VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

17244 CVEsRSS

CVE-2026-81927Medium· 5.4⚖ disputed
2w ago

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.image…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-68953Medium· 6.5
2w ago

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

The affected products are vulnerable to an authentication bypass that allows unauthenticated remote attackers to disclose sensitive device information, including administrator credentials in plaintext, by sending crafted HTTP(S) requests.

▾ SunlitDigital Watchdog · VMAX A1 G4 DVREPSS 0.56%via NVD
CVE-2026-68070High· 8.8
2w ago

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

The affected products are missing authentication for a critical function, which could allow an attacker to run as root and pass received bytes directly to a system command.

▾ TwilightDigital Watchdog · VMAX A1 G4 DVREPSS 0.43%via NVD
CVE-2026-68950High· 8.8
2w ago

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.

▾ TwilightDigital Watchdog · VMAX A1 G4 DVREPSS 0.35%via NVD
CVE-2026-54337Critical· 9.8PoC
2w ago

Fireshare facilitates self-hosted media and link sharing

Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.

▾ AbyssalShaneIsrael · fireshareEPSS 0.63%via NVD
CVE-2026-79994High· 8.7
2w ago

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname

The guest-to-host Unix-domain socket relay in Docker Sandboxes validates that a socket path is inside an authorized workspace, but later reconnects using the pathname. A malicious guest can replace an intermediate directory with a symlin…

▾ TwilightDocker · Docker SandboxesEPSS 0.14%via NVD
CVE-2026-66890Critical· 9.6
2w ago

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

▾ MidnightDigital Watchdog · VMAX A1 G4 DVREPSS 0.33%via NVD
CVE-2026-92240Critical· 9.1⚖ disputed
2w ago

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird

A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnera…

▾ Midnightmozilla · thunderbirdEPSS 0.63%via NVD
CVE-2026-92239High· 8.1⚖ disputed
2w ago

A maliciously constructed IMAP line could cause an out-of-bounds buffer read

A maliciously constructed IMAP line could cause an out-of-bounds buffer read. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ Twilightmozilla · thunderbirdEPSS 0.41%via NVD
CVE-2026-92238Critical· 9.8⚖ disputed
2w ago

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations

A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ Midnightmozilla · thunderbirdEPSS 0.54%via NVD
CVE-2026-89040Critical· 9.8
2w ago

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device

Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code…

▾ MidnightTencent · Mass Service Engine in Cluster (MSEC)EPSS 1.1%via NVD
CVE-2026-89027Medium· 6.5
2w ago

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplyi…

miniOrange JWT Authentication for WP REST APIs plugin for WordPress before 4.8.0 contains an authentication method downgrade vulnerability that allows unauthenticated attackers to bypass administrator-configured authentication by supplyi…

▾ SunlitminiOrange · JWT Authentication for WP REST APIsEPSS 0.38%via NVD
CVE-2026-88922Medium· 6.7
2w ago

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…

The go-getter library up to versions 1.8.8 and 2.2.3 is vulnerable to a privilege escalation issue in its archive decompression handling that may allow a crafted archive to cause extracted files to be created with elevated permission bit…

▾ SunlitHashiCorp · Shared libraryEPSS 0.11%via NVD
CVE-2026-87289High· 7.5
2w ago

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content)

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with …

▾ Twilightoracle · helidonEPSS 0.47%via NVD
CVE-2026-87288High· 8.1
2w ago

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network ac…

▾ TwilightOracle Corporation · Oracle GraalVMEPSS 0.37%via NVD
CVE-2026-87287High· 8.1
2w ago

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network ac…

▾ TwilightOracle Corporation · Oracle GraalVMEPSS 0.37%via NVD
CVE-2026-87286High· 8.1
2w ago

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler)

Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler). The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network ac…

▾ TwilightOracle Corporation · Oracle GraalVMEPSS 0.37%via NVD
CVE-2026-87285Medium· 6.0
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.17%via NVD
CVE-2026-87284Low· 3.2
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.15%via NVD
CVE-2026-87283Medium· 6.0
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.17%via NVD
CVE-2026-87282Medium· 6.0
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.17%via NVD
CVE-2026-87281Low· 3.2
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.16%via NVD
CVE-2026-87280Medium· 4.2
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.15%via NVD
CVE-2026-87279Medium· 6.1
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastru…

▾ Sunlitoracle · vm_virtualboxEPSS 0.15%via NVD
CVE-2026-87278Medium· 6.1
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.15%via NVD
CVE-2026-87277High· 7.5
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via RD…

▾ Twilightoracle · vm_virtualboxEPSS 0.47%via NVD
CVE-2026-87276High· 7.5
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrast…

▾ Twilightoracle · vm_virtualboxEPSS 0.13%via NVD
CVE-2026-87275Medium· 4.6
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastr…

▾ Sunlitoracle · vm_virtualboxEPSS 0.16%via NVD
CVE-2026-87274Medium· 4.4
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrast…

▾ Sunlitoracle · vm_virtualboxEPSS 0.12%via NVD
CVE-2026-87273High· 8.6
2w ago

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core)

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastr…

▾ Twilightoracle · vm_virtualboxEPSS 0.18%via NVD
CVEs tagged “cve.org” — page 241 · VulnSea