VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15756 CVEsRSS

CVE-2026-84070High· 8.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.52%via NVD
CVE-2026-61781Critical· 9.9
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_partition_time() reads the writable part_config.time_encoder text value and interpolates it without identifier quoting into a dyna…

▾ Midnightpgpartman · pg_partmanEPSS 0.80%via NVD
CVE-2026-84071High· 7.2
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality

IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell comman…

▾ TwilightIBM · Guardium Data ProtectionEPSS 1.5%via NVD
CVE-2026-84064Critical· 9.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.62%via NVD
CVE-2026-11725High· 8.8
1w ago

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

▾ TwilightIBM · MQEPSS 0.40%via NVD
CVE-2026-93854High· 7.2
1w ago

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id})

In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce object-level authorization on its update and delete operations (PUT /v2/leases/{lease_id} and DELETE /v2/leases/{lease_id}). The policy authorize() wrapper attempts to …

▾ TwilightOpenStack · BlazarEPSS 0.41%via NVD
CVE-2026-93852High· 7.1
1w ago

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy

In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET /v2/leases) returns leases for every project without enforcing project scoping or an administrator-only policy. Any authenticated user with access to the Blazar REST …

▾ TwilightOpenStack · BlazarEPSS 0.37%via NVD
CVE-2026-11549Medium· 6.5
1w ago

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.

IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a virtual host bypass vulnerability.

▾ SunlitIBM · CICS TX AdvancedEPSS 0.23%via NVD
CVE-2026-75894High· 7.5
1w ago

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU that leads to process crash and remote denial of service.

▾ TwilightOsmocom · osmo-iuhEPSS 0.31%via NVD
CVE-2026-11538Low· 3.7
1w ago

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

IBM WebSphere Application Server 9.0 and 8.5 is affected by a log injection vulnerability through crafted LTPA token cookies.

▾ Sunlitibm · websphere_application_serverEPSS 0.16%via NVD
CVE-2023-54399Critical· 9.8PoC
1w ago

Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped

Hongjing e-HR before 8.2 contains a SQL injection vulnerability in the /servlet/codesettree endpoint where the categories query parameter is passed to a database query without sanitization after HRMS-encoding is stripped. An unauthentica…

▾ AbyssalHongjing · e-HREPSS 0.42%via NVD
CVE-2021-48008High· 7.5
1w ago

Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint

Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of inp…

▾ TwilightChanjet Information Technology Co., Ltd. · CRMEPSS 0.34%via NVD
CVE-2019-25776High· 7.5PoC
1w ago

Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint

Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint. …

▾ MidnightWeaver Network Co., Ltd. · E-cologyEPSS 0.36%via NVD
CVE-2026-93650Low· 3.7PoC
1w ago

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14

A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function get_client_ip of the file saleor/account/throttling.py. Executing a manipulation can lead to improper restriction of…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-75893High· 7.5
1w ago

In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow issue was found in the ipaccess_proxy_read_msg()  function via IPA frame lengths.

▾ TwilightOsmocom · osmo-bscEPSS 0.46%via NVD
CVE-2026-75892Medium· 6.5
1w ago

In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.

In osmo-ggsn 1.14.0 an out of bounds write issue was found in the gtp_decode_pdp_ctx() function through the PDP context GSN-Address sub-field, leading to memory corruption.

▾ SunlitOsmocom · osmo-ggsnEPSS 0.28%via NVD
CVE-2026-93753High· 7.5PoC
1w ago

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to…

▾ MidnightTehShrike · deepmergeEPSS 0.51%via NVD
CVE-2026-93752High· 7.5PoC
1w ago

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names

CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to validate reserved property names. Attackers can supply a stylesheet with a declaration named length to replace the internal…

▾ MidnightNV · CSSOMEPSS 0.68%via NVD
CVE-2026-93751Medium· 6.5
1w ago

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters

uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlong percent-encoded sequences into ASCII metacharacters. Attackers can craft percent-encoded payloads to bypass platfor…

▾ Sunlitgarycourt · uri-jsEPSS 0.40%via NVD
CVE-2026-93750Medium· 5.9PoC
1w ago

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison

http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails to properly validate Vary header wildcards due to byte-for-byte string comparison. Attackers can request URLs previous…

▾ Twilightkornelski · http-cache-semanticsEPSS 0.45%via NVD
CVE-2026-93749High· 7.5
1w ago

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronou…

▾ Twilight7rulnik · source-map-jsEPSS 0.63%via NVD
CVE-2026-93748High· 7.5PoC
1w ago

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users

http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers …

▾ Midnightkornelski · http-cache-semanticsEPSS 0.53%via NVD
CVE-2026-93432Medium· 6.1
1w ago

A flaw was found in the Quarkus Qute template engine

A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails to pass the parent template's content type information. This bypasses standard escaping mechanisms, allowing untrust…

▾ SunlitRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.42%via NVD
CVE-2026-92768Medium· 5.5PoC
1w ago

A flaw was found in cockpit-machines

A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or inst…

▾ TwilightRed Hat · cockpit-machinesEPSS 0.15%via NVD
CVE-2026-92747Medium· 5.0PoC
1w ago

A flaw was found in `cockpit-machines`

A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This …

▾ TwilightRed Hat · cockpit-machinesEPSS 0.14%via NVD
CVE-2026-92745Medium· 5.0
1w ago

A flaw was found in cockpit-machines

A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is p…

▾ SunlitRed Hat · cockpit-machinesEPSS 0.14%via NVD
CVE-2026-81182Medium· 4.2
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a public read-write note share link can disclose an uploaded file or image from the same project by updating the shared…

▾ SunlitSyslifters · sysreptorEPSS 0.27%via NVD
CVE-2026-81181Low· 3.7
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation…

▾ SunlitSyslifters · sysreptorEPSS 0.28%via NVD
CVE-2026-81180High· 8.8
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript…

▾ TwilightSyslifters · sysreptorEPSS 0.66%via NVD
CVE-2026-59163Critical· 9.1PoC
1w ago

Mnemosyne is a memory layer for artificial intelligence agents

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…

▾ Abyssalmnemosyne-memory · mnemosyne-memoryEPSS 0.33%via NVD
CVEs tagged “cve.org” — page 115 · VulnSea