VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15830 CVEsRSS

CVE-2026-93379Medium· 4.3
1w ago

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page

Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

▾ Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-93378Low· 3.1
1w ago

Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file

Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.22%via NVD
CVE-2026-93377High· 8.8
1w ago

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page

Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.44%via NVD
CVE-2026-93376Medium· 6.3
1w ago

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program

Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read memory outside the sandbox via a local program. (Chromium security severity: Medium)

▾ Sunlitgoogle · chromeEPSS 0.11%via NVD
CVE-2026-93375High· 8.1
1w ago

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program

Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a local program. (Chromium security severity: High)

▾ Twilightgoogle · chromeEPSS 0.10%via NVD
CVE-2026-93374Critical· 9.6
1w ago

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.41%via NVD
CVE-2026-93373Critical· 9.6
1w ago

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension

Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted Chrome extension. (Chromium security severity: High)

▾ Midnightgoogle · chromeEPSS 0.34%via NVD
CVE-2026-93372Critical· 9.6
1w ago

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

▾ Midnightgoogle · chromeEPSS 0.45%via NVD
CVE-2026-86049High· 7.1
1w ago

Jupyter Server is the backend for Jupyter web applications

Jupyter Server is the backend for Jupyter web applications. Prior to version 2.21.0, the 5xx request logging path in jupyter_server/log.py copies the Referer header into a JSON header block without applying the token scrubbing used for t…

▾ Twilightjupyter-server · jupyter_serverEPSS 0.42%via NVD
CVE-2026-77615High· 8.7PoC
1w ago

Paella Player is a set of libraries to create a multi stream video player

Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability i…

▾ Midnightopencast · opencastEPSS 0.56%via NVD
CVE-2026-77281Medium· 6.5
1w ago

Caddy is an extensible server platform that uses TLS by default

Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-dependent weaknesses affect the handler and placeholder layer. In modules/caddyhttp/rewrite/rewrite.go, Rewrite.Rewrite()…

▾ Sunlitcaddyserver · caddyEPSS 0.49%via NVD
CVE-2026-76154High· 7.3
1w ago

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…

A stored cross-site scripting vulnerability in the Geomap panel's MapLibre base layer allows a user with the Editor role to execute arbitrary JavaScript in another user's session by hosting a malicious style configuration, enabling escal…

▾ TwilightGrafana · Grafana OSSEPSS 0.35%via NVD
CVE-2026-67071Medium· 6.5
1w ago

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values

HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted property values. If a deployment is configured with a secure property that starts with certain non-ASCII characters, the re…

▾ SunlitHCLSoftware · HCL DevOps Deploy / HCL LaunchEPSS 0.38%via NVD
CVE-2026-54907Medium· 5.3
1w ago

Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates

Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy Proxy Manager enables email and password self-registration by default at /api/auth/sign-up/email, allowing an unauth…

▾ Sunlitfuomag9 · caddy-proxy-managerEPSS 0.29%via NVD
CVE-2026-54604Medium· 5.3
1w ago

OpenSlide is a C library for reading whole slide image files

OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes the indirect TIFF tile path in src/openslide-decode-tiff.c and _openslide_tiff_read_tile() to request a full-height d…

▾ Sunlitopenslide · openslideEPSS 0.53%via NVD
CVE-2026-54597High· 8.3PoC
1w ago

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated user with module_support write permission and access to a credential record can perform ti…

▾ Midnightitflow-org · itflowEPSS 0.43%via NVD
CVE-2026-54596High· 8.1PoC
1w ago

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.07, an authenticated Technician or higher with access to at least one client invoice can inject SQL through the…

▾ Midnightitflow-org · itflowEPSS 0.48%via NVD
CVE-2026-54510High· 7.1PoC
1w ago

Speakr is a personal, self-hosted web application designed for transcribing audio recordings

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the csrf_exempt_for_api_tokens() before_request hook in src/app.py calls csrf.exempt(view_func), permanently adding the …

▾ Midnightmurtaza-nasir · speakrEPSS 0.21%via NVD
CVE-2026-54355Medium· 5.3PoC
1w ago

MapServer is a system for developing web-based GIS applications

MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML output for SERVICE=WMS&REQUEST=GetMap&FORMAT=application/openlayers reflects an attacker-controlled X-Forwarded-Host value…

▾ TwilightMapServer · MapServerEPSS 0.50%via NVD
CVE-2026-54354High· 8.2
1w ago

MapServer is a system for developing web-based GIS applications

MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter translation in src/mappostgis.cpp and msPostGISLayerTranslateFilter() treats a filteritem as numeric when CONNECTIONTYPE …

▾ TwilightMapServer · MapServerEPSS 0.68%via NVD
CVE-2026-54339High· 7.7PoC
1w ago

Glean is a self-hosted RSS reader and personal knowledge management tool

Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passes an attacker-supplied feed_url to discover_feed(feed_url), creates a subscription through FeedService.create_subscri…

▾ MidnightLeslieLeung · gleanEPSS 0.47%via NVD
CVE-2026-48977High· 7.7
1w ago

OpenSlide is a C library for reading whole slide image files

OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF fi…

▾ Twilightopenslide · openslideEPSS 0.48%via NVD
CVE-2026-15815High· 8.8
1w ago

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives

Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugin archive can chain relative symbolic link entries to escape the plugin installation directory, writing arbitrary fi…

▾ TwilightGrafana · Grafana OSSEPSS 0.66%via NVD
CVE-2026-54916High· 8.8
1w ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The absence of tests/init.py and the lack of --import-mode=importlib cause pytest prepend import mode to place the tests dire…

▾ Twilightnetbox-community · devicetype-libraryEPSS 0.61%via NVD
CVE-2026-54918Medium· 5.3
1w ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the affected repository revisions, NETBOX_DT_LIBRARY_URL in tests/test_configuration.py is a free-form tracked constant th…

▾ Sunlitnetbox-community · devicetype-libraryEPSS 0.41%via NVD
CVE-2026-52483High· 8.8PoC
1w ago

The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…

The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(WVK.0)b46 allow authenticated users execute arbitrary OS command via concatenated params on a crafted POST request fo…

▾ MidnightEPSS 0.52%via NVD
CVE-2026-50275High· 7.5
1w ago

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforc…

▾ TwilightDataDog · dd-trace-phpEPSS 0.68%via NVD
CVE-2026-50022Medium· 5.8
1w ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v…

▾ SunlitNCEAS · metacatEPSS 0.40%via NVD
CVE-2026-54460Critical· 9.8
1w ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated sess…

▾ Midnightopen-reception · appointment-booking-softwareEPSS 0.70%via NVD
CVE-2026-45143Critical· 9.0
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue a…

▾ Midnightchamilo · chamilo-lmsEPSS 0.49%via NVD
CVEs tagged “cve.org” — page 133 · VulnSea