VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15465 CVEsRSS

CVE-2026-50547High· 7.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and i…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.46%via NVD
CVE-2026-33639High· 7.2
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for …

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.40%via NVD
CVE-2026-49850High· 7.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POS…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.33%via NVD
CVE-2026-100230Medium· 5.3
2d ago

Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is writt…

Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is writt…

▾ Sunlitinput-leap · Input LeapEPSS 0.65%via NVD
CVE-2026-42324High· 7.2PoC
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The store…

▾ MidnightPiwigo · PiwigoEPSS 0.92%via NVD
CVE-2026-62262Critical· 9.1
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then o…

▾ MidnightPiwigo · PiwigoEPSS 0.30%via NVD
CVE-2026-42323High· 7.2
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager f…

▾ TwilightPiwigo · PiwigoEPSS 0.37%via NVD
CVE-2026-44642High· 8.1PoC
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_mag…

▾ MidnightPiwigo · PiwigoEPSS 1.3%via NVD
CVE-2026-42322Critical· 9.1
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo whe…

▾ MidnightPiwigo · PiwigoEPSS 0.53%via NVD
CVE-2026-85289Medium· 6.5PoC
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.17%via NVD
CVE-2026-67236High· 8.2
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly, Secure, SameS…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.12%via NVD
CVE-2026-85293Medium· 4.8PoC
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.22%via NVD
CVE-2026-92161Critical· 9.8
2d ago

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before …

▾ Midnightfof · fof/oauthEPSS 0.27%via NVD
CVE-2026-84862High· 7.2
2d ago

IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store

IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticated attacker could exploit this vulnerability to execute arbitrary code on the affected system.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.37%via NVD
CVE-2026-88389None
2d ago

Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c

Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Crafted raw/binary string input can cause the lexer to pass a NULL iterator target to jsvLockAgain(). In RELEASE/NO_ASS…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-93306High· 7.1
2d ago

IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface

IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the ASMI web interface. An unauthenticated attacker on the managem…

▾ TwilightIBM · Server FirmwareEPSS 0.18%via NVD
CVE-2026-84882High· 7.5
2d ago

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component

IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.33%via NVD
CVE-2026-93030Medium· 6.5
2d ago

FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.

FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity injection flaw.

▾ SunlitIBM · IBM Financial Transaction Manager (FTM) for Redhat OpenShiftEPSS 0.28%via NVD
CVE-2026-96812High· 8.8
2d ago

Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achi…

Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73cf844f on Linux platforms with CUSE enabled allows a local attacker with container image deployment privileges to achi…

▾ TwilightGoogle · gVisorEPSS 0.10%via NVD
CVE-2026-97866Medium· 5.6PoC
2d ago

A weakness has been identified in Zhonglun CloudPOS 3.0

A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of the file Program.cs of the component Automatic Update. Executing a manipulation of the argument version/url/packagekey…

▾ TwilightZhonglun · CloudPOSEPSS 0.26%via NVD
CVE-2026-100071None
2d ago

In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on device setup failure hsr_dev_finalize() can fail after a lower-device RX handler has already been registered (slave A is added before t…

In the Linux kernel, the following vulnerability has been resolved: net: hsr: free learned nodes on device setup failure hsr_dev_finalize() can fail after a lower-device RX handler has already been registered (slave A is added before t…

▾ SunlitLinux · LinuxEPSS 0.16%via NVD
CVE-2026-100070None
2d ago

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP string is shor…

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: rewind offset when NAT shrinks the packet sashiko says: If map_addr() changes the packet length, such as when the public NAT IP string is shor…

▾ SunlitLinux · LinuxEPSS 0.17%via NVD
CVE-2026-100075Critical· 9.8
2d ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA c…

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA c…

▾ MidnightLinux · LinuxEPSS 0.42%via NVD
CVE-2026-100073None
2d ago

In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Commit 95ad8ee45cdb ("ext4: correct the reserved credits for extent conversion") was correct to note that we need to re…

In the Linux kernel, the following vulnerability has been resolved: ext4: fix transaction overflow during writeback Commit 95ad8ee45cdb ("ext4: correct the reserved credits for extent conversion") was correct to note that we need to re…

▾ SunlitLinux · LinuxEPSS 0.14%via NVD
CVE-2026-100072None
2d ago

In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() The acpi_get_first_physical_node() usage in acpi_platform_fill_resource() and acpi_create_platform_device() is genera…

In the Linux kernel, the following vulnerability has been resolved: ACPI: platform: Use acpi_bus_get_primary_device() The acpi_get_first_physical_node() usage in acpi_platform_fill_resource() and acpi_create_platform_device() is genera…

▾ SunlitLinux · LinuxEPSS 0.14%via NVD
CVE-2026-98160None
2d ago

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_…

In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() padapter->HalData is allocated via vzalloc(), but incorrectly freed using kfree() in the rtw_…

▾ SunlitLinux · LinuxEPSS 0.17%via NVD
CVE-2026-100077None
2d ago

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit During recovery, it is not safe to retire the hung submit before we recover the GPU

In the Linux kernel, the following vulnerability has been resolved: drm/msm: Recover HW before retire hung submit During recovery, it is not safe to retire the hung submit before we recover the GPU. Retiring the submit triggers BO free…

▾ SunlitLinux · LinuxEPSS 0.15%via NVD
CVE-2026-100074None
2d ago

In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUNT is not marked as a unique field, while it should be

In the Linux kernel, the following vulnerability has been resolved: bpf: Mark bpf_refcount field as unique BPF_REFCOUNT is not marked as a unique field, while it should be. Fix this oversight.

▾ SunlitLinux · LinuxEPSS 0.15%via NVD
CVE-2026-100079None
2d ago

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on teardown ucsi_register() creates per-instance debugfs entries, but ucsi_unregister() keeps them around until ucsi_destr…

In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: unregister debugfs entries on teardown ucsi_register() creates per-instance debugfs entries, but ucsi_unregister() keeps them around until ucsi_destr…

▾ SunlitLinux · LinuxEPSS 0.16%via NVD
CVE-2026-100078None
2d ago

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to function The first argument to iwl_mei_write_cyclic_buf() should be the cldev but the q_head pointer is passed instead

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mei: pass correct argument to function The first argument to iwl_mei_write_cyclic_buf() should be the cldev but the q_head pointer is passed instead. Fi…

▾ SunlitLinux · LinuxEPSS 0.16%via NVD
CVEs tagged “cve.org” — page 19 · VulnSea