VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

17172 CVEsRSS

CVE-2026-70416Critical· 10.0
2w ago

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability

Dell ObjectScale, versions prior to 4.4.0.0, contains a Deserialization of Untrusted Data vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

▾ Midnightdell · objectscaleEPSS 0.85%via NVD
CVE-2026-92615Medium· 6.6
2w ago

A flaw was found in flightctl

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates)…

▾ SunlitRed Hat · flightctlEPSS 0.15%via NVD
CVE-2026-92626High· 7.5
2w ago

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled n…

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled n…

▾ TwilightControl iD · iDSecureEPSS 0.46%via NVD
CVE-2026-92625High· 7.5
2w ago

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…

Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecu…

▾ TwilightControl iD · iDSecureEPSS 0.66%via NVD
CVE-2026-92397Critical· 9.1PoC
2w ago

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380

A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function cc_set of the file unifyframe-sgi.elf of the component configChange. Such manipulation of the argument data.url leads t…

▾ AbyssalRuijie · RG-EW3000GXEPSS 3.2%via NVD
CVE-2026-90999Critical· 9.8
2w ago

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can su…

▾ MidnightFunctional Software, Inc. · Sentry SeerEPSS 0.67%via NVD
CVE-2026-17526High· 7.2
2w ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-19607Medium· 5.3
2w ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-92627Medium· 4.6
2w ago

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

▾ SunlitThe HDF Group · HDF5EPSS 0.23%via NVD
CVE-2026-61595High· 7.7
2w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.tenants` isolation was enforced only on the HTTP path. The current tenant was stored in `thread…

▾ Twilightdjust · djustEPSS 0.39%via NVD
CVE-2025-59953Critical· 9.8PoC
2w ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior to version 0.10.2, the LMdeploy implements an rpc server (AsyncRPCServer in zmq_rpc.py) for supporting the RPC commu…

▾ AbyssalInternLM · lmdeployEPSS 0.80%via NVD
CVE-2026-61593High· 8.1
2w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the SSE client→server POST endpoints are `@csrf_exempt` and the SSE GET stream endpoint had no Origin …

▾ Twilightdjust · djustEPSS 0.21%via NVD
CVE-2026-92383Medium· 4.3PoC
2w ago

A security vulnerability has been detected in PbootCMS up to 3.2.24

A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Manage…

▾ TwilightEPSS 0.24%via NVD
CVE-2026-82410High· 8.7
2w ago

Pocketbase is an open source web backend written in go

Pocketbase is an open source web backend written in go. Prior to 0.22.48 and 0.39.7, PocketBase's panic-recovery middleware covers regular request handling but not internal child and worker goroutines. A panic in one of these internal go…

▾ Twilightpocketbase · pocketbaseEPSS 0.58%via NVD
CVE-2025-36591Medium· 4.4
2w ago

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability

Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prior to 4.4.0.0, contains an Use of a Broken or Risky Cryptographic Algorithm vulnerability. A high privileged attacker with local access could potentially exploit…

▾ SunlitDell · Elastic Cloud Storage (ECS)EPSS 0.11%via NVD
CVE-2026-89031Medium· 5.4
2w ago

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users

Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records of other users. The b2s_calendar_move_post AJAX handler in includes/Ajax/Post.php issues an UPDATE against the b2s_pos…

▾ SunlitAdenion · Blog2SocialEPSS 0.30%via NVD
CVE-2026-80274High· 7.5
2w ago

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-76163High· 7.5
2w ago

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-61709Medium· 5.3
2w ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

▾ Sunlitopenfga · openfgaEPSS 0.35%via NVD
CVE-2026-19666High· 7.5
2w ago

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

▾ TwilightISC · BIND 9EPSS 0.57%via NVD
CVE-2026-76825High· 8.4
2w ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

▾ Twilightzopefoundation · RestrictedPythonEPSS 0.62%via NVD
CVE-2026-88976Medium· 6.1
2w ago

Plate is a rich-text editor with AI and shadcn/ui

Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.0-beta.1 builds, Plate core HTML deserialization APIs parse supplied HTML strings in the active document. When an app…

▾ Sunlitudecode · plateEPSS 0.34%via NVD
CVE-2026-19033Medium· 6.5
2w ago

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess…

▾ SunlitISC · BIND 9EPSS 0.24%via NVD
CVE-2026-88064High· 8.8
2w ago

Backstage is an open framework for building developer portals

Backstage is an open framework for building developer portals. Prior to 1.14.6 and from 1.15.0 until 1.15.4, the @backstage/plugin-techdocs-node package insufficiently validates mkdocs.yml supplied by an authenticated user who can regist…

▾ Twilightbackstage · backstageEPSS 0.88%via NVD
CVE-2026-19668Medium· 5.3
2w ago

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the ex…

▾ SunlitISC · BIND 9EPSS 0.47%via NVD
CVE-2026-92366High· 7.3PoC
2w ago

A vulnerability was determined in code-projects Matrimonial System 1.0

A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the file /search.php of the component Regular Search. This manipulation of the argument sex/mothertongue/maritialstatus/country/state…

▾ Midnightcode-projects · Matrimonial SystemEPSS 0.56%via NVD
CVE-2026-77119Medium· 5.9
2w ago

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

▾ SunlitISC · BIND 9EPSS 0.23%via NVD
CVE-2026-75029Medium· 5.3
2w ago

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record)

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can c…

▾ SunlitISC · BIND 9EPSS 0.71%via NVD
CVE-2026-92087High· 8.1
2w ago

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard

@fastify/auth is a Fastify plugin that composes multiple authentication and authorization strategies into a single route guard. In versions 5.0.0 through 5.1.0, when strategies are composed with the relation "or" option together with the…

▾ Twilight@fastify/auth · @fastify/authEPSS 0.47%via NVD
CVE-2026-63671High· 8.1PoC
2w ago

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component

MDC is a tool to take regular Markdown and write documents interacting deeply with a Vue component. Prior to 0.22.1, @nuxtjs/mdc uses parseMarkdown with allowDangerousHtml enabled by default and relies on validateProps, validateProp, and…

▾ Midnightnuxt-content · mdcEPSS 0.47%via NVD
CVEs tagged “cve.org” — page 216 · VulnSea