CVEs classified under CWE-184, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-87985: An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted…
CVE-2026-79696: A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 on Python…
CVE-2026-57138 — CVSS 9.9 (critical): PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes…
CVE-2026-65083 — CVSS 9.9 (critical): NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of…
CVE-2026-47392 — CVSS 9.9 (critical): PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents…
CVE-2026-28363 — CVSS 9.9 (critical): In OpenClaw before 2026.2.23, tools.exec.safeBins validation for sort could be bypassed via GNU long-option abbreviations (such as…
CVE-2026-74886 — CVSS 9.8 (critical): openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of…
CVE-2026-70470 — CVSS 9.8 (critical): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFr…
CVE-2026-69263 — CVSS 9.8 (critical): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943…
CVE-2026-56315 — CVSS 9.8 (critical): picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support…
CVE-2026-53873 — CVSS 9.8 (critical): picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level profile.run()…
CVE-2025-71323 — CVSS 9.8 (critical): picklescan before 0.0.33 fails to block the ctypes module, allowing attackers to achieve remote code execution by invoking direct syscalls…
CVE-2025-71320 — CVSS 9.8 (critical): picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing…
CVE-2026-41264 — CVSS 9.8 (critical): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within…
CVE-2026-34415 — CVSS 9.8 (critical): Xerte Online Toolkits versions 3.15 and earlier contain an incomplete input validation vulnerability in the elFinder connector endpoint…
CVE-2025-1716 — CVSS 9.8 (critical): picklescan before 0.0.21 does not treat 'pip' as an unsafe global. An attacker could craft a malicious model that uses Pickle to pull in a…
CVE-2023-3374 — CVSS 9.8 (critical): Incomplete List of Disallowed Inputs vulnerability in Unisign Bookreen allows Privilege Escalation. This issue affects Bookreen: before…
CVE-2019-9212 — CVSS 9.8 (critical): SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because…
CVE-2018-7489 — CVSS 9.8 (critical): FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution…
CVE-2017-7525 — CVSS 9.8 (critical): A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an…
CVE-2017-0909 — CVSS 9.8 (critical): The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network…
CVE-2017-7540 — CVSS 9.8 (critical): rubygem-safemode, as used in Foreman, versions 1.3.2 and earlier are vulnerable to bypassing safe mode limitations via special Ruby syntax…
CVE-2026-75884 — CVSS 9.1 (critical): A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts…
CVE-2026-43578 — CVSS 9.1 (critical): OpenClaw versions 2026.3.31 before 2026.4.10 contain a privilege escalation vulnerability where heartbeat owner downgrade detection misses…
CVE-2026-43566 — CVSS 9.1 (critical): OpenClaw versions 2026.4.7 before 2026.4.14 contain a privilege escalation vulnerability where heartbeat owner downgrade logic skips…
CVE-2026-34177 — CVSS 9.1 (critical): Canonical LXD versions 4.12 through 6.7 contain an incomplete denylist in isVMLowLevelOptionForbidden (lxd/project/limits/permissions.go)…
CVE-2026-106218 — CVSS 8.8 (high): In JetBrains TeamCity before 2026.1.3 2025.11.7 kotlin DSL sandbox escape leading to RCE on the server was possible
CVE-2026-101882 — CVSS 8.8 (high): OpenClaw Windows Node before 2026.7.1 contains an incomplete validation vulnerability in system.execApprovals.set that accepts…
CVE-2026-100253 — CVSS 8.8 (high): In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings…
CVE-2026-67615 — CVSS 8.8 (high): openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to…
CVE-2026-82536 — CVSS 8.8 (high): Roo-Code through 3.54.0 contains an auto-approve bypass vulnerability in the shell command parsing logic that allows attackers to execute…
CVE-2026-63108 — CVSS 8.8 (high): Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass…
CVE-2026-62203 — CVSS 8.8 (high): OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host exec that fails to properly sanitize…
CVE-2026-62200 — CVSS 8.8 (high): OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that could allow Git ext transport to be abused. When…
CVE-2026-62199 — CVSS 8.8 (high): OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss interpreter startup variables. When the…
CVE-2026-14534 — CVSS 8.8 (high): Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard library modules _posixsubprocess, site, and…
CVE-2026-53836 — CVSS 8.8 (high): OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that allows attackers to…
CVE-2026-48557 — CVSS 8.8 (high): Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The…
CVE-2026-45006 — CVSS 8.8 (high): OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations…
CVE-2026-44115 — CVSS 8.8 (high): OpenClaw before 2026.4.22 contains an exec allowlist analysis vulnerability allowing shell expansion hiding in unquoted heredoc bodies…
CVE-2026-43584 — CVSS 8.8 (high): OpenClaw before 2026.4.10 contains an insufficient environment variable denylist vulnerability in its exec environment policy that allows…
CVE-2026-41934 — CVSS 8.8 (high): Vvveb before version 1.0.8.2 contains an authenticated remote code execution vulnerability in the admin code editor that allows…
CVE-2026-42435 — CVSS 8.8 (high): OpenClaw versions from 2026.2.22 before 2026.4.12 contain an insufficient shell-wrapper detection vulnerability allowing attackers to…
CVE-2026-34430 — CVSS 8.8 (high): ByteDance DeerFlow versions prior to commit 92c7a20 contain a sandbox escape vulnerability in bash tool handling that allows attackers to…
CVE-2022-43396 — CVSS 8.8 (high): In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can…
CVE-2021-25631 — CVSS 8.8 (high): In the LibreOffice 7-1 series in versions prior to 7.1.2, and in the 7-0 series in versions prior to 7.0.5, the denylist can be…
CVE-2018-6383 — CVSS 8.8 (high): Monstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or…
CVE-2026-33197: AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local…
CVE-2026-52776: Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through…