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommende…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-31379

Published May 19, 2026

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Cont…

CVSS 6.1 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-33233

Published May 19, 2026

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.6.34 through 0.6.51, the backend deseriali…

CVSS 7.6 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-8838

Published May 18, 2026

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor t…

CVSS 9.3 · Critical
evidence mentions
3
Buzz score
23.9

CVE-2026-45829

Published May 18, 2026

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server…

CVSS 10.0 · Critical
evidence mentions
7
Buzz score
40.8

CVE-2026-6902

Published May 18, 2026

A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9

CVE-2018-25320

Published May 17, 2026

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE func…

CVSS 9.3 · Critical

CVE-2021-47952

Published May 16, 2026

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containi…

CVSS 9.3 · Critical
evidence mentions
7
Buzz score
40.8

CVE-2025-67031

Published May 15, 2026

ORSEE (Online Recruitment System for Economic Experiments) 3.1.0 contains an authenticated Remote Code Execution vulnerability in the participant profile field processing subsyste…

CVSS 6.3 · Medium

CVE-2021-47964

Published May 15, 2026

Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages throu…

CVSS 8.7 · High

CVE-2026-44717

Published May 15, 2026

MCP Calculate Server is a mathematical calculation service based on MCP protocol and SymPy library. Prior to 0.1.1, the use of eval() to evaluate mathematical expressions without…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2026-41258

Published May 15, 2026

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Co…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9
Showing 351-375 of 6,682 CVEsPage 15 of 268