VulnSea

Tagged “csaf”

CVEs tagged csaf, newest first.

3093 CVEsRSS

CVE-2026-96442High· 7.8
4d ago

A code execution flaw was found in Emacs, affecting versions prior to 31.2

A code execution flaw was found in Emacs, affecting versions prior to 31.2. The Flymake mode using language backends other than Lisp would execute arbitrary code from the edited file while performing syntax checking. Viewing or editing u…

▾ TwilightGNU Emacs · emacsEPSS 0.17%via NVD
CVE-2026-79616Low· 0.6⚖ disputed
4d ago

Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.

Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path.

▾ Sunlitqt · qtEPSS 0.10%via NVD
CVE-2026-89425High· 7.5PoC
4d ago

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound

UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error message by appending Java identifier characters to a StringBuilder in a loop that has no upper bound. Unlike the three …

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-coreEPSS 0.49%via NVD
CVE-2026-95897Medium· 5.5PoC
4d ago

A security vulnerability has been detected in Dask up to 2026.8.0

A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched re…

▾ TwilightRed Hat · DaskEPSS 0.19%via NVD
CVE-2026-77285Low· 2.4⚖ disputed
4d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runn…

▾ Sunlitopenbao · openbaoEPSS 0.13%via NVD
CVE-2026-63132Critical· 9.2
4d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthentic…

▾ Midnightopenbao · openbaoEPSS 0.50%via NVD
CVE-2026-63131Medium· 6.0
4d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] f…

▾ Sunlitopenbao · openbaoEPSS 0.35%via NVD
CVE-2026-95814High· 8.1
5d ago

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization …

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization …

▾ Twilightdani-garcia · vaultwardenEPSS 0.43%via NVD
CVE-2026-91018High· 8.8
5d ago

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

▾ TwilightlwIP · lwIP APIEPSS 0.24%via NVD
CVE-2026-94574High· 7.8
5d ago

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execut…

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execut…

▾ TwilightGNU Wget (Windows Builds) · WgetEPSS 0.12%via NVD
CVE-2026-75432Medium· 6.5
5d ago

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

▾ SunlitRed HatEPSS 0.22%via NVD
CVE-2026-88341Medium· 5.5PoC
5d ago

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.17%via NVD
CVE-2026-83603High· 8.4
5d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata…

▾ Twilightnetdata · netdataEPSS 0.35%via NVD
CVE-2026-83601Medium· 6.5PoC
5d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot in src/plugins.d/pluginsd_internals.h witho…

▾ Twilightnetdata · netdataEPSS 0.37%via NVD
CVE-2026-83600Medium· 6.5PoC
5d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. Th…

▾ Twilightnetdata · netdataEPSS 0.55%via NVD
CVE-2026-76805Medium· 5.3
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that all…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.41%via NVD
CVE-2026-76803Medium· 5.3
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN opti…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.40%via NVD
CVE-2026-95818Low· 3.6⚖ disputed
5d ago

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_R…

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_R…

▾ SunlitThe GNU C Library · glibcEPSS 0.13%via NVD
CVE-2026-76802Medium· 4.7⚖ disputed
5d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzz…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.18%via NVD
CVE-2026-87902High· 8.1CISA KEVPoC
5d ago

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are…

▾ AbyssalWordPress · WordPressEPSS 18%via NVD
CVE-2026-83602Medium· 6.5
5d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled b…

▾ Sunlitnetdata · netdataEPSS 0.51%via NVD
CVE-2026-83599High· 7.5
5d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompre…

▾ Twilightnetdata · netdataEPSS 0.74%via NVD
CVE-2026-13087High· 8.8PoC
5d ago

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write lis…

▾ MidnightRed Hat · kernelEPSS 0.47%via NVD
CVE-2026-81882Low· 3.3
5d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized U…

▾ Sunlitradare · radare2EPSS 0.13%via NVD
CVE-2026-77619High· 8.7
5d ago

Vector is a high-performance observability data pipeline

Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenti…

▾ Twilightvectordotdev · vectorEPSS 0.52%via NVD
CVE-2026-79311Medium· 6.1
5d ago

webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-94640High· 7.5
5d ago

A flaw was found in rpcbind

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedur…

▾ TwilightRed Hat · rpcbindEPSS 0.61%via NVD
CVE-2026-81884Low· 2.5PoC
5d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a fi…

▾ Twilightradareorg · radare2EPSS 0.17%via NVD
CVE-2026-90462Medium· 5.4PoC
5d ago

A flaw was found in SSSD

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. Thi…

▾ TwilightRed Hat · sssdEPSS 0.21%via NVD
CVE-2026-86805Medium· 6.3
5d ago

A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges

A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/se…

▾ SunlitThe GNU C Library · glibcEPSS 0.12%via NVD
CVEs tagged “csaf” — page 7 · VulnSea