VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15462 CVEsRSS

CVE-2026-100523Medium· 6.1
yesterday

Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation

Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect…

▾ SunlitCotonti · CotontiEPSS 0.19%via NVD
CVE-2026-100522Medium· 6.1
yesterday

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft malicious links wi…

▾ SunlitCotonti · CotontiEPSS 0.21%via NVD
CVE-2026-100521Medium· 6.1
yesterday

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the high…

▾ SunlitCotonti · CotontiEPSS 0.20%via NVD
CVE-2026-100520High· 8.8
yesterday

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory tra…

▾ Twilightcrivion · LaranodeEPSS 0.94%via NVD
CVE-2026-100505Medium· 4.4
yesterday

Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length

Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can cra…

▾ SunlitNationalSecurityAgency · ghidraEPSS 0.12%via NVD
CVE-2026-100504High· 7.0
yesterday

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific ins…

▾ TwilightNationalSecurityAgency · ghidraEPSS 0.13%via NVD
CVE-2026-100503Low· 3.3
yesterday

Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references

Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 …

▾ SunlitNationalSecurityAgency · ghidraEPSS 0.12%via NVD
CVE-2026-96795High· 8.8
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Pyt…

▾ Twilighthorilla · horilla-hrEPSS 0.30%via NVD
CVE-2026-86066Medium· 5.9
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-reque…

▾ Sunlithorilla · horilla-hrEPSS 0.20%via NVD
CVE-2026-57449High· 7.1
2d ago

Actual is a local-first personal finance tool

Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TO…

▾ Twilightactualbudget · actualEPSS 0.21%via NVD
CVE-2026-88003High· 7.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_ty…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.30%via NVD
CVE-2026-71483High· 8.5
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft …

▾ Twilighthorilla · horilla-hrEPSS 0.27%via NVD
CVE-2026-63432Medium· 6.5
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at /recruitment/get-mail-preview/ and /…

▾ Sunlithorilla · horilla-hrEPSS 0.32%via NVD
CVE-2026-63431Medium· 6.5
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records sel…

▾ Sunlithorilla · horilla-hrEPSS 0.21%via NVD
CVE-2026-100502Medium· 5.0
2d ago

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. At…

▾ Sunlitpawelmalak · flameEPSS 0.29%via NVD
CVE-2026-100501Medium· 6.5
2d ago

Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password

Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit un…

▾ Sunlitpawelmalak · flameEPSS 0.29%via NVD
CVE-2026-100419High· 7.0
2d ago

gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation

gitoxide gix-fs before 0.23.0 contains a path validation bypass vulnerability in the worktree checkout mechanism that allows attackers to escape the worktree directory via symlink manipulation. During forced checkout with overwrite_exist…

▾ TwilightGitoxideLabs · gitoxideEPSS 0.15%via NVD
CVE-2026-100418Medium· 5.3
2d ago

Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction

Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key an…

▾ Sunlitpawelmalak · flameEPSS 0.34%via NVD
CVE-2026-100383Medium· 4.8
2d ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - WikiLam…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - WikiLam…

▾ SunlitWikimedia Foundation · Mediawiki - WikiLambda ExtensionEPSS 0.32%via NVD
CVE-2026-100381Medium· 5.3
2d ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Uploa…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Uploa…

▾ SunlitWikimedia Foundation · Mediawiki - UploadWizard ExtensionEPSS 0.33%via NVD
CVE-2026-92842Medium· 5.9
2d ago

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself

The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a line-break-chars option whose length is tracked separately from the string itself. The filter constructors duplicate t…

▾ SunlitPHP Group · ext-standardEPSS 0.36%via NVD
CVE-2026-100382Critical· 10.0
2d ago

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData…

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Foundation Mediawiki - ExternalData Extension allows OS Command Injection. This issue affects Mediawiki - ExternalData…

▾ MidnightWikimedia Foundation · Mediawiki - ExternalData ExtensionEPSS 0.95%via NVD
CVE-2026-91768Medium· 6.5
2d ago

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address

The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen.allowed_clients matches on a /96 prefix instead of the exact address. An attacker who can source an address sharing …

▾ SunlitPHP Group · PHP-FPMEPSS 0.56%via NVD
CVE-2026-96879Medium· 6.9
2d ago

Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0.

Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0.

▾ SunlitThe Wikimedia Foundation · Mediawiki - FlaggedRevs extensionEPSS 0.25%via NVD
CVE-2026-91769Medium· 4.3
2d ago

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name

PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matches, falls back to the Common Name. RFC 6125 requires the CN to be ignored once the certificate presents any service …

▾ SunlitPHP Group · ext-opensslEPSS 0.14%via NVD
CVE-2026-91767Medium· 6.5
2d ago

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being ver…

php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS server certificate presents a wildcard name whose literal characters are together longer than the hostname being ver…

▾ SunlitPHP Group · ext-opensslEPSS 0.15%via NVD
CVE-2026-91766Medium· 5.9
2d ago

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HT…

When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authorization headers unchanged, even when the redirect target is a different host, a different port, or a downgrade from HT…

▾ SunlitPHP Group · ext-standardEPSS 0.34%via NVD
CVE-2026-91765High· 7.5
2d ago

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit

cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust th…

▾ TwilightPHP Group · ext-soapEPSS 0.52%via NVD
CVE-2026-6103Medium· 4.3PoC
2d ago

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check

phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 octal digits wide and holds values up to 0x1FFFFFFFF, so a size above 0xFFFFFFFF silently wraps. The parser then skips …

▾ TwilightPHP Group · PHPEPSS 0.17%via NVD
CVE-2026-57443High· 7.5
2d ago

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework

SCBE-AETHERMOORE is a geometric AI governance and evaluation framework. Starting in version 4.0.2 and prior to version 4.2.1, the AetherBrowser API server (`scripts/aetherbrowser/api_server.py`) exposes the `POST /api/ops/check-email` en…

▾ Twilightissdandavis · SCBE-AETHERMOOREEPSS 0.57%via NVD
CVEs tagged “cve.org” — page 13 · VulnSea