Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,686 CVEs tagged with CWE-941,967 Critical, 2,235 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-31253

Published May 11, 2026

The flash-attention training framework thru commit e724e2588cbe754beb97cf7c011b5e7e34119e62 (2025-13-04) contains an insecure deserialization vulnerability (CWE-502) in its checkp…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-31252

Published May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its model loading component. The framew…

CVSS 5.7 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-31251

Published May 11, 2026

CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnerability (CWE-502) in its gRPC server component. When the ser…

CVSS 7.3 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-42607

Published May 11, 2026

Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with administrative privileges can achieve Remote Code Execution (RCE) by uploading a specially cra…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-8262

Published May 11, 2026

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scri…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8256

Published May 11, 2026

A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. This vulnerability affects unknown code of the file /accounts/mr-save. Such manipulation leads to…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8255

Published May 11, 2026

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. This manipulation causes cross site scr…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8254

Published May 11, 2026

A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8253

Published May 11, 2026

A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. Affected by this vulnerability is an unknown functionality of the file /inventory/purchase_save. The manipula…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2022-50944

Published May 10, 2026

Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image paramet…

CVSS 8.7 · High
evidence mentions
3
Buzz score
21.9

CVE-2021-47939

Published May 10, 2026

Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecti…

CVSS 8.7 · High
evidence mentions
4
Buzz score
29.1

CVE-2021-47938

Published May 10, 2026

ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by inje…

CVSS 8.7 · High
evidence mentions
4
Buzz score
27.6

CVE-2021-47935

Published May 10, 2026

Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects thr…

CVSS 8.7 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-8221

Published May 10, 2026

A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8220

Published May 10, 2026

A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site s…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8219

Published May 10, 2026

A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. The impacted element is an unknown function of the file /inventory/supplier-save. The manipulatio…

CVSS 1.9 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8218

Published May 10, 2026

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipula…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-8211

Published May 9, 2026

A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java…

CVSS 2.0 · Low
evidence mentions
4
Buzz score
26.1

CVE-2026-8195

Published May 9, 2026

A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6

CVE-2026-42301

Published May 9, 2026

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the summary field) into the generate…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-42298

Published May 8, 2026

Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-docker…

CVSS 10.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-41486

Published May 8, 2026

Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.da…

CVSS 8.9 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-29202

Published May 8, 2026

Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system us…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-44336

Published May 8, 2026

PraisonAI is a multi-agent teams system. Prior to version 4.6.34, PraisonAI's MCP (Model Context Protocol) server (praisonai mcp serve) registers four file-handling tools by defau…

CVSS 9.4 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44334

Published May 8, 2026

PraisonAI is a multi-agent teams system. From version 4.5.139 to before version 4.6.32, CVE-2026-40287's fix gated tools.py auto-import behind PRAISONAI_ALLOW_LOCAL_TOOLS=true in…

CVSS 8.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 426-450 of 6,686 CVEsPage 18 of 268