VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15461 CVEsRSS

CVE-2026-97885High· 7.3PoC
2d ago

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. T…

▾ Midnightmathurvishal · CloudClassroom-PHP-ProjectEPSS 0.26%via NVD
CVE-2026-67222Medium· 5.9
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, mechanisms/1 applied list_to_atom/1 to every colon-delimited token in an attacker-controlled auth_mechanism value, permanently consuming …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.31%via NVD
CVE-2026-89032High· 7.7
2d ago

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_s…

BerriAI LiteLLM before 1.101.0-rc.1 contains a tenant isolation bypass vulnerability in the semantic cache layer that allows authenticated users to read other tenants' cached responses by exploiting a metadata key mismatch between _get_s…

▾ TwilightBerriAI · litellmEPSS 0.27%via NVD
CVE-2026-67234Low· 2.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term_to_binary/1 on the strict_auth_mechanism or preferred_auth_mechanism atom when clearing the corresponding cookie, producing a …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.56%via NVD
CVE-2026-67230Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the Web STOMP WebSocket handler enforced neither max_frame_size nor login_timeout before authentication, allowing an unauthenticated clie…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.47%via NVD
CVE-2026-67237High· 7.5
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, set_token_auth/2 inserted a bearer token from the Authorization header or access_token cookie into OAuth bootstrap JavaScript without escaping, allowing atta…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.48%via NVD
CVE-2026-66078Low· 2.1
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, protected tag bypass via bulk-delete. dELETE /api/users/:name refuses to delete users tagged protected (rabbitmgmtwmuser:deleteresou…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.36%via NVD
CVE-2026-66071Medium· 6.0
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom exhaustion: OAuth2 JWT tag: scope values. extractscopes/1 parses scopes of the form .tag: and calls rabbitdatacoercio…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.34%via NVD
CVE-2026-100248High· 8.4
2d ago

The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.

The Rattadan Cosmowarp smart contract before 56c6147 can have a comparison to an unintended value of current_admin.

▾ TwilightRattadan · Cosmowarp ContractEPSS 0.40%via NVD
CVE-2026-67241Medium· 4.8
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, AMQP 1.0 management exchange.declare skips alternate-exchange permission check. pUT /exchanges/:name (lines 192-240) checks only configure on the declared ex…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-67223Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance lines but contains conflicting first-fixed versions for the 3.13, 4.0, and 4.1 lines. fill/2 substitutes ${username}…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-97877High· 7.3PoC
2d ago

A vulnerability was determined in zhistaredu StarTraining up to 3.8.1

A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id…

▾ Midnightzhistaredu · StarTrainingEPSS 0.45%via NVD
CVE-2026-67242Medium· 6.3PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, OAuth2 isinteger(Exp) guard skips token-expiry checks for float exp. validatetokenexpiry/1 (lines 208-214) and expirytimestamp/1 (138-144) both guard with 'w…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.46%via NVD
CVE-2026-67409High· 8.2PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS (CWE-252). the JWKS key fetching …

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.49%via NVD
CVE-2026-67415Medium· 5.9PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted attacker-controlled runtime parameter values into non-garbage-collected Erlang atoms before bounding them or checking a…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-97878High· 7.3PoC
2d ago

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be …

▾ Midnightzhistaredu · StarTrainingEPSS 0.63%via NVD
CVE-2026-67413Medium· 6.0
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_jms_topic_exchange plugin's x-jms-topic exchange accepted a client-controlled rjms_erlang_selector binding expression …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-61837Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET /bindings exposes full binding topology to any authenticated AMQP user without resource/management permission checks…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.25%via NVD
CVE-2026-67407Medium· 5.1
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3 and 4.2.9 and 4.1.14 and 4.0.23, Incomplete fix for CVE-2026-44838: escaperegexchar/1 does not escape -, leaving room for an MQTT topic permission bypass. the CVE-2026-…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.25%via NVD
CVE-2026-67226Medium· 6.9PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: PUT /api/users tags list. settags/2 maps rabbitdatacoercion:toatom/1 over the user's tags list. The 20 MB management …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-67410High· 8.2PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200). when OAuth2 authentication is enabled for the RabbitMQ Management UI and the …

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.40%via NVD
CVE-2026-67406Medium· 4.6
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, Shovel does not format state logged by the crash reporter and can leave unencrypted credentials in a crash dump file. the shovel worker gens…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-67227Medium· 5.9
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1, Atom exhaustion: toatom on global-parameter :name. resourceexists/2 (and the PUT/DELETE handlers) call rabbitdatacoercion:toatom/1 on t…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.29%via NVD
CVE-2026-95835Medium· 5.6
2d ago

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

▾ SunlitKovid Goyal · kittyEPSS 0.10%via NVD
CVE-2026-67408High· 7.1PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service. rabbitMQ 4.3.1 with rabbitmqstreammanagement ena…

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.34%via NVD
CVE-2026-91837High· 7.8
2d ago

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedd…

▾ TwilightGNOME · network-manager-iodineEPSS 0.14%via NVD
CVE-2026-67421Medium· 4.5PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAu…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-97879Medium· 5.3PoC
2d ago

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the component api-docs Endpoint. Performing a manipulation results in missing auth…

▾ Twilightzhistaredu · StarTrainingEPSS 0.65%via NVD
CVE-2026-97871High· 7.3PoC
2d ago

A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76

A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to c…

▾ MidnightZhonglun · CloudPosEPSS 0.52%via NVD
CVE-2026-67419High· 7.1PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same t…

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.33%via NVD
CVEs tagged “cve.org” — page 17 · VulnSea