VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15876 CVEsRSS

CVE-2026-92773High· 7.1
1w ago

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and sup…

▾ Twilighttriggerdotdev · trigger.devEPSS 0.32%via NVD
CVE-2026-92765Medium· 6.5PoC
1w ago

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to r…

▾ Twilightarcherysec · archerysecEPSS 0.45%via NVD
CVE-2026-92780High· 8.8PoC
1w ago

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator acc…

▾ Midnightdidi · KnowStreamingEPSS 0.52%via NVD
CVE-2026-92776High· 8.1PoC
1w ago

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated …

▾ Midnightrequarks · Wiki.jsEPSS 0.45%via NVD
CVE-2026-92772High· 7.1PoC
1w ago

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary prope…

▾ MidnightLeantime · leantimeEPSS 0.53%via NVD
CVE-2026-92782High· 8.1PoC
1w ago

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, a…

▾ Midnightchroma-core · chromaEPSS 0.45%via NVD
CVE-2026-92778Medium· 5.4
1w ago

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election schedul…

▾ Sunlityahoo · CMAKEPSS 0.44%via NVD
CVE-2026-92783High· 8.1PoC
1w ago

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legiti…

▾ Midnightyeti-platform · yetiEPSS 0.50%via NVD
CVE-2026-92781Medium· 6.3PoC
1w ago

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview lin…

▾ TwilightBuilderIO · @builder.io/sdk-reactEPSS 0.36%via NVD
CVE-2026-92779High· 7.6
1w ago

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with bindin…

▾ TwilightBuilderIO · @builder.io/sdk-reactEPSS 0.49%via NVD
CVE-2026-92788High· 8.8
1w ago

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against oth…

▾ Twilightcoze-dev · coze-studioEPSS 0.52%via NVD
CVE-2026-92785High· 8.1PoC
1w ago

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending…

▾ MidnightAngel-ML · angelEPSS 0.61%via NVD
CVE-2026-92784High· 7.5
1w ago

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code

@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source code. Attackers controlling the data provider can inject malicious JavaScript through crafted JSON property names that …

▾ Twilightrefinedev · @refinedev/inferencerEPSS 0.48%via NVD
CVE-2026-92789Medium· 6.5
1w ago

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects

Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after following HTTP redirects. Attackers with lookup table or event notification permissions can craft allowlisted endpoi…

▾ SunlitGraylog2 · graylog2-serverEPSS 0.41%via NVD
CVE-2026-92787Critical· 9.8PoC
1w ago

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value

Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain …

▾ Abyssalfeast-dev · feastEPSS 0.70%via NVD
CVE-2026-92786High· 7.8
1w ago

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction

LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node referenc…

▾ Twilightlightgbm-org · LightGBMEPSS 0.19%via NVD
CVE-2026-92792High· 7.5PoC
1w ago

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally

OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing a test_purpose key, causing the FallbackVerifier to execute unconditionally. Attackers can bypass attestation verific…

▾ MidnightOpenNHP · opennhpEPSS 0.60%via NVD
CVE-2026-92791High· 7.5PoC
1w ago

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root

Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated attackers to traverse outside the configured storage root. Attackers can use percent-encoded parent-directory segments i…

▾ Midnightuber · krakenEPSS 0.61%via NVD
CVE-2026-92790Medium· 6.5PoC
1w ago

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting

Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper to recover and return a continue action that bypasses AI token rate limiting. Unauthenticated attackers can craft a ma…

▾ Twilighthigress-group · higressEPSS 0.52%via NVD
CVE-2026-92795Medium· 6.5PoC
1w ago

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services

Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticated users to make the backend fetch internal services. Attackers can construct plugin requests to access cloud metadata…

▾ Twilightcoze-dev · coze-studioEPSS 0.41%via NVD
CVE-2026-92794High· 7.5
1w ago

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled

OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete documen…

▾ TwilightOpenSignLabs · OpenSignEPSS 0.59%via NVD
CVE-2026-92793High· 8.1
1w ago

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter

GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated users to bypass permission checks by appending a query parameter. Attackers can append a query string containing the adm…

▾ TwilightGoAdminGroup · go-adminEPSS 0.45%via NVD
CVE-2026-92802Medium· 4.3
1w ago

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission

kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing guests to create boards despite lacking board:create permission. Attackers can bypass authorization checks by using t…

▾ Sunlitkanbn · kanEPSS 0.37%via NVD
CVE-2026-92801High· 8.8
1w ago

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks

cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactive card callbacks. Attackers can dispatch agent commands by triggering card actions in admitted chats, bypassing the p…

▾ Twilightchenhg5 · cc-connectEPSS 0.55%via NVD
CVE-2026-92796High· 8.8PoC
1w ago

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements a…

▾ Midnightmanticoresoftware · Manticore SearchEPSS 0.52%via NVD
CVE-2026-92804High· 7.1
1w ago

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests …

▾ TwilightNangoHQ · NangoEPSS 0.37%via NVD
CVE-2026-92803Medium· 5.3PoC
1w ago

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files

LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated access to translated files. Attackers can bypass API key requirements and abuse ban lists to download files without auth…

▾ TwilightLibreTranslate · LibreTranslateEPSS 0.53%via NVD
CVE-2026-92800Medium· 6.8PoC
1w ago

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket s…

▾ Twilightsuitenumerique · DocsEPSS 0.41%via NVD
CVE-2026-92809Medium· 4.3PoC
1w ago

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer

PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for …

▾ TwilightPrestaShop · psgdprEPSS 0.34%via NVD
CVE-2026-92806High· 8.1PoC
1w ago

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler

phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitr…

▾ MidnightphpList · phpListEPSS 0.26%via NVD
CVEs tagged “cve.org” — page 168 · VulnSea