VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

17239 CVEsRSS

CVE-2026-86109Medium· 6.6
2w ago

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification

The VeloCloud Edge software update workflow may accept update bundles without properly validating their signatures because the workflow does not restrict the digest algorithm used for artifact verification. An attacker with either suffic…

▾ SunlitArista Networks · VeloCloud EdgeEPSS 0.24%via NVD
CVE-2026-86108High· 8.0
2w ago

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command

Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may allow an authorized management request or configuration value to be interpreted as an operating-system command. Success…

▾ TwilightArista Networks · VeloCloud EdgeEPSS 0.61%via NVD
CVE-2026-92221Medium· 4.7PoC
2w ago

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8

A vulnerability was determined in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this vulnerability is the function generate_index_pasien of the file application/models/app_global_admin_model.p…

▾ Twilightgedelumbung · HospitalManagementEPSS 0.35%via NVD
CVE-2026-92220Medium· 5.3⚖ disputed
2w ago

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_tra…

▾ Sunlitvllm-project · vLLMEPSS 0.70%via NVD
CVE-2026-92299High· 7.4
2w ago

@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows

@jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMedia() picker, allowing any script in the meeting page to enumerate screens and windows. Attackers can call the jitsi-…

▾ TwilightJitsi · @jitsi/electron-sdkEPSS 0.48%via NVD
CVE-2026-92298Medium· 4.8
2w ago

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator

EspoCRM through 10.0.8 uses PHP's rand() function to generate tokens for lead-capture opt-in, event invitation, and campaign URLs instead of a cryptographically secure generator. Remote unauthenticated attackers can guess these roughly 3…

▾ SunlitEspoCRM · EspoCRMEPSS 0.43%via NVD
CVE-2026-73450Medium· 6.9
2w ago

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

On affected platforms running Arista EOS with MLAG Dual Primary Detection configured, an unauthenticated attacker with access to the Dual Primary Detection network segment can send specially crafted packets to interfere with the dual-pri…

▾ SunlitArista Networks · EOSEPSS 0.16%via NVD
CVE-2026-92217Medium· 6.3
2w ago

A vulnerability was determined in a2ui-project a2ui up to 0.10.6

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation cause…

▾ Sunlita2ui-project · a2uiEPSS 0.43%via NVD
CVE-2026-92216Medium· 4.3
2w ago

A vulnerability was found in a2ui-project a2ui up to 0.10.7

A vulnerability was found in a2ui-project a2ui up to 0.10.7. Affected by this issue is the function openUrl of the file renderers/web_core/src/v0_9/rendering/generic-binder.ts of the component Binder. The manipulation results in open red…

▾ Sunlita2ui-project · a2uiEPSS 0.48%via NVD
CVE-2026-92214Low· 3.5
2w ago

A flaw has been found in a2ui-project a2ui up to 0.10.7

A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts of the component a2a-c…

▾ Sunlita2ui-project · a2uiEPSS 0.35%via NVD
CVE-2026-92215High· 7.3
2w ago

A vulnerability has been found in a2ui-project a2ui up to 0.10.7

A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.get of the file agent_sdks/python/a2ui_agent/src/a2ui/extensions/file_resolve/file_resolver.py of the component FileRe…

▾ Twilighta2ui-project · a2uiEPSS 0.51%via NVD
CVE-2026-92213Medium· 5.5
2w ago

A vulnerability was detected in a2ui-project a2ui up to 0.10.6

A vulnerability was detected in a2ui-project a2ui up to 0.10.6. This impacts the function z.any of the file renderers/web_core/src/v0_9/schema/server-to-client.ts of the component Angular Renderer. Performing a manipulation of the argume…

▾ Sunlita2ui-project · a2uiEPSS 0.32%via NVD
CVE-2026-73446High· 7.4
2w ago

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacen…

On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can send a crafted IS-IS Hello Protocol Data Unit (PDU) that causes the device to tear down an established IS-IS adjacen…

▾ TwilightArista Networks · EOSEPSS 0.27%via NVD
CVE-2026-73459High· 7.4
2w ago

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database

On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This …

▾ TwilightArista Networks · EOSEPSS 0.17%via NVD
CVE-2026-73460Medium· 6.1
2w ago

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely

On affected platforms running Arista EOS with IS-IS graceful restart enabled, an unauthenticated attacker who can inject a malformed IS-IS LSP PDU packet can cause the IS-IS graceful restart procedure to terminate prematurely. This may r…

▾ SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-15638Critical· 9.1
2w ago

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys

An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.20%via NVD
CVE-2026-15640Critical· 9.5
2w ago

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.28%via NVD
CVE-2026-15639Critical· 9.3
2w ago

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

▾ MidnightDelinea · Secret Server (On-Prem)EPSS 0.39%via NVD
CVE-2026-92184Medium· 6.3
2w ago

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. Affected is the function urllib.request.urlopen of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component Multimodal Content. The manipulati…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.37%via NVD
CVE-2026-85893High· 8.8
2w ago

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · edge_chromiumEPSS 0.82%via NVD
CVE-2025-11395Medium· 5.5
2w ago

A flaw was found in Podman

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

▾ SunlitRed Hat · buildahEPSS 0.36%via NVD
CVE-2026-69486High· 8.8
2w ago

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · edge_chromiumEPSS 0.82%via NVD
CVE-2026-92257Medium· 5.4
2w ago

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components

Netcore NR255-V version 1.5.130703 contains a stored cross-site scripting vulnerability in L7 content management pages that use eval() sinks, affecting the call board text and policy group handling components. Attackers can inject persis…

▾ SunlitNetcore · NR255-VEPSS 0.24%via NVD
CVE-2026-92256Medium· 6.5
2w ago

NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers

NR255-V version 1.5.130703 contains a sensitive information disclosure vulnerability in l2tpd_config_show_cgi.c, ipsec_show_cgi.c, and mod_vpn_remote/plan.json read handlers. Attackers can query l2tpd_config_show.cgi to expose stored IPs…

▾ SunlitNetcore · NR255-VEPSS 0.36%via NVD
CVE-2026-92255Medium· 5.4
2w ago

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API

Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in filter_arp_put_file.cgi caused by improper use of a string handling API. Attackers can trigger an unterminated buffer over-read by exploiting this flaw in…

▾ SunlitNetcore · NR255-VEPSS 0.35%via NVD
CVE-2026-92248High· 7.8
2w ago

A flaw was found in the file-psd plugin in GIMP

A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photoshop Document) image file, an integer overflow occurs during the multiplication of values from an embedded JPEG header…

▾ TwilightGNOME · gimpEPSS 0.18%via NVD
CVE-2026-83408High· 8.1
2w ago

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle …

▾ TwilightOracle Corporation · Oracle GraalVM for JDK, Oracle GraalVMEPSS 0.42%via NVD
CVE-2026-83368High· 7.0
2w ago

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle Graa…

▾ TwilightOracle Corporation · Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVMEPSS 0.28%via NVD
CVE-2026-83357High· 8.1
2w ago

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle …

▾ TwilightOracle Corporation · Oracle GraalVM for JDK, Oracle GraalVMEPSS 0.45%via NVD
CVE-2026-82567Medium· 6.3
2w ago

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem

The myPRO Manager notification gateway exposes an unauthenticated HTTP endpoint used to send SMS messages through a connected GSM modem. The endpoint is accessible over the network and does not require authentication before accepting a p…

▾ SunlitmySCADA Technologies · mySCADA myPROEPSS 0.34%via NVD
CVEs tagged “cve.org” — page 237 · VulnSea