VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15876 CVEsRSS

CVE-2026-92596High· 7.5PoC
1w ago

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list

Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attackers can send a s…

▾ Midnightnodemailer · nodemailerEPSS 0.82%via NVD
CVE-2026-92599High· 7.5
1w ago

joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule

joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to t…

▾ Twilighthapijs · joiEPSS 0.58%via NVD
CVE-2026-61597Medium· 5.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, many djust built-in component template tags (`djust.components.templatetags.*`) render a developer/use…

▾ Sunlitdjust-org · djustEPSS 0.41%via NVD
CVE-2026-61592High· 7.4
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, SSE sessions were keyed solely by a client-chosen `session_id` with no binding to the authenticated us…

▾ Twilightdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61594Critical· 9.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()…

▾ Midnightdjust-org · djustEPSS 0.48%via NVD
CVE-2026-61591High· 8.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, for views that opt into state snapshots, the snapshot `state_json` embedded in the client page was res…

▾ Twilightdjust-org · djustEPSS 0.22%via NVD
CVE-2026-61588Medium· 6.5
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serialized it to the clie…

▾ Sunlitdjust-org · djustEPSS 0.39%via NVD
CVE-2026-61596High· 7.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) was enforced on the…

▾ Twilightdjust-org · djustEPSS 0.33%via NVD
CVE-2025-56565High· 7.6PoC
1w ago

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory

DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, stores sensitive authentication credentials in cleartext within non-volatile memory. The exposed material includes SSH private keys, dynamic DNS passwords, email n…

▾ MidnightEPSS 0.19%via NVD
CVE-2025-56566Medium· 4.6PoC
1w ago

MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage

MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without aut…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-92527Medium· 6.3
1w ago

A vulnerability has been found in chatwoot up to 4.17.1

A vulnerability has been found in chatwoot up to 4.17.1. This impacts an unknown function of the file callbacks_controller.rb of the component Shopify OAuth. The manipulation leads to server-side request forgery. Remote exploitation of t…

▾ SunlitEPSS 0.37%via NVD
CVE-2025-56563Critical· 9.8PoC
1w ago

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0

A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validat…

▾ AbyssalEPSS 0.40%via NVD
CVE-2026-92748High· 8.8PoC
1w ago

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in th…

▾ MidnightBC-SECURITY · EmpireEPSS 0.82%via NVD
CVE-2026-63506High· 8.8PoC
1w ago

Tina is a headless content management system

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…

▾ Midnighttinacms · tinacmsEPSS 0.52%via NVD
CVE-2026-92749High· 8.1
1w ago

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp …

▾ Twilightchaitin · SafeLineEPSS 0.71%via NVD
CVE-2026-92759Medium· 6.5
1w ago

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retriev…

▾ SunlitSecObserve · SecObserveEPSS 0.46%via NVD
CVE-2026-92753High· 7.1PoC
1w ago

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modif…

▾ MidnightPatrowl · PatrowlManagerEPSS 0.38%via NVD
CVE-2026-92750Medium· 6.5
1w ago

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/i…

▾ Sunlitharness · harnessEPSS 0.28%via NVD
CVE-2026-92761High· 8.8PoC
1w ago

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH ke…

▾ Midnightretspen · webvirtcloudEPSS 0.61%via NVD
CVE-2026-92754Medium· 4.3PoC
1w ago

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all use…

▾ TwilightPatrowl · PatrowlManagerEPSS 0.34%via NVD
CVE-2026-92751High· 8.1PoC
1w ago

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints l…

▾ Midnightyahoo · CMAKEPSS 0.26%via NVD
CVE-2026-92760Medium· 6.5PoC
1w ago

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info end…

▾ Twilightshlinkio · shlinkEPSS 0.41%via NVD
CVE-2026-92752High· 8.3PoC
1w ago

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace,…

▾ Midnightmetasfresh · metasfreshEPSS 0.46%via NVD
CVE-2026-92764Medium· 4.3
1w ago

OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships

OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve ev…

▾ Sunlitopencve · opencveEPSS 0.37%via NVD
CVE-2026-92763High· 8.1PoC
1w ago

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security…

▾ Midnightrundeck · rundeckEPSS 0.51%via NVD
CVE-2026-92762High· 8.8PoC
1w ago

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to inv…

▾ Midnightpelican · panelEPSS 0.65%via NVD
CVE-2026-92775Medium· 6.5PoC
1w ago

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img…

▾ Twilightrequarks · Wiki.jsEPSS 0.41%via NVD
CVE-2026-92771Medium· 6.5PoC
1w ago

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue…

▾ Twilighttwentyhq · twentyEPSS 0.44%via NVD
CVE-2026-92770Medium· 6.5PoC
1w ago

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter…

▾ Twilightgoharbor · harborEPSS 0.45%via NVD
CVE-2026-92774Medium· 4.3PoC
1w ago

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve…

▾ Twilightrequarks · Wiki.jsEPSS 0.37%via NVD
CVEs tagged “cve.org” — page 167 · VulnSea