VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15808 CVEsRSS

CVE-2026-93658High· 7.0PoC
1w ago

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

▾ Midnightuutils · coreutilsEPSS 0.14%via NVD
CVE-2026-93676Low· 3.2
1w ago

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bu…

▾ SunlitRed Hat · xdg-dbus-proxyEPSS 0.14%via NVD
CVE-2026-93660Medium· 6.5
1w ago

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to…

▾ Sunlitdataease · SQLBotEPSS 0.43%via NVD
CVE-2026-93653Medium· 5.5
1w ago

A denial of service flaw was found in Poppler's Splash backend

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that dr…

▾ SunlitRed Hat · popplerEPSS 0.15%via NVD
CVE-2026-93567High· 7.5
1w ago

A flaw was found in Netty's HTTP/2 codec

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker …

▾ TwilightRed Hat · netty-codec-http2EPSS 0.75%via NVD
CVE-2026-77928Medium· 6.5
1w ago

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitizatio…

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitizatio…

▾ SunlitMacWarrior · clipbucket-v5EPSS 0.42%via NVD
CVE-2026-85511Medium· 4.2
1w ago

A flaw was found in EAP's Elytron

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

▾ SunlitRed Hat · eap8-activemq-artemisEPSS 0.28%via NVD
CVE-2026-77927Medium· 6.5
1w ago

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() s…

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() s…

▾ SunlitMacWarrior · clipbucket-v5EPSS 0.42%via NVD
CVE-2026-77929High· 8.8
1w ago

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload:…

▾ TwilightMacWarrior · clipbucket-v5EPSS 0.94%via NVD
CVE-2026-16512Low· 3.1
1w ago

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2024-56344Medium· 5.9
1w ago

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could explo…

▾ SunlitIBM · Cognos AnalyticsEPSS 0.17%via NVD
CVE-2026-16515Medium· 4.7
1w ago

net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error)

net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rules (do not answer an ICMPv6 error with an ICMPv6 error). It did not check whether the triggering packet's source addr…

▾ Sunlitzephyrproject · zephyrEPSS 0.20%via NVD
CVE-2026-16514Medium· 4.3
1w ago

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one

gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS Announce message, comparing each clock identity against the local one. The loop bound was taken solely from the attac…

▾ Sunlitzephyrproject · zephyrEPSS 0.24%via NVD
CVE-2026-93568High· 7.5
1w ago

A flaw was found in Netty

A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HT…

▾ TwilightRed Hat · netty-codec-http2EPSS 0.77%via NVD
CVE-2025-13882Medium· 5.3
1w ago

IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to …

IBM Sterling Partner Engagement Manager Essentials Edition 6.3.0.0 through 6.3.0.2, and 6.2.4.0 through 6.2.4.4 and IBM Sterling Partner Engagement Manager Standard Edition 6.2.4.0 through 6.2.4.4 could allow an unauthenticated user to …

▾ SunlitIBM · Sterling Partner Engagement Manager Essentials EditionEPSS 0.25%via NVD
CVE-2026-93576High· 7.5
1w ago

A flaw was found in Netty netty-codec-smtp

A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this…

▾ TwilightRed Hat · netty-codec-smtpEPSS 0.46%via NVD
CVE-2025-1350Medium· 5.3
1w ago

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser

IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in f…

▾ SunlitIBM · ControllerEPSS 0.24%via NVD
CVE-2026-93652High· 7.5
1w ago

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause DoS

▾ TwilightD3TN GmbH · µD3TNEPSS 0.55%via NVD
CVE-2026-93569High· 8.2
1w ago

A flaw was found in Netty

A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, …

▾ TwilightRed Hat · netty-codec-http2EPSS 0.70%via NVD
CVE-2026-93560High· 7.5
1w ago

A flaw was found in the Netty STOMP codec

A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite dec…

▾ TwilightRed Hat · netty-codec-stompEPSS 0.58%via NVD
CVE-2026-93019Critical· 9.1PoC
1w ago

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_palette_read. The reader unpacks the two-byte colour map length into a signed short, so a length of 32768 or more beco…

▾ AbyssalEPSS 0.65%via NVD
CVE-2026-93018Medium· 5.5
1w ago

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…

Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes past its colour map in i_gpix_p and i_glin_p. The palette is allocated uninitialised, and only the entries a reader add…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-88623High· 7.5PoC
1w ago

NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read

NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is received, and fopen() is used to open the URL in binary read-only mode. The content is then written to…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-88622High· 8.8PoC
1w ago

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.

▾ MidnightEPSS 1.1%via NVD
CVE-2026-79294Medium· 6.1PoC
1w ago

Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component

Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component

▾ TwilightEPSS 0.51%via NVD
CVE-2026-62282Medium· 6.5PoC
1w ago

OpenCVE is a vulnerability intelligence platform

OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permiss…

▾ Twilightopencve · opencveEPSS 0.42%via NVD
CVE-2026-93504Medium· 6.3PoC
1w ago

A vulnerability has been found in SveltyCMS 0.0.6

A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+server.ts of the component User Attribute Update Endpoint. Such manipulation leads to improper access controls. It is p…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-93588Low· 3.1
1w ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NUL…

▾ SunlitImageMagick · ImageMagickEPSS 0.32%via NVD
CVE-2026-93586Low· 2.9
1w ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a cra…

▾ SunlitImageMagick · ImageMagickEPSS 0.14%via NVD
CVE-2026-93587Low· 3.3
1w ago

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource…

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource…

▾ SunlitImageMagick · ImageMagickEPSS 0.15%via NVD
CVEs tagged “cve.org” — page 123 · VulnSea