VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15756 CVEsRSS

CVE-2026-61820High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping e…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61819High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verb…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61818High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically ex…

▾ Twilightpgpartman · pg_partmanEPSS 0.51%via NVD
CVE-2026-61817High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_co…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61723Medium· 6.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned expression cues * 4 + cbsize without checking whether the multiplication …

▾ SunlitFluidSynth · fluidsynthEPSS 0.18%via NVD
CVE-2026-61722Medium· 6.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that …

▾ SunlitFluidSynth · fluidsynthEPSS 0.20%via NVD
CVE-2026-61721High· 8.0
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_valid…

▾ TwilightFluidSynth · fluidsynthEPSS 0.19%via NVD
CVE-2026-61720Medium· 6.2
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A cr…

▾ SunlitFluidSynth · fluidsynthEPSS 0.18%via NVD
CVE-2026-61714High· 7.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap…

▾ TwilightFluidSynth · fluidsynthEPSS 0.18%via NVD
CVE-2026-58264Critical· 9.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied valu…

▾ MidnightFluidSynth · fluidsynthEPSS 0.80%via NVD
CVE-2026-57226Low· 3.7
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe decompre…

▾ Sunlitoisf · suricatavia NVD
CVE-2026-57224Medium· 6.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their…

▾ Sunlitoisf · suricatavia NVD
CVE-2026-57222Medium· 5.3
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, crafted IPv4 and IPv6 address pairs can collide in the IPPair hash because src/ippair.c did …

▾ SunlitOISF · suricataEPSS 0.44%via NVD
CVE-2026-52745Medium· 5.3
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.0, the POST /account-pool/page endpoint allows an authenticated caller with MODULE_SETTING:UPDATE to place a cr…

▾ Sunlit1Panel-dev · CordysCRMEPSS 0.34%via NVD
CVE-2026-75895High· 7.5
1w ago

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was found in the at smpp34_unpack() function via attacker controlled SMPP PDUs, leading to memory corruption.

▾ TwilightOsmocom · libsmpp34EPSS 0.42%via NVD
CVE-2017-20284High· 7.5PoC
1w ago

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the…

▾ MidnightCaucho Technology, Inc. · ResinEPSS 0.96%via NVD
CVE-2026-11545Low· 3.7
1w ago

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the administrative console due to missing authorization checks.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.26%via NVD
CVE-2026-11540Medium· 5.3
1w ago

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0 and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
CVE-2026-11539Medium· 5.3
1w ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

IBM WebSphere Application Server 9.0 and 8.5 is affected by an authentication bypass vulnerability in the SOAP/JMX connector.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.30%via NVD
CVE-2026-93841Low· 3.7
1w ago

vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size

vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs index the penalty prompt-presence bitset without bounds checking against vocabulary size. Attackers can submit multimoda…

▾ Sunlitvllm · vllmvia NVD
CVE-2026-93838Medium· 5.9PoC
1w ago

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments

SGLang versions through 0.5.20 contain an unbounded memory allocation vulnerability in handle_staging_req() that fails to validate chunk_idx from ZMQ STAGING_REQ frames in prefill/decode disaggregation deployments. Attackers with access …

▾ Twilightsgl-project · sglangEPSS 0.65%via NVD
CVE-2026-11548Medium· 4.8
1w ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

▾ SunlitIBM · CICS TX AdvancedEPSS 0.18%via NVD
CVE-2026-93840Low· 3.7
1w ago

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids()

vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in SamplingParams._validate_allowed_token_ids(). Attackers can supply token IDs above the output vocabulary that pass validation…

▾ Sunlitvllm · vllmvia NVD
CVE-2026-93839Critical· 9.8PoC
1w ago

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation

LightLLM through 1.2.0 contains an authentication bypass vulnerability in the /pd_register WebSocket endpoint that allows unauthenticated attackers to register arbitrary nodes by supplying crafted JSON without peer address validation. At…

▾ AbyssalModelTC · LightLLMEPSS 0.76%via NVD
CVE-2026-11711Medium· 6.5
1w ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a deserialization vulnerability in the Name Service component.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.38%via NVD
CVE-2026-11710Medium· 6.5
1w ago

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

IBM WebSphere Application Server 8.5 is affected by an HTTP request smuggling vulnerability due to improper handling of Content-Length headers.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.23%via NVD
CVE-2026-11722Medium· 4.8
1w ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by an HTTP request smuggling vulnerability.

▾ SunlitIBM · CICS TX AdvancedEPSS 0.18%via NVD
CVE-2026-11716High· 7.5
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.33%via NVD
CVE-2026-91205Medium· 6.0
1w ago

A flaw was found in cockpit-files

A flaw was found in cockpit-files. A local unprivileged attacker can exploit a race condition during directory creation with owner assignment. By controlling a writable parent directory, the attacker can replace a newly created directory…

▾ SunlitRed Hat · cockpit-filesEPSS 0.10%via NVD
CVE-2026-11726High· 8.1
1w ago

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

▾ TwilightIBM · MQ for HPE NonStopEPSS 0.33%via NVD
CVEs tagged “cve.org” — page 113 · VulnSea