Weaknesses of type CWE-914
8 resultsCVE-2026-44006CRITICALvm2: Sandbox EscapeEPSS 0.8%CVE-2023-33175CRITICALToUI allows user-specific variables to be shared between usersEPSS 0.7%CVE-2026-34444HIGHLupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattrEPSS 0.6%CVE-2024-54198HIGHInformation Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver Application Server ABAPEPSS 0.6%CVE-2025-14051MEDIUMyoulaitech youlai-mall addresses deleteAddress improper control of dynamically-identified variablesEPSS 0.5%CVE-2024-24914HIGHAuthenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vEPSS 0.4%CVE-2025-14085MEDIUMyoulaitech youlai-mall orders improper control of dynamically-identified variablesEPSS 0.4%CVE-2026-35173MEDIUMChyrp Lite has an IDOR via Mass Assignment in Post ModelEPSS 0.2%