Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,685 CVEs tagged with CWE-941,967 Critical, 2,234 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-44291

Published May 13, 2026

protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup…

CVSS 8.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-43680

Published May 12, 2026

A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a front-end restriction on OS Script schedule types and exec…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42288

Published May 12, 2026

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in Churc…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2025-15463

Published May 12, 2026

The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the soft…

CVSS 6.5 · Medium

CVE-2026-44262

Published May 12, 2026

Scramble generates API documentation for Laravel project. From 0.13.2 to before 0.13.22, when documentation endpoints are publicly accessible and validation rules reference user-c…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-44403

Published May 12, 2026

Wing FTP Server before 8.1.3 contains an authenticated remote code execution vulnerability in the session serialization mechanism that allows authenticated administrators to injec…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-8430

Published May 12, 2026

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbi…

CVSS 9.2 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-8429

Published May 12, 2026

SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server.…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0

CVE-2026-43892

Published May 12, 2026

AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-click RCE via jquery.terminal format code injection. This vuln…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-42898

Published May 12, 2026

Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network.

CVSS 9.9 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-41094

Published May 12, 2026

Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-31236

Published May 12, 2026

The llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line argument. This argument is intended to allow users to provide custom…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.4

CVE-2026-31233

Published May 12, 2026

Guardrails AI thru 0.6.7 contains a code injection vulnerability (CWE-94) in its Hub package installation mechanism. When installing validator packages via guardrails hub install,…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-31231

Published May 12, 2026

Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python code p…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-31230

Published May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). Th…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.4

CVE-2025-65719

Published May 12, 2026

An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user interaction with a crafted HTML page.

CVSS 9.8 · Critical

CVE-2026-31228

Published May 12, 2026

The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a remote code execution vulnerability in its Kubeflow component. The robustness evaluation function for PyTorch model…

CVSS 9.8 · Critical
evidence mentions
5
Buzz score
32.4

CVE-2026-31225

Published May 12, 2026

The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in query.py uses the unsa…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-31220

Published May 12, 2026

PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system a…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-31217

Published May 12, 2026

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code exe…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-40129

Published May 12, 2026

Due to a Code Injection vulnerability in SAP Application Server ABAP for SAP NetWeaver and ABAP Platform, an authenticated attacker could send specially crafted inputs to the appl…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-43874

Published May 11, 2026

WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML eval sink (from CVE-2026-40911)…

CVSS 7.2 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-37630

Published May 11, 2026

An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-42603

Published May 11, 2026

OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-31253

Published May 11, 2026

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkp…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5
Showing 401-425 of 6,685 CVEsPage 17 of 268