VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15929 CVEsRSS

CVE-2026-76434Medium· 4.9
1w ago

A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system

A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this …

▾ Sunlitcisco · identity_services_engineEPSS 0.38%via NVD
CVE-2026-76433Medium· 5.3
1w ago

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient vali…

A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient vali…

▾ Sunlitcisco · identity_services_engineEPSS 1.3%via NVD
CVE-2026-76432Medium· 4.9
1w ago

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability…

A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability…

▾ Sunlitcisco · identity_services_engineEPSS 1.2%via NVD
CVE-2026-76431Medium· 4.9
1w ago

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device

A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploi…

▾ Sunlitcisco · identity_services_engineEPSS 1.2%via NVD
CVE-2026-20286Medium· 4.3
1w ago

A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the l…

A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the l…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.36%via NVD
CVE-2026-20285Medium· 4.3
1w ago

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an aff…

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an aff…

▾ SunlitCisco · Cisco Identity Services Engine SoftwareEPSS 0.36%via NVD
CVE-2026-20121Medium· 5.3
1w ago

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

▾ SunlitCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.49%via NVD
CVE-2026-20120Medium· 5.8
1w ago

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthen…

▾ SunlitCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.41%via NVD
CVE-2026-20248Medium· 6.8
1w ago

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the T…

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the T…

▾ SunlitCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.34%via NVD
CVE-2026-20222High· 7.4
1w ago

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device…

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device…

▾ TwilightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.17%via NVD
CVE-2025-43936High· 8.1
1w ago

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability

Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

▾ Twilightdell · objectscaleEPSS 0.48%via NVD
CVE-2026-26947Medium· 6.7
1w ago

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability…

▾ SunlitDell · ECSEPSS 0.15%via NVD
CVE-2026-92385Low· 2.4PoC
1w ago

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0

A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/update_category.php of the component Category Update. The manipulation leads to cross site s…

▾ TwilightSourceCodester · Online Food Ordering SystemEPSS 0.38%via NVD
CVE-2026-76104Medium· 5.5
1w ago

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS

Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability in the OS. A high privileged attacker with remote access could potentially exploit this vulnerability, leading t…

▾ Sunlitdell · objectscaleEPSS 0.36%via NVD
CVE-2026-70416Critical· 10.0
1w ago

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

▾ Midnightdell · objectscaleEPSS 0.85%via NVD
CVE-2026-92615Medium· 6.6
1w ago

A flaw was found in flightctl

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates)…

▾ SunlitRed Hat · flightctlEPSS 0.15%via NVD
CVE-2026-92626High· 7.5
1w ago

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled n…

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled n…

▾ TwilightControl iD · iDSecureEPSS 0.46%via NVD
CVE-2026-92625High· 7.5
1w ago

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…

▾ TwilightControl iD · iDSecureEPSS 0.66%via NVD
CVE-2026-92397Critical· 9.1PoC
1w ago

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads t…

▾ AbyssalRuijie · RG-EW3000GXEPSS 3.2%via NVD
CVE-2026-90999Critical· 9.8
1w ago

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can su…

▾ MidnightFunctional Software, Inc. · Sentry SeerEPSS 0.67%via NVD
CVE-2026-17526High· 7.2
1w ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-19607Medium· 5.3
1w ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-92627Medium· 4.6
1w ago

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

▾ SunlitThe HDF Group · HDF5EPSS 0.23%via NVD
CVE-2026-61595High· 7.7
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

▾ Twilightdjust · djustEPSS 0.39%via NVD
CVE-2025-59953Critical· 9.8PoC
1w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

▾ AbyssalInternLM · lmdeployEPSS 0.80%via NVD
CVE-2026-61593High· 8.1
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …

▾ Twilightdjust · djustEPSS 0.21%via NVD
CVE-2026-92383Medium· 4.3PoC
1w ago

A security vulnerability has been detected in PbootCMS up to 3.2.24

A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Manage…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-82410High· 8.7
1w ago

Pocketbase is an open source web backend written in go

Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal go…

▾ Twilightpocketbase · pocketbaseEPSS 0.58%via NVD
CVE-2025-36591Medium· 4.4
1w ago

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit…

▾ SunlitDell · Elastic Cloud Storage (ECS)EPSS 0.11%via NVD
CVE-2026-89031Medium· 5.4
1w ago

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_pos…

▾ SunlitAdenion · Blog2SocialEPSS 0.30%via NVD
CVEs tagged “cve.org” — page 177 · VulnSea