VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15476 CVEsRSS

CVE-2026-93642Critical· 9.3
2d ago

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.23%via NVD
CVE-2026-85542High· 8.8⚠ ExploitedPoC
2d ago

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed …

▾ MidnightIBM · Guardium Data ProtectionEPSS 2.4%via NVD
CVE-2026-100190Medium· 6.3
2d ago

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file path…

▾ Sunlitail project · ail frameworkEPSS 0.32%via NVD
CVE-2026-93641Critical· 9.3
2d ago

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.27%via NVD
CVE-2026-85029High· 7.5
2d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.

IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.54%via NVD
CVE-2026-93643Critical· 9.8
2d ago

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.96%via NVD
CVE-2026-93647Critical· 9.3
2d ago

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.23%via NVD
CVE-2026-84893High· 7.6
2d ago

IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service

IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.18%via NVD
CVE-2026-84884High· 7.5
2d ago

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an ad…

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.24%via NVD
CVE-2026-52622High· 7.5
2d ago

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

▾ TwilightEPSS 0.30%via NVD
CVE-2026-51772NonePoC
2d ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locati…

▾ TwilightEPSS 0.31%via NVD
CVE-2026-51773High· 8.1PoC
2d ago

An issue in the VMware datastore driver of OpenStack glance_store

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destina…

▾ MidnightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.32%via NVD
CVE-2026-88420None
2d ago

A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute arbitrary code in the context of the …

A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute arbitrary code in the context of the …

▾ SunlitEPSS 0.15%via NVD
CVE-2026-78902Medium· 6.1PoC
2d ago

Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package

Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package

▾ TwilightEPSS 0.30%via NVD
CVE-2026-95832Critical· 9.3
2d ago

Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in…

Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in…

▾ MidnightKovid Goyal · kittyEPSS 0.16%via NVD
CVE-2026-88421High· 7.5PoC
2d ago

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the si…

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the si…

▾ MidnightEPSS 0.30%via NVD
CVE-2025-51457High· 8.8PoC
2d ago

D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint

D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary syste…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-79153High· 7.8
2d ago

Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected s…

Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected s…

▾ TwilightEPSS 0.09%via NVD
CVE-2026-97524High· 7.5
2d ago

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error…

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error…

▾ TwilightLinux · LinuxEPSS 0.60%via NVD
CVE-2026-97523High· 7.5
2d ago

In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state change The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail …

In the Linux kernel, the following vulnerability has been resolved: mptcp: close race between scheduler and state change The mptcp scheduler may race with subflow sockets state change: data transmission on the selected socket may fail …

▾ TwilightLinux · LinuxEPSS 0.60%via NVD
CVE-2026-97522None
2d ago

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix bad accounting in __mptcp_subflow_push_pending() If __subflow_push_pending() errors out we should avoid updating the copied byte counters, to avoid mismatch…

In the Linux kernel, the following vulnerability has been resolved: mptcp: fix bad accounting in __mptcp_subflow_push_pending() If __subflow_push_pending() errors out we should avoid updating the copied byte counters, to avoid mismatch…

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-97527High· 8.8
2d ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock The fcport->unsol_ctx_head list is modified from several contexts without a common lock

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Serialize NVMe unsol ctx list with a per-fcport lock The fcport->unsol_ctx_head list is modified from several contexts without a common lock. Entries ar…

▾ TwilightLinux · LinuxEPSS 0.32%via NVD
CVE-2026-97526None
2d ago

In the Linux kernel, the following vulnerability has been resolved: s390/pai: Support CPU hotplug for PMU PAI The command 'perf stat -e pai_crypto/CRYPTO_ALL/ -- <command>' crashes the kernel when CPUs are hotplug added during that run…

In the Linux kernel, the following vulnerability has been resolved: s390/pai: Support CPU hotplug for PMU PAI The command 'perf stat -e pai_crypto/CRYPTO_ALL/ -- <command>' crashes the kernel when CPUs are hotplug added during that run…

▾ SunlitLinux · LinuxEPSS 0.19%via NVD
CVE-2026-97525High· 8.2
2d ago

In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Allocate split page tables as kernel page tables A PTE is allocated directly without going through the standard page table allocation routines (such as pte…

In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Allocate split page tables as kernel page tables A PTE is allocated directly without going through the standard page table allocation routines (such as pte…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-97532None
2d ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path When qla2x00_mem_alloc() fails, qla2x00_probe_one() jumps to probe_hw_failed and calls qla2x00…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Null out freed pointers in qla2x00_mem_alloc() error path When qla2x00_mem_alloc() fails, qla2x00_probe_one() jumps to probe_hw_failed and calls qla2x00…

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-97529None
2d ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] The FC BSG transport allocates job->request via memdup_user() using the exact user-supplied request…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Validate BSG request_len before reading vendor_cmd[] The FC BSG transport allocates job->request via memdup_user() using the exact user-supplied request…

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-97528High· 8.8
2d ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error qla_nvme_xmt_ls_rsp() obtains uctx, which was linked into fcport->unsol_ctx_head by qla2xxx_proc…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Unlink NVMe unsol ctx before freeing on LS reject error qla_nvme_xmt_ls_rsp() obtains uctx, which was linked into fcport->unsol_ctx_head by qla2xxx_proc…

▾ TwilightLinux · LinuxEPSS 0.32%via NVD
CVE-2026-97533None
2d ago

In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF A previous commit protected against races between ptdump and CPA collapse, however one still ex…

In the Linux kernel, the following vulnerability has been resolved: x86/mm/pat: Acquire init_mm read lock on attribute changes to avoid UAF A previous commit protected against races between ptdump and CPA collapse, however one still ex…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-97531High· 7.5
2d ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Skip vport under deletion in report ID acquisition qla24xx_report_id_acquisition() format-1 handling walks ha->vp_list under vport_slock, takes a vref_c…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Skip vport under deletion in report ID acquisition qla24xx_report_id_acquisition() format-1 handling walks ha->vp_list under vport_slock, takes a vref_c…

▾ TwilightLinux · LinuxEPSS 0.27%via NVD
CVE-2026-97530None
2d ago

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature qla27xx_copy_multiple_pkt() and qla27xx_copy_fpin_pkt() poll rsp_q->ring_ptr->signature for RESPONSE…

In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix soft lockup polling continuation IOCB signature qla27xx_copy_multiple_pkt() and qla27xx_copy_fpin_pkt() poll rsp_q->ring_ptr->signature for RESPONSE…

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVEs tagged “cve.org” — page 21 · VulnSea