CVE-2026-90556: Schwachstellen-Eintrag (NVD)
Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious savegame files that write past the entries array into adjacent heap-allocated struct fields, potentially corrupting memory when a user or server operator loads the file.
- 🔗 github.com/freeciv/freeciv
- 🔗 github.com/freeciv/freeciv/blob/R3_2_5/server/savega…
- 🔗 github.com/freeciv/freeciv/blob/R3_2_5/server/savega…
- 🔗 github.com/freeciv/freeciv/commit/75ecde3e86ddf2fe77…
- 🔗 github.com/freeciv/freeciv/releases/tag/R3_2_6
- 🔗 redmine.freeciv.org/issues/2161
- 🔗 www.vulncheck.com/advisories/freeciv-before-3.2.6-heap-buff…
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-15 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
WSO2 API Manager: JWT-Bypass über falsche Admin-Token (CVE-2026-5430)
LONDON (IT BOLTWISE) – Eine Sicherheitslücke in WSO2 API Manager und verwandten Komponenten wird laut aktuellen Beobachtungen bereits aktiv in der Praxis ausgenutzt. Die Ursache liegt in einer unzureichenden Prüfung kryptografischer Signatu
CVE-2022-44096 | Sanitization Management System 1.0 Admin Panel hard-coded credentials (EUVD-2022-47047)
A vulnerability, which was classified as critical, was found in Sanitization Management System 1.0. This vulnerability affects unknown code of the component Admin Panel. Such manipulation leads to hard-coded credentials. This vulnerability
CVE-2022-44081 | Lodepng 20220717 pngdetail memory corruption (Issue 177 / EUVD-2022-47032)
A vulnerability classified as critical has been found in Lodepng 20220717. This affects the function pngdetail. The manipulation leads to memory corruption. This vulnerability is documented as CVE-2022-44081. The attack requires being on th
CVE-2022-44079 | zrax pycdc 44a730f3a889503014fec94ae6e62d8401cb75e5 StackDepotNode stack-based overflow (Issue 291 / EUVD-2022-47030)
A vulnerability identified as critical has been detected in zrax pycdc 44a730f3a889503014fec94ae6e62d8401cb75e5. This issue affects the function __sanitizer::StackDepotBase&lt;__sanitizer::StackDepotNode. This manipulation causes stack-
CVE-2022-44039 | Franklin Fueling Colibri 1.9.22.8925 fopen access control (EUVD-2022-47001)
A vulnerability classified as critical was found in Franklin Fueling Colibri 1.9.22.8925. Affected by this vulnerability is the function fopen. The manipulation results in improper access controls. This vulnerability is known as CVE-2022-44
CVE-2022-44038 | Russound XSourcePlayer 777D 06.08.03 scriptRunner.cgi privilege escalation (EUVD-2022-47000)
A vulnerability classified as critical has been found in Russound XSourcePlayer 777D 06.08.03. This issue affects some unknown processing of the file scriptRunner.cgi. The manipulation leads to privilege escalation. This vulnerability is li
CVE-2022-44037 | APsystems Energy Communication Unit up to W2.1NA access control (EUVD-2022-46999)
A vulnerability labeled as critical has been found in APsystems Energy Communication Unit V4.1NA/V3.11.4/W2.1NA/V4.1SAA/C1.2.2. Affected by this issue is some unknown functionality. Such manipulation leads to improper access controls. This
CVE-2025-65022 | Portabilis i-Educar up to 2.10.0 agenda.php cod_agenda sql injection (GHSA-4hrj-5gwx-r4w4)
A vulnerability classified as critical was found in Portabilis i-Educar up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file ieducar/intranet/agenda.php. Such manipulation of the argument cod_agenda leads to
CVE-2024-45058 | portabilis i-educar up to 2.8 Setting educar_usuario_cad.php authorization
A vulnerability classified as problematic was found in portabilis i-educar up to 2.8. This issue affects some unknown processing of the file ieducar/intranet/educar_usuario_cad.php of the component Setting Handler. Such manipulation leads t
Cisco-FMC-Sicherheitslücke ermöglicht Root-Zugriff ohne Anmeldung
Eine aktiv ausgenutzte Schwachstelle in Cisco Secure Firewall Management Center ermöglicht Angreifern die Umgehung der Anmeldung und Root-Zugriff. Cisco hat Hot Fixes veröffentlicht, die eine bestehende Kompromittierung jedoch nicht beseit
Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the browser, including three bugs rated Critical. The Stable channel is moving to 153.0.8010.47/.48 for Windows and macOS and 153.0.8010.47 for
Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869
Finding the Workflow Orchestrators: ZoomEye Exposure Data for Kestra After CVE-2026-49869 CVE-2026-49869 is an authentication bypass in Kestra OSS that escalates to unauthenticated remote code execution, rated Critical at CVSS 3.1 10.0 and
CVE-2026-28572 | Google Android 16-qpr2 Tapjacking InstallLaunch.kt OnCreate privileges management
A vulnerability was found in Google Android 16-qpr2. It has been rated as problematic. This impacts the function OnCreate of the file InstallLaunch.kt of the component Tapjacking. The manipulation leads to improper privilege management. Thi
CVE-2026-0084 | Google Android 16/16-qpr2 HostEmulationManager HostEmulationManager.java privileges management
A vulnerability was found in Google Android 16/16-qpr2. It has been declared as very critical. This affects an unknown function of the file HostEmulationManager.java of the component HostEmulationManager. Executing a manipulation can lead t
CVE-2026-0065 | Google Android 14/15/16/16-qpr2 Background Launch Process Controller BackgroundLaunchProcessController.java areBackgroundActivityStartsAllowed privileges management
A vulnerability has been found in Google Android 14/15/16/16-qpr2 and classified as very critical. Impacted is the function areBackgroundActivityStartsAllowed of the file BackgroundLaunchProcessController.java of the component Background La
CVE-2026-0054 | Google Android 14/15/16/16-qpr2 WalletContextualLocationsService.kt isCallerAllowed permission
A vulnerability, which was classified as problematic, was found in Google Android 14/15/16/16-qpr2. This issue affects the function isCallerAllowed of the file WalletContextualLocationsService.kt. The manipulation results in permission issu
CVE-2026-75015 | Apache Syncope missing encryption (CNNVD-2026-93574773)
A vulnerability was found in Apache Syncope. It has been declared as problematic. The affected element is an unknown function. Executing a manipulation can lead to missing encryption of sensitive data. This vulnerability is handled as CVE-2
CVE-2022-44031 | Redmine up to 4.2.8/5.0.3 Textile Formatter cross site scripting (EUVD-2022-46993 / Nessus ID 257919)
A vulnerability identified as problematic has been detected in Redmine up to 4.2.8/5.0.3. The affected element is an unknown function of the component Textile Formatter. This manipulation causes cross site scripting. This vulnerability is t
CVE-2022-44030 | Redmine up to 5.0.3 permission (EUVD-2022-46992)
A vulnerability was found in Redmine up to 5.0.3. It has been rated as critical. This affects an unknown function. This manipulation causes permission issues. This vulnerability is tracked as CVE-2022-44030. The attack is only possible with
CVE-2022-44029 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46991)
A vulnerability identified as problematic has been detected in NetScout nGeniusONE up to 6.3.2 P9. This issue affects some unknown processing. The manipulation leads to cross site scripting. This vulnerability is documented as CVE-2022-4402
CVE-2022-44028 | NetScout nGeniusONE up to 6.3.2 P9 cross site scripting (EUVD-2022-46990)
A vulnerability was found in NetScout nGeniusONE up to 6.3.2 P9. It has been rated as problematic. This affects an unknown part. Performing a manipulation results in cross site scripting. This vulnerability is cataloged as CVE-2022-44028. I
CVE-2026-92298 | EspoCRM up to 10.0.8 rand random values (EUVD-2026-80078)
A vulnerability classified as problematic has been found in EspoCRM up to 10.0.8. This affects the function rand. Performing a manipulation results in insufficiently random values. This vulnerability is cataloged as CVE-2026-92298. It is po
CVE-2026-92216 | a2ui-project a2ui up to 0.10.7 Binder generic-binder.ts openUrl redirect (Issue 2296 / EUVD-2026-80077)
A vulnerability classified as problematic was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulat
CVE-2026-92299 | Jitsi Electron SDK up to 10.0.4 Screen Sharing IPC Route getDesktopSources permission (EUVD-2026-80079)
A vulnerability classified as problematic was found in Jitsi Electron SDK up to 10.0.4. This impacts the function getDesktopSources of the component Screen Sharing IPC Route. Executing a manipulation can lead to permission issues. This vuln
CVE-2026-92220 | vllm-project vLLM 0.26.0/0.27.0 MoRIIO Acknowledgement moriio_connector.py request_id/kv_transfer_params resource consumption (ID 50674 / EUVD-2026-80081)
A vulnerability identified as problematic has been detected in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of t
CVE-2026-92217 | a2ui-project a2ui up to 0.10.6 Message Parsing message-processor.ts processMessages dynamically-determined object attributes (Issue 2297 / EUVD-2026-80080)
A vulnerability, which was classified as critical, has been found in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message
CVE-2026-92221 | gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8 app_global_admin_model.php generate_index_pasien cari sql injection (EUVD-2026-80082)
A vulnerability labeled as problematic has been found in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_
CVE-2026-73450 | Arista EOS up to 4.36.1F state issue (EUVD-2026-80083)
A vulnerability was found in Arista EOS up to 4.32.x/4.33.9M/4.34.7.1M/4.35.5M/4.36.1F and classified as critical. Impacted is an unknown function. Executing a manipulation can lead to state issue. This vulnerability appears as CVE-2026-734
CVE-2026-84961 | undici up to 7.29.0/8.10.1 BalancedPool BalancedPool constructor connect/tls certificate validation
A vulnerability marked as problematic has been reported in undici up to 7.29.0/8.10.1. Affected by this issue is the function BalancedPool constructor of the component BalancedPool. Performing a manipulation of the argument connect/tls resu
CVE-2026-85014 | undici up to 7.29.0/8.10.1 Socket Close denial of service
A vulnerability labeled as problematic has been found in undici up to 7.29.0/8.10.1. Affected by this vulnerability is an unknown functionality of the component Socket Close Handler. Such manipulation leads to denial of service. This vulner
CVE-2026-84947 | Node.js Undici up to 7.29.0/8.10.1 Dump Interceptor input validation (EUVD-2026-71517)
A vulnerability categorized as problematic has been discovered in Node.js Undici up to 7.29.0/8.10.1. The affected element is an unknown function of the component Dump Interceptor. Executing a manipulation can lead to improper input validat
CVE-2026-79418 | EMX Tecnologia Gestao X up to 8.4 Help Chat cross site scripting
A vulnerability was found in EMX Tecnologia Gestao X up to 8.4. It has been declared as problematic. This impacts an unknown function of the component Help Chat. The manipulation results in cross site scripting. This vulnerability is known
CVE-2026-84657 | Jenkins up to 2.567.x CLI permission
A vulnerability has been found in Jenkins up to 2.567.x and classified as problematic. Impacted is an unknown function of the component CLI. Performing a manipulation results in permission issues. This vulnerability is known as CVE-2026-846
CVE-2026-3416 | WSO2 API Manager/API Control Plane API Publisher random values
A vulnerability was found in WSO2 API Manager and API Control Plane. It has been rated as problematic. The impacted element is an unknown function of the component API Publisher. The manipulation leads to insufficiently random values. This
CVE-2026-84655 | Jenkins Project up to 2.567.x REST API injection
A vulnerability classified as very critical was found in Jenkins Project Jenkins up to 2.567.x. Affected is an unknown function of the component REST API. Executing a manipulation can lead to injection. This vulnerability appears as CVE-202
CVE-2026-84656 | Jenkins Project Jenkins Plugin up to 2.567.x permission
A vulnerability, which was classified as problematic, was found in Jenkins Project Jenkins Plugin up to 2.567.x. This issue affects some unknown processing. Such manipulation leads to permission issues. This vulnerability is traded as CVE-2
CVE-2024-44971 | Linux Kernel up to 6.10.4 bcm_sf2_mdio_register memory leak (Nessus ID 208425 / WID-SEC-2024-2057)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 5.10.223/5.15.164/6.1.104/6.6.45/6.10.4. The impacted element is the function bcm_sf2_mdio_register. Such manipulation leads to memory leak. This vulnerabilit
CVE-2024-44970 | Linux Kernel up to 6.1.104/6.6.45/6.10.4 mlx5_wq_ll_pop privilege escalation (Nessus ID 208425 / WID-SEC-2024-2057)
A vulnerability was found in Linux Kernel up to 6.1.104/6.6.45/6.10.4. It has been declared as problematic. This affects the function mlx5_wq_ll_pop. Such manipulation leads to privilege escalation. This vulnerability is listed as CVE-2024-
CVE-2024-44969 | Linux Kernel up to 6.10.4 buffer overflow (Nessus ID 208672 / WID-SEC-2024-2057)
A vulnerability was found in Linux Kernel up to 6.10.4. It has been rated as critical. The affected element is an unknown function. This manipulation causes buffer overflow. This vulnerability is registered as CVE-2024-44969. The attack req
CVE-2024-44967 | Linux Kernel up to 6.1.104/6.6.45/6.10.4 mgag200 devm_add_action_or_reset privilege escalation (Nessus ID 212724 / WID-SEC-2024-2057)
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.104/6.6.45/6.10.4. This affects the function devm_add_action_or_reset of the component mgag200. Such manipulation leads to privilege escalation. This vulnerabilit
CVE-2024-44968 | Linux Kernel up to 6.1.104/6.6.45/6.10.4/6.11-rc1 smp_processor_id privilege escalation (Nessus ID 208953 / WID-SEC-2024-2057)
A vulnerability was found in Linux Kernel up to 6.1.104/6.6.45/6.10.4/6.11-rc1. It has been classified as problematic. The impacted element is the function smp_processor_id. This manipulation causes privilege escalation. This vulnerability
CVE-2024-44966 | Linux Kernel up to 5.15.164/6.1.105/6.6.46/6.10.5 binfmt_flat initialization (Nessus ID 209056 / WID-SEC-2024-2057)
A vulnerability, which was classified as critical, was found in Linux Kernel up to 5.15.164/6.1.105/6.6.46/6.10.5. This issue affects some unknown processing of the component binfmt_flat. Executing a manipulation can lead to improper initia
CVE-2024-44965 | Linux Kernel up to 6.10.4 pti_clone_pgtable stack-based overflow (Nessus ID 208953 / WID-SEC-2024-2057)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.10.4. Affected by this issue is the function pti_clone_pgtable. The manipulation results in stack-based buffer overflow. This vulnerability is reported as CVE-2024-4
CVE-2026-18798 | OpenSSL up to 3.5.7/3.6.3/4.0.1 QUIC port_default_packet_handler double free (Nessus ID 345934 / WID-SEC-2026-3034)
A vulnerability was found in OpenSSL up to 3.5.7/3.6.3/4.0.1. It has been declared as critical. Affected by this issue is the function port_default_packet_handler of the component QUIC. Executing a manipulation can lead to double free. The
CVE-2026-82232 | Apache Syncope Task Search sort sql injection (CNNVD-2026-94660639)
A vulnerability, which was classified as critical, has been found in Apache Syncope. This issue affects some unknown processing of the component Task Search. This manipulation of the argument sort causes sql injection. This vulnerability is
CVE-2026-55416 | Pimcore prior 11.5.19/12.3.10/2026.1.6 CustomReportsBundle Sql.php buildQueryString sql/from/where/groupby sql injection (CNNVD-2026-96012029)
A vulnerability has been found in Pimcore and classified as problematic. Affected by this vulnerability is the function Pimcore\Bundle\CustomReportsBundle\Tool\Adapter\Sql::buildQueryString of the file bundles/CustomReportsBundle/src/Tool/A
CVE-2026-75757 | Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state cookies (tenant, actor_resource, actor_primary_key, actor_action, actor_domain, actor_authorizing, actor_paused) by matching the cookie name with an unanchored regular expression (new RegE
Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin'
CVE-2026-82605 | A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix this issue. The affected component should be upgraded.
A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading
CVE-2026-82604 | A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this issue. You should upgrade the affected component.
A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to vers
CVE-2026-82603 | A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The exploit is now public and may be used.
A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The at
CVE-2026-82602 | A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclo
CVE-2026-82601 | A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks.
A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has b
CVE-2026-75760 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset error whose message inspected the raw error term (An error occurred while generating embeddings: #{inspect(error)}). A plain-string add_error produces an Ash.Error.Changes.InvalidChange
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider ca
CVE-2026-82580 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the tool-result content. That content is appended to the conversation, emitted as a {:tool_result, ...} stream event, and sent back to the model, which typically relays it to the user. No
Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verb
CVE-2026-82579 | Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then filters the calls through normalize_tool_calls/2 and unprocessed_tool_calls/2. Both can empty the list: a call missing a valid name, or one reusing a tool_call_id that already has a resul
Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a
CVE-2026-82564 | Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the update/destroy filter directly from the raw tool arguments as [{key, Map.get(arguments, to_string(key))}] and passed it to Ash.Query.do_filter/2. A map value is parsed as a predicate expression
Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution
CVE-2026-82600 | A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be in
CVE-2026-81315 | Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins: nil, origin_allowed?/3 accepts an origin when uri.host == conn.host and the forwarded scheme is https. Both values are attacker-controlled: conn.host comes from the Host header and the
Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Ser
CVE-2026-77956 | Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input, context -> ... end form lets the prompt content be built from action arguments, so when a prompt action's text incorporates request data, that attacker-controlled text is compiled and run as
Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2.
CVE-2026-82599 | A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path tr