VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15462 CVEsRSS

CVE-2026-17545Medium· 6.9PoC
2d ago

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path

On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM9, LPT1 to LPT9, CONIN$ and CONOUT$ when they appear as a component of a path. An attacker-controlled filename theref…

▾ TwilightPHP Group · PHPEPSS 0.32%via NVD
CVE-2026-10758High· 7.5
2d ago

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type

Esri LERC is an open-source image or raster format which supports rapid encoding and decoding for any pixel type. A Heap based Out-of-Bounds Write via Integer Overflow in LERC versions 4.1.0 and earlier may allow a remote, unauthenticate…

▾ TwilightEsri · LercEPSS 0.33%via NVD
CVE-2026-100417Low· 3.1
2d ago

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileCon…

▾ Sunlitrustdesk · rustdeskEPSS 0.21%via NVD
CVE-2026-100391High· 8.2
2d ago

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter

MediaFlow Proxy through 2.4.9 contains a server-side request forgery vulnerability in the /proxy routes due to missing and incomplete destination validation in the d query parameter. Remote attackers can supply arbitrary internal URLs in…

▾ Twilightmhdzumair · mediaflow-proxyEPSS 0.31%via NVD
CVE-2026-100390High· 7.4
2d ago

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers

Zoraxy versions 3.2.3 through 3.3.4 fail to properly parse IPv6 addresses in the RemoteAddr field when setting forwarded headers. Unauthenticated attackers connecting over IPv6 can supply arbitrary X-Forwarded-For values to spoof their s…

▾ Twilighttobychui · zoraxyEPSS 0.29%via NVD
CVE-2026-100389High· 8.1
2d ago

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions

GestSup versions before 3.2.61 contain a remote code execution vulnerability in the basic IMAP connector's attachment handling that fails to skip blocked file extensions. Unauthenticated attackers can send emails with PHP attachments to …

▾ TwilightGestSup · GestSupEPSS 0.57%via NVD
CVE-2026-100388Medium· 5.4
2d ago

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions …

▾ Sunlitrustdesk · rustdeskEPSS 0.18%via NVD
CVE-2026-100387High· 8.1
2d ago

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory

pgPointcloud through 1.2.5 contains a heap out-of-bounds read vulnerability in dimensional patch WKB deserialization that allows authenticated database users to read adjacent heap memory. Attackers can supply crafted pcpatch values with …

▾ Twilightpgpointcloud · pointcloudEPSS 0.32%via NVD
CVE-2026-100380Medium· 5.3
2d ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Wikibase …

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Wikibase …

▾ SunlitWikimedia Foundation · Mediawiki - Wikibase ExtensionEPSS 0.33%via NVD
CVE-2026-100379Medium· 5.3
2d ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main.

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App allows Accessing/Intercepting/Modifying HTTP Cookies. This issue affects Wikipedia Android App: main.

▾ SunlitWikimedia Foundation · Wikipedia Android AppEPSS 0.32%via NVD
CVE-2026-100378Medium· 5.3
2d ago

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from * before 1.46.1, 1.45.…

Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Mediawiki - Translate Extension: from * before 1.46.1, 1.45.…

▾ SunlitWikimedia Foundation · Mediawiki - Translate ExtensionEPSS 0.27%via NVD
CVE-2026-100377Medium· 6.9
2d ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Excavation. This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha. The issue has been r…

▾ SunlitWikimedia Foundation · Mediawiki - WikiLambda ExtensionEPSS 0.32%via NVD
CVE-2026-100376Medium· 4.8
2d ago

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Te…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - TemplateSandbox Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Te…

▾ SunlitWikimedia Foundation · Mediawiki - TemplateSandbox ExtensionEPSS 0.29%via NVD
CVE-2026-100369High· 8.4
2d ago

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.1…

▾ Twilightalastairlundy · CliInvokeEPSS 0.36%via NVD
CVE-2025-1218Low· 3.4
2d ago

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the …

▾ SunlitPHP Group · ext-mysqlndEPSS 0.18%via NVD
CVE-2025-14181Medium· 6.5PoC
2d ago

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make…

▾ TwilightPHP Group · ext-soapEPSS 0.34%via NVD
CVE-2026-96876Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-96875Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-96878Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-96877Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-93682Medium· 5.8PoC
2d ago

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte d…

▾ TwilightPHP Group · ext-standardEPSS 0.35%via NVD
CVE-2026-5267High· 7.5
2d ago

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service c…

▾ TwilightCiena · Navigator NCSEPSS 0.36%via NVD
CVE-2026-100373Medium· 4.1PoC
2d ago

OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses

OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update Ev…

▾ Twilightopen-metadata · OpenMetadataEPSS 0.26%via NVD
CVE-2026-100372High· 7.2
2d ago

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Atta…

▾ TwilightMacWarrior · clipbucket-v5EPSS 1.1%via NVD
CVE-2026-100368High· 8.4
2d ago

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.…

▾ Twilightalastairlundy · CliInvoke.SpecializationsEPSS 0.58%via NVD
CVE-2026-100310High· 7.0
2d ago

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a dir…

▾ TwilightGNU · libextractorEPSS 0.14%via NVD
CVE-2026-100208High· 7.5
2d ago

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.35%via NVD
CVE-2026-97064Critical· 9.1
2d ago

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emai…

▾ Midnightyzcheng90 · X-SpringBootEPSS 0.30%via NVD
CVE-2026-97060High· 7.2
2d ago

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords …

▾ Twilightyzcheng90 · X-SpringBootEPSS 0.31%via NVD
CVE-2026-100192Medium· 6.5
2d ago

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send ar…

▾ Sunlityzcheng90 · X-SpringBootEPSS 0.32%via NVD
CVEs tagged “cve.org” — page 14 · VulnSea