VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15756 CVEsRSS

CVE-2026-92702Critical· 9.1PoC
1w ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) AMD SEV-SNP verification path does not enforce att…

▾ Abyssalultravioletrs · cocosEPSS 0.31%via NVD
CVE-2026-92701Critical· 9.1PoC
1w ago

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments

Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions up to and including 0.8.2, the intra-handshake attested TLS (aTLS) Intel TDX verification path does not copy the expe…

▾ Abyssalultravioletrs · cocosEPSS 0.27%via NVD
CVE-2026-93764Medium· 6.5
1w ago

Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema

Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level encryption schema. Applications that enable this feature can therefore store values intended to be encrypted in readable…

▾ Sunlitmongodb · mongoidEPSS 0.15%via NVD
CVE-2026-84975High· 7.4
1w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuTLS backends in pjlib/src/pj/ssl_sock_ossl.c and pjlib/src/pj/ssl_sock_gtls.c copy DNS SubjectAltName values with stri…

▾ Twilightpjsip · pjprojectEPSS 0.23%via NVD
CVE-2026-77396Medium· 6.9
1w ago

PJSIP is a free and open source multimedia communication library written in C

PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser in pjmedia/src/pjmedia/avi_player.c uses an input-file video chunk length as the number of bytes copied into a frame…

▾ Sunlitpjsip · pjprojectEPSS 0.17%via NVD
CVE-2026-93763Medium· 6.5
1w ago

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any erro…

A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that an application declared for client-side field-level encryption to be written and kept in cleartext, without any erro…

▾ Sunlitmongodb · mongoidEPSS 0.15%via NVD
CVE-2026-62279High· 7.1
1w ago

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an authenticated user could submit caller-controlled recordIds to the DuplicateRecordsToOtherVehicles endpoint while naming…

▾ Twilighthargata · lubelogEPSS 0.40%via NVD
CVE-2026-93762Critical· 9.8
1w ago

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents

Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain un…

▾ Midnightmongodb · mongoidEPSS 0.57%via NVD
CVE-2026-77385Medium· 4.3PoC
1w ago

Kyoo is a self-hosted media server focused on movies, series, and anime

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core.play permission could supply a base64-encoded filesystem path to the transcoder. The path handling in transcoder/src…

▾ Twilightzoriya · KyooEPSS 0.34%via NVD
CVE-2026-62278High· 8.1
1w ago

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker

LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authenticated non-administrative users could reach HandleTranslationFileUpload and influence the name passed from Controlle…

▾ Twilighthargata · lubelogEPSS 0.51%via NVD
CVE-2026-77386Medium· 6.5PoC
1w ago

Kyoo is a self-hosted media server focused on movies, series, and anime

Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker could initiate the OIDC login flow with an attacker-controlled redirectUrl. The login handling in auth/oidc.go stored th…

▾ Twilightzoriya · KyooEPSS 0.56%via NVD
CVE-2026-93761High· 7.5
1w ago

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process

An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an unauthenticated party to cause excessive processing within an embedding application process. Applications …

▾ Twilightmongodb · mongoidEPSS 0.46%via NVD
CVE-2026-61550Critical· 9.8
1w ago

Icinga 2 is an open source monitoring system

Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to co…

▾ MidnightIcinga · icinga2EPSS 0.67%via NVD
CVE-2026-61551High· 8.6
1w ago

Icinga 2 is an open source monitoring system

Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticat…

▾ TwilightIcinga · icinga2EPSS 0.94%via NVD
CVE-2026-93760High· 8.2
1w ago

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods

Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this wa…

▾ Twilightmongodb · mongoidEPSS 0.47%via NVD
CVE-2026-61552High· 7.2
1w ago

Icinga 2 is an open source monitoring system

Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attacker-controlled template names into generated configuration without escaping them. An authenticated ApiUser with an o…

▾ TwilightIcinga · icinga2EPSS 0.90%via NVD
CVE-2026-69186Medium· 5.3PoC⚖ disputed
1w ago

c-ares is an asynchronous resolver library

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NSCOUNT, and ARCOUNT fields before confirming that the DNS response contains enough bytes for the claimed records. Beca…

▾ Twilightc-ares · c-aresEPSS 0.52%via NVD
CVE-2026-69184High· 7.5
1w ago

c-ares is an asynchronous resolver library

c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not bound the total pointer hops or assembled name length. A malicious DNS server can send a response …

▾ Twilightc-ares · c-aresEPSS 0.68%via NVD
CVE-2026-93759High· 8.6
1w ago

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression

Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application s…

▾ Twilightmongodb · mongoidEPSS 0.40%via NVD
CVE-2026-32641High· 7.5
1w ago

Parseable is a log analytics platform built for high-volume data ingestion and analysis

Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before authentication. A rem…

▾ Twilightparseablehq · parseableEPSS 0.92%via NVD
CVE-2026-85058High· 7.5PoC
1w ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths…

▾ Midnightmoquette · io.moquette:moquette-brokerEPSS 0.45%via NVD
CVE-2026-71537Medium· 6.5
1w ago

Paymenter is a free and open-source webshop solution for management of hosting services

Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…

▾ SunlitPaymenter · PaymenterEPSS 0.33%via NVD
CVE-2026-81179High· 8.1
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a…

▾ TwilightSyslifters · sysreptorEPSS 0.48%via NVD
CVE-2026-81178Low· 3.5
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same c…

▾ SunlitSyslifters · sysreptorEPSS 0.30%via NVD
CVE-2025-66455Critical· 9.8
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

▾ MidnightInternLM · lmdeployEPSS 0.69%via NVD
CVE-2026-33625High· 8.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…

▾ MidnightInternLM · lmdeployEPSS 0.44%via NVD
CVE-2026-64847Medium· 6.8
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…

▾ Sunlitagronholm · anyioEPSS 0.16%via NVD
CVE-2026-91127High· 8.2
1w ago

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled h…

▾ Twilightfile-viewer · @file-viewer/docEPSS 0.40%via NVD
CVE-2026-84992Medium· 6.1PoC
1w ago

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language …

▾ Twilightimzbf · md-editor-v3EPSS 0.33%via NVD
CVE-2026-63458High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on projec…

▾ Twilightperses · persesEPSS 0.30%via NVD
CVEs tagged “cve.org” — page 116 · VulnSea