VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15760 CVEsRSS

CVE-2026-63445High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…

▾ Twilightperses · github.com/perses/persesEPSS 0.56%via NVD
CVE-2026-63199High· 8.3
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope…

▾ Twilightperses · persesEPSS 0.27%via NVD
CVE-2026-93765Critical· 9.1
1w ago

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended inte…

▾ Midnightmongodb · mongoidEPSS 0.51%via NVD
CVE-2026-93758High· 8.1
1w ago

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a requ…

▾ Twilightmongodb · mongoidEPSS 0.36%via NVD
CVE-2026-93559High· 7.3
1w ago

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to …

▾ TwilightForget-C · Jellyfish AI Short Drama StudioEPSS 0.65%via NVD
CVE-2026-77616Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…

▾ Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.33%via NVD
CVE-2026-77610Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`)…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-77609Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…

▾ Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.25%via NVD
CVE-2026-77607Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-77239High· 8.1
1w ago

WACRM is a self-hostable CRM template for WhatsApp

WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypa…

▾ TwilightArnasDon · wacrmEPSS 0.53%via NVD
CVE-2026-63406Medium· 5.9PoC
1w ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…

▾ Twilightanycable · github.com/anycable/anycableEPSS 0.30%via NVD
CVE-2026-63405Medium· 5.9PoC
1w ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…

▾ Twilightanycable · github.com/anycable/anycableEPSS 0.21%via NVD
CVE-2026-63349High· 7.0⚖ disputed
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…

▾ Twilightagronholm · anyioEPSS 0.11%via NVD
CVE-2026-61833High· 8.1PoC
1w ago

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…

▾ Midnightproject-zot · zotEPSS 0.51%via NVD
CVE-2026-61548High· 8.1
1w ago

Rsyslog is a rocket-fast system for log processing

Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] st…

▾ Twilightrsyslog · rsyslogEPSS 0.94%via NVD
CVE-2026-55556High· 8.2PoC
1w ago

Rsyslog is a rocket-fast system for log processing

Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic…

▾ Midnightrsyslog · rsyslogEPSS 0.85%via NVD
CVE-2026-46655High· 7.8PoC
1w ago

virtio-win provides Windows paravirtualized drivers for QEMU and KVM

virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*]…

▾ Midnightvirtio-win · kvm-guest-drivers-windowsEPSS 0.18%via NVD
CVE-2026-93533Medium· 6.3PoC
1w ago

A vulnerability was determined in spatie Scotty up to 1.4.4

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler…

▾ Twilightspatie · ScottyEPSS 1.4%via NVD
CVE-2026-85478Low· 3.5
1w ago

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot p…

▾ SunlitCareCam · HMT.CM2507 FirmwareEPSS 0.22%via NVD
CVE-2026-44639Low· 3.7PoC
1w ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properties(). A remote un…

▾ Twilightnanomq · nanomqEPSS 0.44%via NVD
CVE-2026-85497Critical· 9.8
1w ago

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking

CareCam CM2507 IP cameras store the device's root-account password using a fixed legacy password hash that provides insufficient resistance to offline cracking. An attacker who obtains the firmware image or password database could recove…

▾ MidnightCareCam · HMT.CM2507 FirmwareEPSS 0.34%via NVD
CVE-2026-73863High· 7.0PoC
1w ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/protocol/mqtt/mqtt_parser.c reuses len_of_varint from the outer Properties Length while parsing each SUBSCRIPTION_IDENTI…

▾ Midnightnanomq · nanomqEPSS 0.35%via NVD
CVE-2026-61633Low· 2.0PoC
1w ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supplemental/mqtt/mqtt_codec.c does not handle a failed read_uint16() while counting topics in a malformed UNSUBSCRIBE pa…

▾ Twilightnanomq · nanomqEPSS 0.34%via NVD
CVE-2026-93338Medium· 5.3
1w ago

Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with…

Grandstream GWN7660ELR before firmware version 1.0.27.6 contains an information disclosure vulnerability that allows unauthenticated remote attackers to obtain sensitive system information by querying the SNMP v2c service configured with…

▾ SunlitGrandstream Networks · GWN7660ELREPSS 0.53%via NVD
CVE-2026-81505High· 7.1PoC
1w ago

Convoy is a cloud native webhooks gateway

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() a…

▾ Midnightfrain-dev · github.com/frain-dev/convoyEPSS 0.46%via NVD
CVE-2026-81321Critical· 9.8
1w ago

CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem

CM2507 IP cameras store configured wireless network credentials in cleartext within the device filesystem. An attacker who obtains filesystem access through physical access, a debugging interface, or another vulnerability could recover t…

▾ MidnightCareCam · HMT.CM2507 FirmwareEPSS 0.34%via NVD
CVE-2026-93534Medium· 6.3PoC
1w ago

A vulnerability was identified in spatie Scotty up to 1.4.2

A vulnerability was identified in spatie Scotty up to 1.4.2. Affected is the function SelfUpdater::update of the file app/Updater/SelfUpdater.php of the component Self Update Handler. Such manipulation leads to download of code without i…

▾ Twilightspatie · ScottyEPSS 0.21%via NVD
CVE-2026-62943High· 8.7
1w ago

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes

btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filter_btrbk.sh constructs allow_stream_match with a start anchor but without an end-of-string anchor for the complete c…

▾ Twilightdigint · btrbkEPSS 0.50%via NVD
CVE-2026-61794Medium· 6.8PoC
1w ago

Capsule is a multi-tenancy and policy-based framework for Kubernetes

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the…

▾ Twilightprojectcapsule · capsuleEPSS 0.59%via NVD
CVE-2026-93579Medium· 6.5
1w ago

A flaw was found in Netty's HTTP/2 stack

A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When thes…

▾ SunlitRed Hat · netty-codec-http2EPSS 0.58%via NVD
CVEs tagged “cve.org” — page 117 · VulnSea