VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-92071Critical· 9.6⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.48%via NVD
CVE-2026-92068Medium· 5.4⚖ disputed
1w ago

Site isolation issue in the Reader Mode component

Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.17%via NVD
CVE-2026-92064High· 8.8⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92073High· 8.8⚖ disputed
1w ago

Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.44%via NVD
CVE-2026-92072High· 8.0⚖ disputed
1w ago

Incorrect boundary conditions in the Safe Browsing component

Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.43%via NVD
CVE-2026-92065High· 8.8⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-91926Low· 3.7
1w ago

A flaw was found in gss-ntlmssp

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not …

▾ SunlitRed Hat · gssntlmsspEPSS 0.37%via NVD
CVE-2026-91786Medium· 6.1
1w ago

A flaw was found in GNOME Shell

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search pro…

▾ SunlitRed Hat · gnome-shellEPSS 0.17%via NVD
CVE-2026-86818Medium· 4.8
1w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved nam…

▾ Sunlitfast-uri · fast-uriEPSS 0.25%via NVD
CVE-2026-80489Medium· 5.9
1w ago

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

▾ SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-77117Medium· 5.9
1w ago

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

▾ SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-86472Medium· 4.8
1w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the …

▾ Sunlitfast-uri · fast-uriEPSS 0.25%via NVD
CVE-2026-91826Medium· 4.4
1w ago

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

▾ SunlitSamsung Opensource · rLottieEPSS 0.14%via NVD
CVE-2026-75092High· 7.3
1w ago

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository)

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root…

▾ TwilightRed Hat · leapp-repositoryEPSS 0.13%via NVD
CVE-2026-81320Medium· 5.5
1w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and wri…

▾ SunlitRed Hat · rhbac-4/hawtio-rhel9EPSS 0.19%via NVD
CVE-2026-81303Medium· 6.3
1w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without valida…

▾ SunlitRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.49%via NVD
CVE-2026-17495Medium· 5.9
1w ago

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal…

▾ Sunlitmoment · momentEPSS 0.36%via NVD
CVE-2026-90878Medium· 4.3PoC
1w ago

A vulnerability was determined in vllm-project vLLM up to 0.27.1

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource co…

▾ Twilightvllm-project · vLLMEPSS 0.53%via NVD
CVE-2026-90852High· 7.3PoC
1w ago

A vulnerability has been found in luben zstd-jni up to 1.5.7-13

A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after …

▾ Midnightluben · zstd-jniEPSS 0.54%via NVD
CVE-2026-91771High· 8.8
1w ago

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal s…

▾ Twilightwandb · wandbEPSS 1.2%via NVD
CVE-2026-91752High· 7.5PoC
1w ago

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarO…

▾ MidnightGNU · libextractorEPSS 0.74%via NVD
CVE-2026-54167High· 8.2
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…

▾ Twilighttektoncd · pipelines-as-codeEPSS 0.27%via NVD
CVE-2026-54168Medium· 6.5
1w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …

▾ Sunlittektoncd · pipelines-as-codeEPSS 0.59%via NVD
CVE-2026-53941Medium· 6.9
1w ago

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to co…

▾ Sunlitinspektor-gadget · inspektor-gadgetEPSS 0.52%via NVD
CVE-2026-55225High· 8.0
1w ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator wat…

▾ Twilightstrimzi · strimzi-kafka-operatorEPSS 0.29%via NVD
CVE-2026-55226Medium· 5.4
1w ago

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom res…

▾ Sunlitstrimzi · strimzi-kafka-operatorEPSS 0.25%via NVD
CVE-2026-44778Low· 2.9⚖ disputed
1w ago

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivi…

▾ Sunlitinspektor-gadget · inspektor-gadgetEPSS 0.63%via NVD
CVE-2026-55770Medium· 6.8PoC
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…

▾ Twilightopenbao · openbaoEPSS 0.53%via NVD
CVE-2026-55774Low· 2.1
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…

▾ Sunlitopenbao · openbaoEPSS 0.56%via NVD
CVE-2026-55775Low· 2.3⚖ disputed
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespa…

▾ Sunlitopenbao · openbaoEPSS 0.48%via NVD
CVEs tagged “csaf” — page 25 · VulnSea