VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

16981 CVEsRSS

CVE-2026-81546High· 7.7
1w ago

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity documen…

▾ TwilightCanva · AffinityEPSS 0.15%via NVD
CVE-2026-92838High· 7.8
1w ago

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in …

▾ TwilightGeoVision Inc. · GV-Remote E-mapEPSS 0.20%via NVD
CVE-2026-55061Low· 1.0
1w ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as a…

▾ Sunlituniget-org · cliEPSS 0.15%via NVD
CVE-2026-55062High· 8.4PoC
1w ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

▾ Midnightuniget-org · cliEPSS 0.19%via NVD
CVE-2026-54546Medium· 5.0PoC
1w ago

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/ro…

▾ Twilightdfpc-coe · CloudTAKEPSS 0.37%via NVD
CVE-2026-50285High· 7.5PoC
1w ago

Pomerium is an identity and context-aware access proxy

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V…

▾ Midnightpomerium · pomeriumEPSS 0.74%via NVD
CVE-2026-54504High· 8.8PoC
1w ago

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with STA…

▾ Midnightandrea9293 · mcp-documentation-serverEPSS 0.57%via NVD
CVE-2026-54495Medium· 4.3
1w ago

The OpenFeature Operator allows users to expose feature flags to applications

The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME…

▾ Sunlitopen-feature · open-feature-operatorEPSS 0.31%via NVD
CVE-2026-54451High· 8.2PoC
1w ago

Elixir protobuf is a pure Elixir implementation of Google Protobuf

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…

▾ Midnightelixir-protobuf · protobufEPSS 0.52%via NVD
CVE-2026-54446High· 8.1PoC
1w ago

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-ne…

▾ MidnightLabs64 · NetLicensing-MCPEPSS 0.62%via NVD
CVE-2026-50158High· 7.7
1w ago

yutu is an AI-powered toolkit for managing and growing YouTube channels

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg…

▾ Twilighteat-pray-ai · yutuEPSS 0.23%via NVD
CVE-2026-50125High· 7.5PoC
1w ago

MKP is a Model Context Protocol server for Kubernetes

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, which accepts attacker-controlled limitByt…

▾ MidnightStacklokLabs · mkpEPSS 0.49%via NVD
CVE-2026-47252Critical· 9.0PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brav…

▾ Abyssaljulien040 · anyqueryEPSS 0.70%via NVD
CVE-2026-54617Critical· 9.8
1w ago

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274…

▾ MidnightGravitLauncher · LauncherEPSS 0.68%via NVD
CVE-2026-49292Low· 0.0
1w ago

Kiwi TCMS is an open source test management system

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migra…

▾ Sunlitkiwitcms · KiwiEPSS 0.44%via NVD
CVE-2026-65388High· 7.5
2w ago

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in contai…

▾ TwilightApple · containerizationEPSS 0.43%via NVD
CVE-2026-61599High· 8.8
2w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling …

▾ Twilightdjust-org · djustEPSS 0.60%via NVD
CVE-2026-61589Medium· 6.3
2w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…

▾ Sunlitdjust-org · djustEPSS 0.18%via NVD
CVE-2026-92577High· 7.5
2w ago

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by …

▾ TwilightWWBN · AVideoEPSS 0.43%via NVD
CVE-2026-92576High· 8.6PoC
2w ago

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instruc…

▾ MidnightHKUDS · nanobotEPSS 0.45%via NVD
CVE-2026-64684Medium· 6.8
2w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…

▾ Sunlitmodelcontextprotocol · rust-sdkEPSS 0.50%via NVD
CVE-2026-92581Medium· 4.3PoC
2w ago

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed li…

▾ TwilightWWBN · AVideoEPSS 0.29%via NVD
CVE-2026-89034Medium· 6.5PoC
2w ago

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, o…

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, o…

▾ TwilightTCH · QRingEPSS 0.33%via NVD
CVE-2026-85469High· 8.0
2w ago

A flaw was found in quay-builder-qemu

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inj…

▾ TwilightRed Hat · quay/quay-builder-qemu-rhcos-rhel8EPSS 0.52%via NVD
CVE-2026-92580High· 8.8PoC
2w ago

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync…

▾ MidnightWWBN · AVideoEPSS 1.4%via NVD
CVE-2026-92579Medium· 5.4PoC
2w ago

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugi…

▾ TwilightWWBN · AVideoEPSS 0.27%via NVD
CVE-2026-92578High· 8.1PoC
2w ago

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify()

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attacke…

▾ MidnightWWBN · AVideoEPSS 0.62%via NVD
CVE-2026-92584Medium· 6.1
2w ago

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's…

▾ SunlitWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-92583Medium· 6.5PoC
2w ago

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-92582High· 7.1
2w ago

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global…

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVEs tagged “cve.org” — page 201 · VulnSea