VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

16981 CVEsRSS

CVE-2026-66575Medium· 5.3
1w ago

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions.

▾ SunlitKingAddons.com · king-addonsEPSS 0.29%via NVD
CVE-2026-66574Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions.

▾ Sunlitbdthemes · bdthemes-element-pack-liteEPSS 0.22%via NVD
CVE-2026-66573Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetTabsEPSS 0.22%via NVD
CVE-2026-66572Medium· 6.5
1w ago

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions.

▾ SunlitCrocoblock. Jetimpex Inc. · JetBlogEPSS 0.22%via NVD
CVE-2026-66571High· 7.1
1w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Asset CleanUp: Page Speed Booster <= 1.4.0.5 versions.

▾ TwilightGabe Livan · wp-asset-clean-upEPSS 0.13%via NVD
CVE-2026-62108Critical· 9.8
1w ago

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

▾ MidnightminiOrange · headless-single-sign-onEPSS 0.61%via NVD
CVE-2026-62104Critical· 10.0
1w ago

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

▾ Midnightsuperweby · migratico-liteEPSS 0.86%via NVD
CVE-2026-62101Critical· 9.8
1w ago

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

▾ MidnightChris Åkerfeldt Wendel · eduadmin-bookingEPSS 0.61%via NVD
CVE-2026-14850High· 8.8
1w ago

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter

The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker can manipulate this predictable numeric identifier to reset passwords for arbitrary users…

▾ TwilightMobiAPParc · MobiAPParcEPSS 0.29%via NVD
CVE-2026-82723Low· 1.8
1w ago

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of user password digests to readers of the audit store. The audit_log add-on builds each entry's extra_data in AshAuthent…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.18%via NVD
CVE-2026-86522Medium· 6.3
1w ago

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…

Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing newlines or control characters…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.74%via NVD
CVE-2026-82760High· 8.2
1w ago

Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in…

Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API key. AshAuthentication.Base.decode62/1 in…

▾ Twilightteam-alembic · ash_authenticationEPSS 0.74%via NVD
CVE-2026-82759Low· 1.8
1w ago

Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. …

Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audit store to recover the client IP addresses that the audit log add-on's :hash privacy mode is meant to pseudonymise. …

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.14%via NVD
CVE-2026-82685High· 7.6
1w ago

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account

Authorization Bypass Through User-Controlled Key vulnerability in team-alembic AshAuthentication allows an authenticated attacker to overwrite and confirm another user's email address, and so take over that account. A confirmation token …

▾ Twilightteam-alembic · ash_authenticationEPSS 0.66%via NVD
CVE-2026-81632High· 7.2
1w ago

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

▾ Twilightteam-alembic · ash_authentication_phoenixEPSS 0.21%via NVD
CVE-2026-80218High· 7.6
1w ago

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.Sig…

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.Sig…

▾ Twilightteam-alembic · ash_authenticationEPSS 0.64%via NVD
CVE-2026-82761Critical· 9.1
1w ago

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configur…

▾ Midnightteam-alembic · ash_authenticationEPSS 0.56%via NVD
CVE-2026-81637Low· 2.3
1w ago

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticat…

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticat…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.61%via NVD
CVE-2026-78223Medium· 6.9
1w ago

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthenticatio…

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthenticatio…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.44%via NVD
CVE-2026-86533Critical· 9.1
1w ago

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_p…

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_p…

▾ Midnightteam-alembic · ash_authenticationEPSS 0.91%via NVD
CVE-2026-85500Critical· 9.1
1w ago

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.…

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.…

▾ Midnightteam-alembic · ash_authenticationEPSS 0.77%via NVD
CVE-2026-92932Medium· 5.1
1w ago

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] &…

▾ Sunlitmisp · sachertortephpEPSS 0.39%via NVD
CVE-2026-92921Medium· 4.9PoC
1w ago

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force …

▾ Twilightcjbi · admin3EPSS 0.30%via NVD
CVE-2026-92920Medium· 5.4PoC
1w ago

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disab…

▾ Twilightcjbi · admin3EPSS 0.32%via NVD
CVE-2026-92919High· 8.1PoC
1w ago

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to …

▾ Midnightcjbi · admin3EPSS 0.58%via NVD
CVE-2026-92918High· 8.8PoC
1w ago

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens…

▾ Midnightcjbi · admin3EPSS 0.65%via NVD
CVE-2026-92904Medium· 4.3
1w ago

A flaw was found in the foreman_remote_execution plugin's template invocations controller

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filt…

▾ SunlitRed Hat · rubygem-foreman_remote_executionEPSS 0.34%via NVD
CVE-2026-81481High· 7.5
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially …

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.53%via NVD
CVE-2026-81475High· 8.1
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading…

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.70%via NVD
CVE-2026-78296Medium· 5.3
1w ago

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

▾ SunlitWP ManageNinja LLC · fluent-securityEPSS 0.16%via NVD
CVEs tagged “cve.org” — page 197 · VulnSea