VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15730 CVEsRSS

CVE-2026-85010Medium· 5.3
1w ago

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place ord…

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place ord…

▾ SunlitEPSS 0.32%via NVD
CVE-2025-12999Critical· 9.1PoC
1w ago

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

▾ AbyssalEclipse Foundation · Eclipse Open VSXEPSS 0.34%via NVD
CVE-2026-94151Medium· 5.3PoC
1w ago

A weakness has been identified in Omega Solution HRM OS up to 20260717

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can le…

▾ TwilightOmega Solution · HRM OSEPSS 0.68%via NVD
CVE-2026-94150Low· 2.4PoC
1w ago

A security flaw has been discovered in Omega Solution HRM OS up to 20260717

A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting…

▾ TwilightOmega Solution · HRM OSEPSS 0.35%via NVD
CVE-2026-94149Medium· 4.3PoC
1w ago

A vulnerability was identified in Omega Solution HRM OS up to 20260717

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the arg…

▾ TwilightOmega Solution · HRM OSEPSS 0.38%via NVD
CVE-2026-15801High· 8.0⚖ disputed
1w ago

A vulnerability was found in CRI-O related to the container checkpoint and restore feature

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with suffic…

▾ TwilightRed Hat · cri-oEPSS 0.32%via NVD
CVE-2026-94148Medium· 5.3PoC
1w ago

A vulnerability was determined in ScadaBR up to 1.1

A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. T…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-47321High· 7.5
1w ago

The CompressionFilter class uses ZLib to deflate and inflate data sent and received

The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a comp…

▾ TwilightApache Software Foundation · org.apache.mina:mina-filter-compressionEPSS 0.49%via NVD
CVE-2026-94218Low· 3.1
1w ago

A flaw was found in the authentication session management of Keycloak, an identity and access management solution

A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authenticatio…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.31%via NVD
CVE-2026-94217Low· 3.5
1w ago

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system in…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.24%via NVD
CVE-2026-94146High· 8.8
1w ago

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in writ…

▾ TwilightBioStar · BIOS Update UtilityEPSS 0.18%via NVD
CVE-2026-94145Low· 3.5PoC
1w ago

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…

▾ Twilightxuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-94144High· 7.3PoC
1w ago

A flaw has been found in drogonframework drogon up to 1.9.13

A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. …

▾ Midnightdrogonframework · drogonEPSS 0.43%via NVD
CVE-2026-90860High· 7.1
1w ago

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

▾ TwilightCanva · CanvaEPSS 0.30%via NVD
CVE-2026-94213Medium· 4.9
1w ago

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution

A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solution. The issue occurs in the policy evaluation endpoint, which is used by administrators to test how access policies…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.39%via NVD
CVE-2026-94215Medium· 5.5
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs because the API uses a per-request in-memory cache to resolve clients by their unique identifier without verifyi…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.30%via NVD
CVE-2026-82187Critical· 9.8
1w ago

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to…

The Web to Print Online Designer WordPress plugin before 2.15.0 does not validate the type or extension of uploaded files, and hands the token protecting those uploads to any visitor who asks for it, allowing unauthenticated attackers to…

▾ MidnightEPSS 0.55%via NVD
CVE-2026-94143High· 7.3PoC
1w ago

A vulnerability was detected in drogonframework drogon up to 1.9.13

A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Mapper::orderBy in the library Mapper.h of the component ORM Mapper. Performing a manipulation of the argument sort results in sq…

▾ Midnightdrogonframework · drogonEPSS 0.43%via NVD
CVE-2026-94142High· 8.8PoC
1w ago

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200

A security vulnerability has been detected in BioStar Temperature Monitor Utility 1.2.1806.2200. Affected by this vulnerability is the function sub_1105C of the file BS_HWMIO64_W10.sys of the component IOCTL Handler. Such manipulation of…

▾ MidnightBioStar · Temperature Monitor UtilityEPSS 0.18%via NVD
CVE-2026-94139High· 7.4PoC
1w ago

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A weakness has been identified in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. Affected is an unknown function of the file /send_order.cgi?parameter=loginout of the component Cookie Handler. This manipulation o…

▾ MidnightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 1.2%via NVD
CVE-2026-94138Medium· 6.6PoC
1w ago

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656

A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impacts an unknown function of the file /send_order.cgi?parameter=del_expmac. The manipulation of the argument mac result…

▾ TwilightChengdu Feiyuxing Technology · Feiyu Star RouterEPSS 2.1%via NVD
CVE-2026-94137Low· 3.3
1w ago

A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693

A vulnerability was identified in Hangzhou Shunwang Technology shzh 10.7.2.693. This affects the function sub_180004AC0 of the file shdrv_x64.sys of the component IRP_MJ_DEVICE_CONTROL Handler. The manipulation of the argument PID leads …

▾ SunlitHangzhou Shunwang Technology · shzhEPSS 0.16%via NVD
CVE-2026-94185Medium· 5.5
1w ago

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias

nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() concatenated the requested name onto that directory and read the result with no containment check, so a name containi…

▾ Sunlitnvm-sh · nvmEPSS 0.22%via NVD
CVE-2026-94129High· 8.8PoC
1w ago

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800

A vulnerability was detected in BioStar VALKYRIE AURORA 2.10.2411.0800. This vulnerability affects the function sub_1105C of the file BS_RVSIO64.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress results…

▾ MidnightBioStar · VALKYRIE AURORAEPSS 0.18%via NVD
CVE-2026-94128High· 8.8PoC
1w ago

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500

A security vulnerability has been detected in BioStar VIVID LED DJ 4.0.2411.1500. This affects the function sub_1105C of the file BS_LED64.sys of the component IOCTL Handler. The manipulation of the argument AssociatedIrp leads to write-…

▾ MidnightBioStar · VIVID LED DJEPSS 0.18%via NVD
CVE-2026-94110High· 7.3PoC
1w ago

A security vulnerability has been detected in QCMS up to 6.0.6

A security vulnerability has been detected in QCMS up to 6.0.6. This issue affects the function self_Tmp in the library Lib/Config/Controllers.php of the component Content Detail Page. Such manipulation of the argument ID leads to sql in…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-94102Medium· 4.3PoC
1w ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login of the component Login. This manipulation of the argument forward causes open redirect. The attack can be initiated r…

▾ TwilightEPSS 0.43%via NVD
CVE-2026-94101Critical· 9.9PoC
1w ago

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246

A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It…

▾ AbyssalNetcore · NBR200V2EPSS 0.80%via NVD
CVE-2026-94103Medium· 4.7PoC
1w ago

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2

A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/site_pagePHP.php of the component Frontend Rendering. Such manipulation of the argument content leads to code injection.…

▾ TwilightEPSS 0.41%via NVD
CVE-2026-94100Critical· 9.9PoC
1w ago

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246

A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX…

▾ AbyssalNetcore · NBR200V2EPSS 0.80%via NVD
CVEs tagged “cve.org” — page 102 · VulnSea