VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15808 CVEsRSS

CVE-2025-33141Medium· 6.5
1w ago

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 006 could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.

▾ SunlitIBM · QRadarEPSS 0.27%via NVD
CVE-2025-15399Critical· 10.0
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from …

▾ MidnightIBM · Common LicensingEPSS 0.18%via NVD
CVE-2026-7006High· 7.3PoC
1w ago

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges …

▾ MidnightSublime HQ Pty Ltd · Sublime Text 4EPSS 0.13%via NVD
CVE-2026-93689Medium· 5.5
1w ago

WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use

WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device control handler that fails to validate the volume context before use. An unprivileged local user can trigger a denial of se…

▾ Sunlitwinfsp · winfspEPSS 0.15%via NVD
CVE-2026-93688High· 7.5
1w ago

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's …

▾ Twilightsgl-project · sglangEPSS 0.72%via NVD
CVE-2026-93687High· 7.5PoC
1w ago

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards

braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attackers can supply deeply nested brace patterns under the character limit to exhaust the call stack and terminate the Nod…

▾ Midnightmicromatch · bracesEPSS 0.74%via NVD
CVE-2026-93690High· 7.5PoC
1w ago

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDot…

▾ Midnightgarycourt · uri-jsEPSS 0.68%via NVD
CVE-2026-81945Medium· 6.6
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer …

▾ SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.58%via NVD
CVE-2026-81942High· 8.8
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without suffic…

▾ TwilightPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 1.9%via NVD
CVE-2026-93531Medium· 4.3PoC
1w ago

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vulnerability affects unknown code. This manipulation causes cross-site request forgery. The attack may be initiated re…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.23%via NVD
CVE-2026-81946Medium· 4.4
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 use MD5-based password hashing, a cryptographic algorithm with known weaknesses. An attacker who obtains the device confi…

▾ SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.17%via NVD
CVE-2026-81943Medium· 6.7
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable …

▾ SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.18%via NVD
CVE-2026-81944High· 7.5
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer …

▾ TwilightPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.71%via NVD
CVE-2026-75031Critical· 9.8
1w ago

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unau…

▾ MidnightInterchange · InterchangeEPSS 0.71%via NVD
CVE-2025-14753High· 7.5
1w ago

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

▾ Twilightibm · cloud_pak_for_dataEPSS 0.46%via NVD
CVE-2026-75883Medium· 6.8
1w ago

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementi…

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementi…

▾ SunlitPPP Project · pppEPSS 0.26%via NVD
CVE-2025-53837Critical· 9.9
1w ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile o…

▾ Midnightxwiki · xwiki-renderingEPSS 0.64%via NVD
CVE-2025-14754High· 8.8
1w ago

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

▾ Twilightibm · cloud_pak_for_dataEPSS 0.44%via NVD
CVE-2026-93685Medium· 5.4
1w ago

A flaw was found in the multicluster-observability-addon

A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensit…

▾ SunlitRed Hat · redhat-user-workloads/multicluster-observability-addon-acm-213EPSS 0.44%via NVD
CVE-2026-93573Medium· 6.5
1w ago

A flaw was found in Netty's HTTP/1.1 decoder

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing …

▾ SunlitRed Hat · netty-codec-httpEPSS 0.58%via NVD
CVE-2026-93506Medium· 6.3
1w ago

A vulnerability was determined in SveltyCMS 0.0.6

A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery.…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-93558High· 7.5PoC
1w ago

A flaw was found in Netty's WebSocketServerExtensionHandler

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unboun…

▾ MidnightRed Hat · netty-codec-httpEPSS 0.79%via NVD
CVE-2026-25684Medium· 4.4
1w ago

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

▾ SunlitZscaler · ZIA File Type ControlEPSS 0.20%via NVD
CVE-2026-93565High· 7.5
1w ago

A flaw was found in Netty RtspDecoder

A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a spe…

▾ TwilightRed Hat · netty-codec-httpEPSS 0.64%via NVD
CVE-2026-93564High· 7.5
1w ago

A flaw was found in Netty

A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a D…

▾ TwilightRed Hat · netty-codec-haproxyEPSS 0.79%via NVD
CVE-2026-93505Low· 3.5PoC
1w ago

A vulnerability was found in SveltyCMS 0.0.6

A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The a…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-93657High· 7.5
1w ago

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the a…

▾ Twilighthickory-dns · hickory-resolverEPSS 0.40%via NVD
CVE-2026-93566Medium· 6.5
1w ago

A flaw was found in Netty

A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker …

▾ SunlitRed Hat · netty-codec-httpEPSS 0.64%via NVD
CVE-2026-10832Medium· 5.9
1w ago

A flaw was found in the DERDecoder class within wildfly-elytron-asn1

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to…

▾ SunlitRed Hat · wildfly-elytron-asn1EPSS 0.42%via NVD
CVE-2026-93659High· 8.1PoC
1w ago

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute …

▾ Midnightconcretecms-community-store · concretecms-community-store/community_storevia NVD
CVEs tagged “cve.org” — page 122 · VulnSea