VulnSea

CWE-20

CVEs classified under CWE-20, newest first.

552 CVEsRSS

CVE-2026-94383High· 8.6
today

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A …

TwilightMISP · MISPvia NVD
CVE-2026-94379Medium· 6.9
today

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PU…

SunlitMISP · MISPvia NVD
CVE-2026-94093Medium· 6.3PoC
yesterday

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0

A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/load_replay_buffer/VecNormalize.load of the file save_util.py. Such manipulation leads to deserialization. It is possi…

TwilightDLR-RM · stable-baselines3EPSS 0.26%via NVD
CVE-2026-94092Medium· 5.5
yesterday

A vulnerability was detected in dmlc dgl up to 2.1.0

A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file utils.py. Performing a manipulation of the argument path results in deserialization. The attack can be initiated remot…

Sunlitdmlc · dglEPSS 0.19%via NVD
CVE-2026-94091Medium· 5.5PoC
yesterday

A weakness has been identified in piskvorky gensim up to 4.4.0

A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file gensim/utils.py of the component Model Loader. This manipulation of the argument fname causes deserialization. It is po…

Twilightpiskvorky · gensimEPSS 0.19%via NVD
CVE-2026-92254Medium· 6.9
yesterday

Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary file…

Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driver versions 1.3.0.0 and earlier) on Microsoft Windows allows local, low-privileged attackers to delete arbitrary file…

SunlitWatchdog · Anti-VirusEPSS 0.10%via NVD
CVE-2026-81180High· 8.8
3d ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript…

TwilightSyslifters · sysreptorEPSS 0.36%via NVD
CVE-2026-61794Medium· 6.8
3d ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the…

Sunlitprojectcapsule · github.com/projectcapsule/capsuleEPSS 0.33%via NVD
CVE-2026-25684Medium· 4.4
3d ago

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

SunlitZscaler · ZIA File Type ControlEPSS 0.18%via NVD
CVE-2026-93567High· 7.5
3d ago

A flaw was found in Netty's HTTP/2 codec

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker …

TwilightRed Hat · netty-codec-http2EPSS 0.40%via NVD
CVE-2026-93568High· 7.5
3d ago

A flaw was found in Netty

A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HT…

TwilightRed Hat · netty-codec-http2EPSS 0.47%via NVD
CVE-2026-12954High· 8.8
3d ago

The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function

The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no cap…

Twilightmapster · Mapster WP MapsEPSS 0.46%via NVD
CVE-2026-18911High· 7.5
3d ago

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

TwilightZohocorp · ManageEngine DataSecurity PlusEPSS 1.1%via NVD
CVE-2026-54501Critical· 9.4
4d ago

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Cust…

Midnightwebrecorder · browsertrixEPSS 1.2%via NVD
CVE-2026-45723Low· 2.7
4d ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClie…

Sunlitsiderolabs · omniEPSS 0.39%via NVD
CVE-2026-93295Medium· 5.1
4d ago

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher:…

Sunlitmisp · mispEPSS 0.50%via NVD
CVE-2026-54577Low· 2.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automat…

SunlitMidnightBSD · mportEPSS 0.15%via NVD
CVE-2026-61793Medium· 6.9PoC
4d ago

Nuxt OG Image generates OG Images with Vue templates in Nuxt

Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults security.strict = false and security.secret = "" are used, and b…

Twilightnuxt-modules · og-imageEPSS 0.46%via NVD
CVE-2026-92860Critical· 9.1PoC
4d ago

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of th…

Abyssalrcourtman · PulseEPSS 0.47%via NVD
CVE-2026-92581Medium· 4.3PoC
5d ago

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed li…

TwilightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-81875High· 7.5PoC
5d ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can consume attacker…

Midnighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-81876High· 7.5
5d ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to version 6.9.12, SHCParser in org.hl7.fhir.r5/src/main/java/org/hl7/fhir/r5/elementmodel/SHCParser.java can enter an infinit…

Twilighthapifhir · org.hl7.fhir.coreEPSS 0.63%via NVD
CVE-2026-20237Critical· 9.1
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal secur…

MidnightCisco · Cisco Identity Services Engine SoftwareEPSS 0.33%via NVD
CVE-2026-90999Critical· 9.8
5d ago

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can su…

MidnightFunctional Software, Inc. · Sentry SeerEPSS 0.51%via NVD
CVE-2026-88064High· 8.8
5d ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can regist…

Twilightbackstage · backstageEPSS 0.63%via NVD
CVE-2026-77190Medium· 6.5
5d ago

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent …

On affected platforms running Arista EOS, an unauthenticated attacker who is network-adjacent to the switch and able to connect to a device with PIM Sparse Mode and MLAG configured, can send malformed messages that cause the Pimsm agent …

SunlitArista Networks · EOSEPSS 0.28%via NVD
CVE-2026-73445Medium· 4.9
5d ago

On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active

On affected platforms running Arista EOS, an issue with the gRPC Network Security Interface (gNSI) Authz Rotate RPC may cause an incorrect Authz policy which was uploaded in the ongoing RPC stream to become active. This does not affect B…

SunlitArista Networks · EOSEPSS 0.33%via NVD
CVE-2026-86475Medium· 5.3PoC
5d ago

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully…

The Appointment Hour Booking WordPress plugin before 1.5.95 does not check every appointment in a booking submission against the capacity configured for its own slot, allowing unauthenticated visitors to take slots that are already fully…

TwilightEPSS 0.26%via NVD
CVE-2026-91738Critical· 9.6
6d ago

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-19655Medium· 6.5
6d ago

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…

On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay/snooping configured with the information option (Option 82), or with the DHCP server configured with match criteria based on the information o…

SunlitArista Networks · EOSEPSS 0.19%via NVD
CWE-20 vulnerabilities (CVEs) · VulnSea