VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18336 CVEsRSS

CVE-2026-91962Medium· 6.3
2w ago

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages

FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer s…

▾ Sunlitfreerdp · freerdpEPSS 0.26%via NVD
CVE-2026-91969Medium· 6.5
2w ago

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91968Medium· 6.5PoC
2w ago

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits

vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested pa…

▾ Twilightgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91965High· 7.5PoC
2w ago

WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints

WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream…

▾ MidnightWWBN · AVideoEPSS 0.45%via NVD
CVE-2026-91973High· 7.5PoC
2w ago

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection

Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well…

▾ Midnightgo-vikunja · vikunjaEPSS 0.67%via NVD
CVE-2026-91970Medium· 6.5PoC
2w ago

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs

Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to atta…

▾ Twilightgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91967Medium· 5.0PoC
2w ago

AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation

AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission c…

▾ TwilightWWBN · AVideoEPSS 0.34%via NVD
CVE-2026-91980Medium· 4.3PoC
2w ago

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve comp…

▾ Twilightgo-vikunja · vikunjaEPSS 0.31%via NVD
CVE-2026-91972High· 7.5PoC
2w ago

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential gue…

▾ Midnightgo-vikunja · vikunjaEPSS 0.63%via NVD
CVE-2026-91971Medium· 6.5PoC
2w ago

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images wit…

▾ Twilightgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91982Medium· 4.3PoC
2w ago

Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication

Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a valid access toke…

▾ Twilightgo-vikunja · vikunjaEPSS 0.35%via NVD
CVE-2026-91981Medium· 4.3PoC
2w ago

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames ex…

▾ Twilightgo-vikunja · vikunjaEPSS 0.31%via NVD
CVE-2026-91979Medium· 6.5
2w ago

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausti…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91986Medium· 5.4PoC
2w ago

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof …

▾ TwilightGitoxideLabs · gitoxideEPSS 0.23%via NVD
CVE-2026-91985High· 7.5PoC
2w ago

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-…

▾ Midnightgo-vikunja · vikunjaEPSS 0.43%via NVD
CVE-2026-91983Medium· 4.3PoC
2w ago

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restric…

▾ Twilightgo-vikunja · vikunjaEPSS 0.30%via NVD
CVE-2026-91990High· 7.5PoC
2w ago

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create lar…

▾ Midnighttornadoweb · tornadoEPSS 0.49%via NVD
CVE-2026-91987Medium· 6.5
2w ago

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers…

▾ Sunlitdep0we · atomic-agents-stackEPSS 0.48%via NVD
CVE-2026-91984Medium· 4.3
2w ago

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST o…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.26%via NVD
CVE-2026-91989High· 7.5
2w ago

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass …

▾ Twilightdep0we · atomic-agents-stackEPSS 1.3%via NVD
CVE-2026-91988High· 8.1
2w ago

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argume…

▾ Twilightdep0we · atomic-agents-stackEPSS 0.32%via NVD
CVE-2026-65831High· 7.7
2w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions …

▾ TwilightArcadeData · arcadedbEPSS 0.60%via NVD
CVE-2026-91992Medium· 5.9PoC
2w ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

▾ Twilighttornadoweb · tornadoEPSS 0.26%via NVD
CVE-2026-91991Medium· 5.4PoC
2w ago

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-de…

▾ Twilighttornadoweb · tornadoEPSS 0.28%via NVD
CVE-2026-87793Medium· 5.1
2w ago

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

▾ SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.51%via NVD
CVE-2026-87792High· 8.7
2w ago

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

▾ TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.46%via NVD
CVE-2026-19407High· 7.7
2w ago

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

▾ TwilightGoogle Cloud · Gemini Enterprise Agent Platform SDK for PythonEPSS 0.52%via NVD
CVE-2026-89307Medium· 5.1
2w ago

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

▾ SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.36%via NVD
CVE-2026-88620Medium· 4.3
2w ago

SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint

SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allow…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-91849Medium· 6.3PoC
2w ago

A security flaw has been discovered in WuzhiCMS up to 4.1.0

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in …

▾ TwilightEPSS 0.37%via NVD
CVEs tagged “cve.org” — page 298 · VulnSea