VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15830 CVEsRSS

CVE-2026-54612High· 8.8
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file …

▾ Twilightgivanz · VvvebEPSS 0.76%via NVD
CVE-2026-54608High· 7.1PoC
1w ago

MythicalDash is a Pterodactyl client area

MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/System/Gateways/Stripe.php creates a pending row in mythicaldash_stripe_payments before Stripe checkout succeeds and embed…

▾ MidnightMythicalLTD · MythicalDashEPSS 0.20%via NVD
CVE-2026-54520High· 8.1PoC
1w ago

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, the executeStep file-step implementation in backend/src/agents/executor.js passes the user-controlled step.…

▾ MidnightvmDeshpande · ai-agent-automationEPSS 0.49%via NVD
CVE-2026-54519High· 8.8PoC
1w ago

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability

AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior to 0.9.1, backend/src/controllers/memory.controller.js authenticates requests but listMemories, deleteMemory, and cle…

▾ MidnightvmDeshpande · ai-agent-automationEPSS 0.52%via NVD
CVE-2026-54507High· 8.4
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, the oEmbedProxy() handler in admin/controller/editor/editor.php accepts an attacker-controlled url parameter and pa…

▾ Twilightgivanz · VvvebEPSS 0.45%via NVD
CVE-2026-54506High· 7.6PoC
1w ago

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5, app/controller/user/profile.php accepts the user[bio] field and passes stored content through sanitizeHTML() in sys…

▾ Midnightgivanz · VvvebEPSS 0.31%via NVD
CVE-2026-54343High· 8.7
1w ago

Frappe Learning Management System (LMS) is a learning system that helps users structure their content

Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.52.1, a remote attacker can request a traversal path handled by SCORMRenderer.render in lms/page_renderers.py. The …

▾ Twilightfrappe · lmsEPSS 0.68%via NVD
CVE-2026-53557High· 7.7
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated user can supply a crafted sheet["tableName"] value in the Excel datasource configuration submitted through POST /api/v1/…

▾ Twilightdataease · SQLBotEPSS 0.34%via NVD
CVE-2026-53556Medium· 6.0PoC
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/previewData endpoint in backend/apps/datasource/crud/datasource.py incorporates the client-controlled table_n…

▾ Twilightdataease · SQLBotEPSS 0.48%via NVD
CVE-2026-53555Medium· 5.1PoC
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated uploader can submit an image/svg+xml assistant UI logo through PATCH /api/v1/system/assistant/ui, and SQLBot stores the …

▾ Twilightdataease · SQLBotEPSS 0.48%via NVD
CVE-2026-53554High· 7.3PoC
1w ago

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/datasource/parseExcel endpoint in backend/apps/datasource/api/datasource.py uses attacker-controlled multipart filename …

▾ Midnightdataease · SQLBotEPSS 0.41%via NVD
CVE-2026-53534High· 7.5
1w ago

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries

JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef's built-in HTTP server is enabled, the GET /better-bibtex/cayw endpoint accepts an external command query parameter a…

▾ TwilightJabRef · jabrefEPSS 0.45%via NVD
CVE-2026-50291Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to versions 3.0.16.0 and 3.1.11.0, processing a crafted BMP file through oiiotool or an application l…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-16750Medium· 5.3
1w ago

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, …

The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of data due to missing authorization checks in mvl_ajax_dealer_load_cars() function in all versions up to, and including, …

▾ Sunlitstylemix · Motors – Car Dealership & Classified Listings PluginEPSS 0.24%via NVD
CVE-2026-16582Medium· 5.3
1w ago

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 2.4.5. This is due to the plugin accepting a client-supplied package-…

▾ Sunlitmelograno · Booking for Appointments and Events Calendar – AmeliaEPSS 0.23%via NVD
CVE-2026-14311Medium· 5.4
1w ago

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to…

The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and modification of data due to a missing ownership verification on /users/customers/<id> endpoint in all versions up to…

▾ Sunlitmelograno · Booking for Appointments and Events Calendar – AmeliaEPSS 0.17%via NVD
CVE-2026-93426High· 8.5PoC
1w ago

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL

SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in fi…

▾ MidnightSigNoz · signozEPSS 0.50%via NVD
CVE-2026-73639Critical· 9.1
1w ago

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creat…

Imager::File::PNG versions from 1.003 before 1.004 for Perl write past the end of the row buffer reading a PNG with a tRNS transparency chunk in read_direct8. With a tRNS chunk, read_direct8() adds an alpha channel to the image it creat…

▾ MidnightEPSS 0.70%via NVD
CVE-2026-73638Medium· 6.2
1w ago

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the E…

Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_ifd. tiff_load_ifd() validates an IFD entry's data by checking that `entry->offset + entry->size` stays within the E…

▾ SunlitEPSS 0.19%via NVD
CVE-2026-93395Medium· 5.3
1w ago

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix

A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when processing BSON data with a zero-length prefix. The function reads a 32-bit document length from the input buffer but doe…

▾ Sunlitmongodb · c_driverEPSS 0.40%via NVD
CVE-2026-93394Low· 3.7
1w ago

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message

A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and transmit the client proof even when a nonce mismatch was detected in the server's first message. An unauthorized par…

▾ Sunlitmongodb · c_driverEPSS 0.32%via NVD
CVE-2026-93393High· 8.1
1w ago

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend

A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platform TLS backend. A remote endpoint that the client connects to can cause the driver to write uncontrolled data outsid…

▾ TwilightMongoDB Inc. · C DriverEPSS 0.47%via NVD
CVE-2026-93387Medium· 4.3⚖ disputed
1w ago

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-93386Medium· 5.4
1w ago

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-93385Medium· 6.5
1w ago

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page

Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.31%via NVD
CVE-2026-93384Low· 3.7
1w ago

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic

Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to bypass system access restrictions via crafted network traffic. (Chromium security sev…

▾ Sunlitgoogle · chromeEPSS 0.24%via NVD
CVE-2026-93383Medium· 4.3
1w ago

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page

Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-93382High· 8.8
1w ago

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page

Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.37%via NVD
CVE-2026-93381High· 8.8
1w ago

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file

Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security s…

▾ Twilightgoogle · chromeEPSS 0.39%via NVD
CVE-2026-93380Low· 3.1
1w ago

Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page

Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass system access restrictions via a crafted HTML page. (Chrom…

▾ Sunlitgoogle · chromeEPSS 0.20%via NVD
CVEs tagged “cve.org” — page 132 · VulnSea