VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15465 CVEsRSS

CVE-2026-67420Low· 2.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAuth credential refresh retains revoked runtime tags. when an existing AMQP connection refreshes from an OAuth token th…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.24%via NVD
CVE-2026-67225Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol stored the FrameMax value negotiated during the Tune handshake but did not compare it with an inbound frame's declare…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.32%via NVD
CVE-2026-66073Medium· 6.0
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exhaustion via management API node field. pUT /api/queues/:vhost/:name (and the exchanges and bindings endpoints) accepts…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.33%via NVD
CVE-2026-94445High· 8.8
2d ago

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctl…

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctl…

▾ Twilightgolang.org/x/playground · golang.org/x/playgroundEPSS 0.36%via NVD
CVE-2026-67239High· 7.6
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11). lines 102/106/110 render peercertsubject…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.27%via NVD
CVE-2026-67412Medium· 6.0PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policy…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-56724High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked i…

▾ Twilightzammad · zammadEPSS 0.27%via NVD
CVE-2026-100237Medium· 6.1
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects Mediawiki - Thanks Extension: from * befor…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects Mediawiki - Thanks Extension: from * befor…

▾ SunlitThe Wikimedia Foundation · Mediawiki - Thanks ExtensionEPSS 0.15%via NVD
CVE-2026-93363Medium· 4.3
2d ago

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attac…

▾ Sunlitpayloadcms · payloadEPSS 0.18%via NVD
CVE-2026-56723High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket cannot see internal ticket articles through the article listing API. However, the same customer can directly request an …

▾ Twilightzammad · zammadEPSS 0.27%via NVD
CVE-2026-18312Medium· 6.1
2d ago

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL strings and inserts them into the DOM via …

▾ SunlitReadwise · ReaderEPSS 0.19%via NVD
CVE-2026-93364Medium· 4.3
2d ago

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

▾ SunlitBludit · Bludit CMSEPSS 0.19%via NVD
CVE-2026-80432Medium· 6.0
2d ago

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

▾ SunlitKovid Goyal · kittyEPSS 0.12%via NVD
CVE-2026-56729Low· 2.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledge_base.editor in one category can see answer titles and updated_at …

▾ Sunlitzammad · zammadEPSS 0.38%via NVD
CVE-2026-18320Medium· 6.1
2d ago

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration fails to remove script-capable attributes such as event handlers (e.…

▾ SunlitReadwise · ReaderEPSS 0.16%via NVD
CVE-2026-67411Medium· 6.0PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address before th…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.39%via NVD
CVE-2026-18311Medium· 6.1
2d ago

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebVie…

▾ SunlitReadwise · ReaderEPSS 0.16%via NVD
CVE-2026-93365Medium· 6.5
2d ago

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

▾ SunlitBludit · Bludit CMSEPSS 0.21%via NVD
CVE-2026-95834Medium· 4.6
2d ago

Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag_remote_file_…

Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag_remote_file_…

▾ SunlitKovid Goyal · kittyEPSS 0.13%via NVD
CVE-2026-97868Low· 3.5PoC
2d ago

A security vulnerability has been detected in sheshbabu zen up to 1.5.0

A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerouslySetInnerHTML of the file features/notes/NotesEditor.jsx of the component Note Editor. The manipulation leads to cr…

▾ Twilightsheshbabu · zenEPSS 0.19%via NVD
CVE-2026-96874Low· 2.3
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.20%via NVD
CVE-2026-97869Medium· 4.1PoC
2d ago

A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27

A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-a…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-85290Medium· 5.3
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without …

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.24%via NVD
CVE-2026-54790Medium· 6.0
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom…

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.23%via NVD
CVE-2026-39372Medium· 4.9
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads …

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.28%via NVD
CVE-2026-85292Medium· 4.8
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequalit…

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.25%via NVD
CVE-2026-85291Medium· 6.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without…

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.26%via NVD
CVE-2026-85274Medium· 6.5PoC
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.17%via NVD
CVE-2026-39353Critical· 9.1PoC
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an …

▾ AbyssalInvoicePlane · InvoicePlaneEPSS 0.45%via NVD
CVE-2026-97469Medium· 4.3
2d ago

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A maske…

▾ SunlitDALIBO · PostgreSQL AnonymizerEPSS 0.12%via NVD
CVEs tagged “cve.org” — page 18 · VulnSea