Skip to main content

CWE archive

CWE-94 CVEs

Programmatic archive

6,686 CVEs tagged with CWE-941,967 Critical, 2,235 High, 1,606 Medium, 877 Low, 1 Unrated.

CVE-2026-41512

Published May 8, 2026

ai-scanner is an AI model safety scanner built on NVIDIA garak. From version 1.0.0 to before version 1.4.1, there is a remote code execution vulnerability via JavaScript injection…

CVSS 9.9 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-41507

Published May 8, 2026

math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body with…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-25077

Published May 8, 2026

Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file n…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-67887

Published May 8, 2026

1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file…

CVSS 9.8 · Critical

CVE-2024-46507

Published May 8, 2026

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the applicatio…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2026-8136

Published May 8, 2026

A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /index.php?page=users. Executing a manipulation of the ar…

CVSS 1.9 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-43944

Published May 8, 2026

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code exec…

CVSS 9.4 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-42203

Published May 8, 2026

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before version 1.83.7, the POST /prompts/test endpoint accepted user-s…

CVSS 8.6 · High
evidence mentions
5
Buzz score
30.9
Vendor/product tagsBeta · best-effort

CVE-2026-41900

Published May 8, 2026

OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code execution (RCE) vulnerability was identified in the OpenLearnX…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-41645

Published May 8, 2026

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it p…

CVSS 5.3 · Medium
evidence mentions
6
Buzz score
24.5
Vendor/product tagsBeta · best-effort

CVE-2026-8117

Published May 8, 2026

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. This issue affects some unknown processing of the file /admin/index.php. Such manipulati…

CVSS 2.1 · Low
evidence mentions
5
Buzz score
29.4

CVE-2026-41692

Published May 7, 2026

i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation t…

CVSS 4.7 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-44244

Published May 7, 2026

GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validatin…

CVSS 7.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-42214

Published May 7, 2026

Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension direct…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-36458

Published May 7, 2026

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2025-63706

Published May 7, 2026

NPM package next-npm-version1.0.1 is vulnerable to Command injection.

CVSS 9.8 · Critical

CVE-2026-41139

Published May 7, 2026

Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary JavaScript can be executed via the expression parser of ma…

CVSS 8.8 · High
evidence mentions
8
Buzz score
35.0
Vendor/product tagsBeta · best-effort

CVE-2026-7841

Published May 6, 2026

A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user with System Setting permissions can execute arbitrary comm…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-38431

Published May 5, 2026

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-54345

Published May 5, 2026

Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by e…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2026-42238

Published May 4, 2026

Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, nginx-ui exposes a backup restore endpoint (POST /api/restore) that is completely unauthenticate…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort
Showing 451-475 of 6,686 CVEsPage 19 of 268