VulnSea

CWE-15

CVEs classified under CWE-15, newest first.

14 CVEsRSS

CVE-2026-54918Medium· 5.3
5d ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant th…

Sunlitnetbox-community · devicetype-libraryEPSS 0.30%via NVD
CVE-2026-87987Critical· 10.0
1w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabl…

Midnightmistralai · mistral-vibeEPSS 0.33%via NVD
CVE-2026-85217High· 8.6
1w ago

Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated…

TwilightAutodesk · FusionEPSS 0.14%via CVEORG
CVE-2026-73661None
1mo ago

FreePBX is an open source IP PBX

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE setting with the value none through runRestore() in amp_conf/htdocs/admin/libraries/Buil…

SunlitEPSS 0.34%via NVD
CVE-2026-66065High
3mo ago

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

Twilightouroboros-ai · ouroboros-aiEPSS 0.30%via OSV
GHSA-jv2h-4p9v-wf5wHigh
3mo ago

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

ouroboros-ai: Incomplete fix of CVE-2026-47211: untrusted project .env can still reach RCE via omitted execution-routing keys

Twilightouroboros-ai · ouroboros-aivia GHSA
CVE-2026-1784High· 8.8
3mo ago

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a contro…

Twilightredhat · openshift_container_platformEPSS 0.19%via NVD
CVE-2019-25716Medium· 6.5
3mo ago

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet

Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain a denial-of-service vulnerability that allows remote attackers to cause the monitor to reboot by sending a malformed network packet. Attackers can repeatedly send malfor…

Sunlitdraeger · infinity_delta_firmwareEPSS 0.41%via NVD
CVE-2026-41176Critical· 9.8PoC
5mo ago

Rclone is a command-line program to sync files and directories to and from different cloud storage providers

Rclone is a command-line program to sync files and directories to and from different cloud storage providers. The RC endpoint `options/set` is exposed without `AuthRequired: true`, but it can mutate global runtime configuration, includin…

Abyssalrclone · rcloneEPSS 33%via NVD
CVE-2026-0232Medium· 4.4
5mo ago

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.

Sunlitpaloaltonetworks · cortex_xdr_agentEPSS 0.15%via NVD
CVE-2026-30817Medium· 5.7
5mo ago

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed

An external configuration control vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary files when a malicious configuration file is processed. Successful exploitation may a…

Sunlittp-link · archer_ax53_firmwareEPSS 0.34%via NVD
CVE-2026-30816Medium· 5.7
5mo ago

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may…

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may…

Sunlittp-link · archer_ax53_firmwareEPSS 0.29%via NVD
CVE-2025-8283Low· 3.7
1y ago

A vulnerability was found in the netavark package, a network stack for containers used with Podman

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When …

Sunlitredhat · openshift_container_platformEPSS 0.31%via NVD
CVE-2024-58351High
1y ago

Flowise OverrideConfig security vulnerability

Flowise OverrideConfig security vulnerability

Twilightflowise · flowiseEPSS 0.93%via GHSA
CWE-15 vulnerabilities (CVEs) · VulnSea