VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15818 CVEsRSS

CVE-2026-84902Medium· 6.8
1w ago

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elem…

The King Addons for Elementor WordPress plugin before 51.1.81 does not perform an object-level authorization check when importing template content into a page, allowing users with contributor-level access and above to overwrite the Elem…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-84738Critical· 9.1
1w ago

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, le…

The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import features, allowing users with a low-privileged store-management role to upload arbitrary files, including PHP ones, le…

▾ MidnightEPSS 0.82%via NVD
CVE-2026-81810High· 7.2
1w ago

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export…

The All-in-One WP Migration and Backup WordPress plugin before 7.111 does not perform any capability check on several of its AJAX actions, gating them only on an installation-wide secret which it discloses to any user permitted to export…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-81340Low· 3.8
1w ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability checks when updating orders through its REST API, allowing users with the Instructor role to modify any order on the…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-18912High· 7.7
1w ago

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerability, allowing an authenticated technician to execute arbitrary SQL queries through the Reports module.

▾ TwilightZohocorp · ManageEngine DataSecurity PlusEPSS 1.5%via NVD
CVE-2026-18911High· 7.5
1w ago

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an agent authentication bypass, allowing unenrolled agents to send requests without proper authentication.

▾ TwilightZohocorp · ManageEngine DataSecurity PlusEPSS 1.1%via NVD
CVE-2026-17086High· 8.8
1w ago

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input

The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.5.5 via deserialization of untrusted input . This makes it possible …

▾ Twilightshortpixel · ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIFEPSS 0.89%via NVD
CVE-2026-93468High· 7.5
1w ago

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability

The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit Relative Path Traversal to read arbitrary system files.

▾ TwilightHGiga · OAKlouds-bulletin_v3-2.0EPSS 0.68%via NVD
CVE-2026-93371High· 8.3
1w ago

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4

A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NewGenericDownload of the file server/internal/downloaders/generic.go. Such manipulation of the argument params leads t…

▾ Twilightmarcopiovanello · yt-dlp-web-uiEPSS 1.4%via NVD
CVE-2026-93467Critical· 9.8
1w ago

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability

The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.

▾ MidnightHGiga · OAKlouds-custom_page-2.0EPSS 0.91%via NVD
CVE-2026-15650Medium· 6.4
1w ago

The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to insufficient inpu…

The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pointer_menu_item' Block Attribute in all versions up to, and including, 1.5.2 due to insufficient inpu…

▾ Sunlitthemewant · RT Mega Menu – Mega Menu Builder for Elementor & GutenbergEPSS 0.21%via NVD
CVE-2026-14855Medium· 6.4
1w ago

The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping

The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all versions up to, and including, 1.5.1 due to insufficient input sanitization and output escaping. This makes it possib…

▾ Sunlitthemewant · RT Mega Menu – Mega Menu Builder for Elementor & GutenbergEPSS 0.20%via NVD
CVE-2026-92991Medium· 5.4
1w ago

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping

The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in various versions due to insufficient output escaping. This makes it possible for attackers who can compromise the Sigmative…

▾ Sunlitbdthemes · Live Copy Paste for Elementor – Cross Domain Copy Paste & Page DuplicatorEPSS 0.43%via NVD
CVE-2026-93331High· 7.3
1w ago

A vulnerability was identified in GPAC 26.08-DEV

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-77169Medium· 6.5
1w ago

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls

A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed API/REST-only delegated administrators to bypass folder-level authorization controls. The workspace app enables orga…

▾ SunlitNextcloud · Team FoldersEPSS 0.47%via NVD
CVE-2026-68493Low· 3.1
1w ago

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships for a circle they are not a member of.

▾ SunlitNextcloud · ServerEPSS 0.23%via NVD
CVE-2026-93455Medium· 6.5
1w ago

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths

django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff account to read arbitrary page content and stored media paths. Attackers with low-privilege staff credentials can enumer…

▾ Sunlitbatiste · django-page-cmsEPSS 0.45%via NVD
CVE-2026-82982Medium· 4.3
1w ago

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforc…

▾ SunlitNextcloud · ApprovalEPSS 0.33%via NVD
CVE-2026-93456High· 8.2
1w ago

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content

django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing attackers to forge requests that modify page content. Signed-in editors visiting a malicious page can be tricked into…

▾ Twilightbatiste · django-page-cmsEPSS 0.20%via NVD
CVE-2026-93313Medium· 6.3PoC
1w ago

A vulnerability was found in Freedesktop Poppler 26.07.0

A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG2Stream.cc. Performing a manipulation results in integer overflow. The attack can be ini…

▾ TwilightFreedesktop · PopplerEPSS 0.43%via NVD
CVE-2026-77170Medium· 4.3
1w ago

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without validating whether the user owns or has permission to manage the referenced board.

▾ SunlitNextcloud · DeckEPSS 0.27%via NVD
CVE-2026-82985Medium· 6.5
1w ago

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration

The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolders) of the user viewing the album, rather than the album owner's configuration. When an album owner shares a smart alb…

▾ SunlitNextcloud · ServerEPSS 0.38%via NVD
CVE-2026-82980Medium· 6.3
1w ago

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users

Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The DAV plugin resolves files from the absolute request URI without verifying that the path segment matches the authentica…

▾ SunlitNextcloud · Files LockEPSS 0.30%via NVD
CVE-2026-77164Medium· 6.2
1w ago

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote instance is established, and explicitly allows local/private addresses for this request, bypassing Nextcloud's core SSRF p…

▾ SunlitNextcloud · ServerEPSS 0.19%via NVD
CVE-2026-93314Medium· 6.3PoC
1w ago

A vulnerability was determined in Freedesktop Poppler 26.07.0

A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. Executing a manipulation of the argument segCnt can lead to integer overflow. The attac…

▾ TwilightFreedesktop · PopplerEPSS 0.43%via NVD
CVE-2026-93312Medium· 4.3PoC
1w ago

A flaw has been found in Freedesktop Poppler 26.07.0

A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulation causes null pointer dereference. It is possible to initiate the attack remotely. The…

▾ TwilightFreedesktop · PopplerEPSS 0.59%via NVD
CVE-2026-93311Medium· 4.3PoC
1w ago

A vulnerability was detected in Freedesktop Poppler 26.07.0

A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFunction of the file poppler/Function.cc of the component SampledFunction. The manipulation of the argument BitsPerSampl…

▾ TwilightFreedesktop · PopplerEPSS 0.56%via NVD
CVE-2026-79954High· 8.7
1w ago

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path

NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiver selects the Security Association used for SDLS processing solely from the SPI field inside the incoming frame, but…

▾ TwilightNASA · CryptoLibEPSS 0.56%via NVD
CVE-2026-93310Medium· 5.3PoC
1w ago

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collector. The manipulation leads to allocation of resources. Remote exploitation of the attack is possible. The exploit is …

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.70%via NVD
CVE-2026-93308Medium· 4.3PoC
1w ago

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiate…

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.52%via NVD
CVEs tagged “cve.org” — page 129 · VulnSea