VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15873 CVEsRSS

CVE-2026-81476High· 8.1
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could …

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 1.2%via NVD
CVE-2026-81480High· 7.2
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.62%via NVD
CVE-2026-92611Medium· 4.8
1w ago

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

In Eclipse Ankaios versions 0.6.0 to before 1.0.4, `LogRule::matches` in the agent control-interface authorizer stops at the first wildcard pattern in a single rule instead of evaluating later entries, which can cause deny `LogRule` entr…

▾ SunlitEclipse Foundation · Eclipse AnkaiosEPSS 0.30%via NVD
CVE-2026-66269High· 7.3
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability. An unauthenticated attacker with remote access could potential…

▾ TwilightDell · Dell OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.37%via NVD
CVE-2026-92903High· 8.2
1w ago

Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries

Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be interpolated into SQL strings that are executed as multi-statement queries. An attacker who is able to supply a maliciou…

▾ TwilightSnowflake · snowflake-cliEPSS 0.19%via NVD
CVE-2026-81474High· 7.8
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of priv…

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.15%via NVD
CVE-2026-81438Low· 3.7
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leadi…

▾ SunlitDell · Dell OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.18%via NVD
CVE-2026-92893Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible inventory API

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.28%via NVD
CVE-2026-81439Low· 3.7
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechani…

▾ SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.19%via NVD
CVE-2026-78428High· 8.0
1w ago

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving another user's authenticated session when multiple SSO login attempts occur concurrently

▾ Twilightgo · neuvectorEPSS 0.32%via NVD
CVE-2026-78426Low· 3.7
1w ago

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field

The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding a valid JWT that has not expired, but was logged out of NeuVector, can continue using the non-expired token with equ…

▾ Sunlitgo · neuvectorEPSS 0.19%via NVD
CVE-2026-78425High· 7.6
1w ago

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…

Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticketing system, an expenses tool, or anything they legitimately hold an account on can log into their system via SAML SS…

▾ Twilightgo · github.com/neuvector/neuvectorEPSS 0.36%via NVD
CVE-2026-92894Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible override values API

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authent…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.26%via NVD
CVE-2026-78427Medium· 4.3
1w ago

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images

The NeuVector admission webhook silently excludes containers from policy evaluation when their image path matches one of three hardcoded service mesh sidecar images. Since the image path is entirely controlled by the workload author, any…

▾ Sunlitgo · github.com/neuvector/neuvectorEPSS 0.37%via NVD
CVE-2026-50609High· 7.4
1w ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform …

▾ TwilightAcer · System MonitoringEPSS 0.13%via NVD
CVE-2026-50610High· 7.4
1w ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the ser…

▾ TwilightAcer · System MonitoringEPSS 0.13%via NVD
CVE-2026-50608Low· 1.2
1w ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. …

▾ SunlitAcer · System MonitoringEPSS 0.21%via NVD
CVE-2026-15688Critical· 9.2
1w ago

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affe…

Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affe…

▾ MidnightMitsubishi Electric Corporation · GX Works3EPSS 0.12%via NVD
CVE-2026-86320High· 7.8PoC
1w ago

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on…

▾ MidnightRed Hat · flatpak-builderEPSS 0.22%via NVD
CVE-2026-50605High· 7.4
1w ago

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized re…

▾ TwilightAcer · Agent SerivceEPSS 0.13%via NVD
CVE-2026-87831Medium· 4.3
1w ago

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-87829Medium· 4.3
1w ago

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

The Checkout Field Manager (Checkout Manager) for WooCommerce WordPress plugin before 7.9.7 does not properly validate the ownership of an attachment before deleting it, allowing any authenticated user such as a customer to delete arbitr…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-50606Low· 1.2
1w ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumst…

▾ SunlitAcer · System MonitoringEPSS 0.10%via NVD
CVE-2026-50607Low· 2.7
1w ago

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended ne…

▾ SunlitAcer · System MonitoringEPSS 0.43%via NVD
CVE-2026-90982Medium· 5.3
1w ago

@fastify/static is a Fastify plugin that serves static files from a configured root directory

@fastify/static is a Fastify plugin that serves static files from a configured root directory. In versions before 10.1.4, on a case-insensitive filesystem such as Windows or the default macOS volume, a route guard or allowedPath restrict…

▾ Sunlit@fastify/static · @fastify/staticEPSS 0.58%via NVD
CVE-2026-44940Medium· 5.7
1w ago

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely

The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unaut…

▾ SunlitSUSE · rancher-extension-stackstateEPSS 0.22%via NVD
CVE-2026-91017Low· 3.7
1w ago

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers t…

The Robokassa payment gateway for Woocommerce WordPress plugin before 1.8.9 does not verify the authenticity of incoming payment notifications when its non-default deferred-payment feature is enabled, allowing unauthenticated attackers t…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-87963High· 8.6
1w ago

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attacker…

The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before using it in a SQL query, and reads it before WordPress applies its request escaping, allowing unauthenticated attacker…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-86801High· 8.8
1w ago

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploa…

The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress and therefore applies no authentication, capability or nonce check of any kind, and validates only the name of an uploa…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-86707Critical· 9.8
1w ago

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any…

The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any…

▾ MidnightEPSS 0.50%via NVD
CVEs tagged “cve.org” — page 163 · VulnSea