VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15745 CVEsRSS

CVE-2026-94084Critical· 9.4
1w ago

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.

▾ Midnightoisf · suricatavia NVD
CVE-2026-94083Critical· 9.4
1w ago

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade)

Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). Thi…

▾ Midnightoisf · suricatavia NVD
CVE-2026-93958Critical· 9.1PoC
1w ago

A vulnerability was found in D-Link R95 BE9500_1.00.16

A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/ssi of the component DHMAPI. The manipulation of the argument NTPServer results in os command injection. The attack c…

▾ AbyssalD-Link · R95EPSS 2.7%via NVD
CVE-2026-86551Low· 3.3
1w ago

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address by querying the read-only field factory_mac_address in the Settings.Secure database.

▾ SunlitZTE · NX741JEPSS 0.19%via NVD
CVE-2026-93956Low· 3.5PoC
1w ago

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2

A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighlights of the file src/SearchEngine.php of the component Search Engine. Executing a manipulation of the argument Query…

▾ Twilightolivier-ls · PHP-FTSEPSS 0.42%via NVD
CVE-2026-93955Medium· 4.3PoC
1w ago

A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component…

▾ Twilightgrimmory-tools · grimmoryEPSS 0.41%via NVD
CVE-2026-94056High· 7.5
1w ago

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uninitialized data from stack memory.

▾ Twilightexim · eximEPSS 0.36%via NVD
CVE-2026-94054High· 7.0
1w ago

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write.

▾ Twilightexim · eximEPSS 0.27%via NVD
CVE-2026-93990High· 7.5
1w ago

Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted

Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that c…

▾ Twilightlibexpat · libexpatvia NVD
CVE-2026-93988Medium· 6.5PoC
1w ago

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email par…

▾ Twilightwebkul · qloappsEPSS 0.55%via NVD
CVE-2026-94057Medium· 4.0
1w ago

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead depends on crafted data sent after a rejection during DATA processing.

▾ Sunlitexim · eximEPSS 0.20%via NVD
CVE-2026-93991High· 7.7
1w ago

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator

Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that fails to apply cluster-scoped access review when the metadata.namespace field selector uses the NotEquals operator. A…

▾ Twilightargoproj · argo-workflowsEPSS 0.44%via NVD
CVE-2026-93989Low· 3.1
1w ago

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer()

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of …

▾ Sunlitvllm · vllmvia NVD
CVE-2026-93992High· 8.1PoC
1w ago

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing dir…

▾ MidnightGopeedLab · gopeedEPSS 0.91%via NVD
CVE-2026-94055Low· 3.7
1w ago

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

▾ Sunlitexim · eximEPSS 0.29%via NVD
CVE-2026-93993High· 8.8PoC
1w ago

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes…

▾ Midnightmistralai · mistral-vibeEPSS 0.77%via NVD
CVE-2026-93954Medium· 4.3PoC
1w ago

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of …

▾ Twilightgrimmory-tools · grimmoryEPSS 0.39%via NVD
CVE-2026-82672Medium· 6.3PoC
1w ago

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabli…

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabli…

▾ Twilightelixir-mint · mintEPSS 0.52%via NVD
CVE-2026-82560High· 7.5
1w ago

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the outp…

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the outp…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-94000Medium· 6.6
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges be…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.40%via NVD
CVE-2026-93999Medium· 4.2
1w ago

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client I…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.23%via NVD
CVE-2026-94001Medium· 6.5
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.44%via NVD
CVE-2026-93981Medium· 4.7
1w ago

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

▾ Sunlithonojs · honoEPSS 0.23%via NVD
CVE-2026-93983Medium· 5.0
1w ago

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics…

▾ SunlitOpenpanel-dev · openpanelEPSS 0.33%via NVD
CVE-2026-93982Low· 3.3PoC
1w ago

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems c…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.17%via NVD
CVE-2026-93986Low· 3.1
1w ago

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent…

▾ Sunlitrclone · rcloneEPSS 0.29%via NVD
CVE-2026-93985Critical· 9.9PoC
1w ago

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can c…

▾ AbyssalOpenpanel-dev · openpanelEPSS 0.67%via NVD
CVE-2026-93984Medium· 5.3PoC
1w ago

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitr…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.41%via NVD
CVE-2026-93987Low· 3.4PoC⚖ disputed
1w ago

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the a…

▾ Twilightrclone · rcloneEPSS 0.15%via NVD
CVE-2026-78030Critical· 9.8
1w ago

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

▾ MidnightEPSS 0.42%via NVD
CVEs tagged “cve.org” — page 107 · VulnSea