VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15880 CVEsRSS

CVE-2026-69147Medium· 6.5PoC
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

▾ Twilightvllm-project · vllmEPSS 0.55%via NVD
CVE-2026-92604High· 8.1PoC
1w ago

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths

Scirius through 3.8.0 contains an arbitrary file write vulnerability in the PCAP filestore upload endpoint that allows default User role users to write attacker-controlled JSON content to filesystem paths. Attackers can supply path trave…

▾ MidnightStamusNetworks · sciriusEPSS 0.58%via NVD
CVE-2026-84397Medium· 5.4
1w ago

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields

Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in …

▾ SunlitAdobe · Adobe Experience Manager as a Cloud ServiceEPSS 0.63%via NVD
CVE-2026-92406High· 7.3PoC
1w ago

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0

A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an unknown function of the file /admins/assessments/databank/btn_functions.php?action=add. Performing a manipulation of the argum…

▾ MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.43%via NVD
CVE-2026-88593Medium· 6.1PoC
1w ago

kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint

kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templat…

▾ TwilightEPSS 0.25%via NVD
CVE-2026-92405High· 7.3PoC
1w ago

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0

A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected element is an unknown function of the file /index.php. Such manipulation of the argument Username leads to sql injection. The …

▾ MidnightSourceCodester · Inventory and Monitoring SystemEPSS 0.43%via NVD
CVE-2026-42784High· 7.4
1w ago

A flaw was found in sequoia-openpgp

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an at…

▾ TwilightRed Hat · rust-podman-sequoia-mainEPSS 0.20%via NVD
CVE-2026-92398Critical· 9.1PoC
1w ago

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Nam…

▾ AbyssalRuijie · RG-EW3000GXEPSS 3.2%via NVD
CVE-2026-92602High· 7.1PoC
1w ago

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController

TDuck survey form through version 5.3 fails to validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can attach webhooks to other users' forms and exfiltrate submissions to arbitrary exter…

▾ MidnightTDuckCloud · tduck-survey-formEPSS 0.40%via NVD
CVE-2026-92601Medium· 6.5PoC
1w ago

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods

Guns through 8.3.5 contains an improper access control vulnerability in SysNoticeController where requiredPermission defaults to false and is not overridden by any action methods. Authenticated users without assigned roles can exploit th…

▾ Twilightstylefeng · GunsEPSS 0.39%via NVD
CVE-2026-92600Medium· 6.5
1w ago

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC validation …

Guns through 8.3.5 contains an information disclosure vulnerability in SysUserController where /sysUser/detail and /sysUser/page endpoints omit requiredPermission configuration, causing the permission interceptor to skip RBAC validation …

▾ Sunlitstylefeng · GunsEPSS 0.42%via NVD
CVE-2026-92603Medium· 6.5PoC
1w ago

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements

ContiNew Admin through 4.1.0 contains an authorization bypass vulnerability in the personal message delete endpoint that allows authenticated users to delete other users' messages and announcements. Attackers can supply arbitrary message…

▾ Twilightcontinew-org · continew-adminEPSS 0.47%via NVD
CVE-2026-71179High· 7.3
1w ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentiall…

▾ Twilightdell · update_package_frameworkEPSS 0.59%via NVD
CVE-2026-59974High· 7.8PoC
1w ago

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages

Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.14.0, stanza.resources.common.unzip in stanza/resources/common.py passes downloaded model and resource …

▾ Midnightstanfordnlp · stanzaEPSS 0.40%via NVD
CVE-2026-59944Medium· 6.1
1w ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates litera…

▾ Sunlitcomposer · composerEPSS 0.32%via NVD
CVE-2026-71180High· 8.2
1w ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

▾ Twilightdell · update_package_frameworkEPSS 0.15%via NVD
CVE-2026-92399High· 7.3PoC
1w ago

A vulnerability was determined in GPAC 26.07.0

A vulnerability was determined in GPAC 26.07.0. This affects the function rmt_client_handle_ws_frame of the file src/utils/rmt_ws.c of the component WebSocket Handler. Executing a manipulation of the argument payload_size can lead to hea…

▾ MidnightEPSS 0.69%via NVD
CVE-2026-69200Low· 3.7PoC
1w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to node-opcua-client 2.145.0, the internal fieldsToJson method in packages/node-opcua-client/source/alarms_and_conditions/client_alarm.ts directly assigns unsanitiz…

▾ Twilightnode-opcua · node-opcuaEPSS 0.35%via NVD
CVE-2026-71182Low· 3.0
1w ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabilit…

▾ Sunlitdell · update_package_frameworkEPSS 0.15%via NVD
CVE-2026-71181Low· 3.0
1w ago

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabilit…

▾ Sunlitdell · update_package_frameworkEPSS 0.15%via NVD
CVE-2026-85732Medium· 4.7PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …

▾ Twilightoras-project · oras-goEPSS 0.35%via NVD
CVE-2026-86358Medium· 6.5
1w ago

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability

Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote exe…

▾ Sunlitdell · update_package_frameworkEPSS 0.41%via NVD
CVE-2026-85731High· 8.8PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…

▾ Midnightoras-project · oras-goEPSS 0.63%via NVD
CVE-2026-86359High· 8.5
1w ago

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability

Dell Repository Manager, versions prior to 3.5.2, contains an Incorrect Default Permissions vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

▾ TwilightDell · Repository ManagerEPSS 0.32%via NVD
CVE-2026-84993Medium· 6.5
1w ago

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an orderBy clause but does not validate its direction value…

▾ Sunlitmikro-orm · mikro-ormEPSS 0.51%via NVD
CVE-2026-92401High· 7.3
1w ago

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd

A vulnerability was identified in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affects the function top.upstudy.crm.utils.LoginUserUtil.releaseUserIdFromCookie. The manipulation leads to improper aut…

▾ TwilightChangeWeDer · crmEPSS 0.69%via NVD
CVE-2026-85385Critical· 9.6
1w ago

Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchang…

Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchang…

▾ Midnightconcretecms · concrete_cmsEPSS 0.50%via NVD
CVE-2026-85386Medium· 6.1
1w ago

Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question

Concrete CMS before 9.5.4 did not sanitize XML and XSLT documents uploaded through a public Form Block file-upload question. Plain XML uploads were validated by file extension only and stored as publicly accessible files that were served…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-57173Medium· 6.5
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURA…

▾ Sunlitvllm-project · vllmEPSS 0.69%via NVD
CVE-2026-85756High· 7.5
1w ago

SSH.NET is a Secure Shell (SSH) library for .NET

SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into the command used to run scp on the server, and the default RemotePathTransformation.DoubleQuote transformation cannot…

▾ Twilightsshnet · SSH.NETEPSS 0.62%via NVD
CVEs tagged “cve.org” — page 172 · VulnSea