VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15796 CVEsRSS

CVE-2026-85058High· 7.5PoC
1w ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths…

▾ Midnightmoquette · io.moquette:moquette-brokerEPSS 0.45%via NVD
CVE-2026-71537Medium· 6.5
1w ago

Paymenter is a free and open-source webshop solution for management of hosting services

Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…

▾ SunlitPaymenter · PaymenterEPSS 0.33%via NVD
CVE-2026-81179High· 8.1
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a…

▾ TwilightSyslifters · sysreptorEPSS 0.48%via NVD
CVE-2026-81178Low· 3.5
1w ago

SysReptor is a fully customizable pentest reporting platform

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public note share link receives project-wide collaborative editing metadata because the public share consumer joins the same c…

▾ SunlitSyslifters · sysreptorEPSS 0.30%via NVD
CVE-2025-66455Critical· 9.8
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

▾ MidnightInternLM · lmdeployEPSS 0.69%via NVD
CVE-2026-33625High· 8.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…

▾ MidnightInternLM · lmdeployEPSS 0.44%via NVD
CVE-2026-64847Medium· 6.8
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…

▾ Sunlitagronholm · anyioEPSS 0.16%via NVD
CVE-2026-91127High· 8.2
1w ago

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled h…

▾ Twilightfile-viewer · @file-viewer/docEPSS 0.40%via NVD
CVE-2026-84992Medium· 6.1PoC
1w ago

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language …

▾ Twilightimzbf · md-editor-v3EPSS 0.33%via NVD
CVE-2026-63458High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on projec…

▾ Twilightperses · persesEPSS 0.30%via NVD
CVE-2026-63445High· 7.1
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…

▾ Twilightperses · github.com/perses/persesEPSS 0.56%via NVD
CVE-2026-63199High· 8.3
1w ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope…

▾ Twilightperses · persesEPSS 0.27%via NVD
CVE-2026-93765Critical· 9.1
1w ago

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code

Mongoid contains an unsafe reflection weakness in the document persistence layer of its object-document mapping code. Input whose keys are passed through from an unauthenticated party by an embedding application can cause unintended inte…

▾ Midnightmongodb · mongoidEPSS 0.51%via NVD
CVE-2026-93758High· 8.1
1w ago

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own

An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a requ…

▾ Twilightmongodb · mongoidEPSS 0.36%via NVD
CVE-2026-93559High· 7.3
1w ago

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to …

▾ TwilightForget-C · Jellyfish AI Short Drama StudioEPSS 0.65%via NVD
CVE-2026-77616Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…

▾ Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.33%via NVD
CVE-2026-77610Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`)…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-77609Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…

▾ Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.25%via NVD
CVE-2026-77607Medium· 6.1
1w ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML…

▾ SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.26%via NVD
CVE-2026-77239High· 8.1
1w ago

WACRM is a self-hostable CRM template for WhatsApp

WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes authenticate account viewers but do not enforce the agent role before using a service-role database client that bypa…

▾ TwilightArnasDon · wacrmEPSS 0.53%via NVD
CVE-2026-63406Medium· 5.9PoC
1w ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…

▾ Twilightanycable · github.com/anycable/anycableEPSS 0.30%via NVD
CVE-2026-63405Medium· 5.9PoC
1w ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…

▾ Twilightanycable · github.com/anycable/anycableEPSS 0.21%via NVD
CVE-2026-63349High· 7.0⚖ disputed
1w ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…

▾ Twilightagronholm · anyioEPSS 0.11%via NVD
CVE-2026-61833High· 8.1PoC
1w ago

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…

▾ Midnightproject-zot · zotEPSS 0.51%via NVD
CVE-2026-61548High· 8.1
1w ago

Rsyslog is a rocket-fast system for log processing

Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] st…

▾ Twilightrsyslog · rsyslogEPSS 0.94%via NVD
CVE-2026-55556High· 8.2PoC
1w ago

Rsyslog is a rocket-fast system for log processing

Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_auth_header function in contrib/imhttp/imhttp.c allocates a zero-byte heap buffer with calloc(0, len) when an HTTP Basic…

▾ Midnightrsyslog · rsyslogEPSS 0.85%via NVD
CVE-2026-46655High· 7.8PoC
1w ago

virtio-win provides Windows paravirtualized drivers for QEMU and KVM

virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*]…

▾ Midnightvirtio-win · kvm-guest-drivers-windowsEPSS 0.18%via NVD
CVE-2026-93533Medium· 6.3PoC
1w ago

A vulnerability was determined in spatie Scotty up to 1.4.4

A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler…

▾ Twilightspatie · ScottyEPSS 1.4%via NVD
CVE-2026-85478Low· 3.5
1w ago

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication

A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical debug interface without requiring authentication. An attacker with physical access could interrupt the normal boot p…

▾ SunlitCareCam · HMT.CM2507 FirmwareEPSS 0.22%via NVD
CVE-2026-44639Low· 3.7PoC
1w ago

NanoMQ is an MQTT broker

NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c uses property_append() to walk the entire linked list for each property added by decode_buf_properties(). A remote un…

▾ Twilightnanomq · nanomqEPSS 0.44%via NVD
CVEs tagged “cve.org” — page 118 · VulnSea