VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15929 CVEsRSS

CVE-2026-80274High· 7.5
1w ago

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-76163High· 7.5
1w ago

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-61709Medium· 5.3
1w ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

▾ Sunlitopenfga · openfgaEPSS 0.35%via NVD
CVE-2026-19666High· 7.5
1w ago

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

▾ TwilightISC · BIND 9EPSS 0.57%via NVD
CVE-2026-76825High· 8.4
1w ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

▾ Twilightzopefoundation · RestrictedPythonEPSS 0.62%via NVD
CVE-2026-88976Medium· 6.1
1w ago

Plate is a rich-text editor with AI and shadcn/ui

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an app…

▾ Sunlitudecode · plateEPSS 0.34%via NVD
CVE-2026-19033Medium· 6.5
1w ago

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess…

▾ SunlitISC · BIND 9EPSS 0.24%via NVD
CVE-2026-88064High· 8.8
1w ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can regist…

▾ Twilightbackstage · backstageEPSS 0.88%via NVD
CVE-2026-19668Medium· 5.3
1w ago

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the ex…

▾ SunlitISC · BIND 9EPSS 0.47%via NVD
CVE-2026-92366High· 7.3PoC
1w ago

A vulnerability was determined in code-projects Matrimonial System 1.0

A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state…

▾ Midnightcode-projects · Matrimonial SystemEPSS 0.56%via NVD
CVE-2026-77119Medium· 5.9
1w ago

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

▾ SunlitISC · BIND 9EPSS 0.23%via NVD
CVE-2026-75029Medium· 5.3
1w ago

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record)

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can c…

▾ SunlitISC · BIND 9EPSS 0.71%via NVD
CVE-2026-92087High· 8.1
1w ago

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the…

▾ Twilight@fastify/auth · @fastify/authEPSS 0.47%via NVD
CVE-2026-63671High· 8.1PoC
1w ago

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and…

▾ Midnightnuxt-content · mdcEPSS 0.47%via NVD
CVE-2026-77401Medium· 6.8
1w ago

Zope AccessControl provides a general security framework for use in Zope

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map …

▾ Sunlitzopefoundation · AccessControlEPSS 0.47%via NVD
CVE-2026-92380High· 7.3PoC
1w ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-77408Critical· 9.1
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application t…

▾ Midnightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-92395Critical· 9.1
1w ago

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IP…

▾ Midnight@fastify/proxy-addr · @fastify/proxy-addrEPSS 0.33%via NVD
CVE-2026-77407High· 7.0
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection…

▾ Twilightrabbitmq · amqp091-goEPSS 0.13%via NVD
CVE-2026-77406High· 8.2
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

▾ Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77403High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not en…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-92616Medium· 6.8
1w ago

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interfa…

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interfa…

▾ Sunliterror311 · FileRiseEPSS 0.39%via NVD
CVE-2026-77410High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation …

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-92568Medium· 5.4PoC
1w ago

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update …

▾ Twilightmlrun · mlrunEPSS 0.33%via NVD
CVE-2026-92569Medium· 4.3PoC
1w ago

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trig…

▾ Twilightopengoofy · hippo4jEPSS 0.34%via NVD
CVE-2026-92566High· 8.2PoC
1w ago

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers ca…

▾ Midnightdatageartech · datagearEPSS 0.54%via NVD
CVE-2026-92565Medium· 5.3
1w ago

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from pub…

▾ Sunlitlukevella · ralllyEPSS 0.46%via NVD
CVE-2026-92570Medium· 6.5PoC
1w ago

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can ac…

▾ Twilightyogeshojha · rengineEPSS 0.44%via NVD
CVE-2026-92567Medium· 6.5
1w ago

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submi…

▾ SunlitTDuckCloud · tduck-survey-formEPSS 0.42%via NVD
CVE-2026-77404High· 8.7
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters w…

▾ Twilightrabbitmq · amqp091-goEPSS 0.10%via NVD
CVEs tagged “cve.org” — page 178 · VulnSea