VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

12188 CVEsRSS

CVE-2026-77518Medium· 5.0
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because …

Sunlit1Panel-dev · MaxKBvia NVD
CVE-2026-88403None
today

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

Sunlitvia NVD
CVE-2026-77525Medium· 4.2
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id and chat_record_id values without confirming that the c…

Sunlit1Panel-dev · MaxKBvia NVD
CVE-2026-77523High· 7.4
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads and saves a Model by id alone without including wo…

Twilight1Panel-dev · MaxKBvia NVD
CVE-2026-77516Medium· 5.4
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can still bind its identifier through tool_ids, skill_tool_i…

Sunlit1Panel-dev · MaxKBvia NVD
CVE-2026-93433Medium· 5.5
today

A flaw was found in libstoragemgmt

A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, spec…

SunlitRed Hat · libstoragemgmtvia NVD
CVE-2026-79917Medium· 6.5
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat…

Sunlit1Panel-dev · MaxKBvia NVD
CVE-2026-94424High· 8.8
today

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overfl…

TwilightMoore Threads · MTT S80 Driver Packagevia NVD
CVE-2026-77522Medium· 4.3
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get wit…

Sunlit1Panel-dev · MaxKBvia NVD
CVE-2026-77521Critical· 10.0
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits exe…

Midnight1Panel-dev · MaxKBvia NVD
CVE-2026-77517Medium· 5.4
today

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, then query the target Document by document_id or Paragraph…

Sunlit1Panel-dev · MaxKBvia NVD
CVE-2026-94588Medium· 4.4
today

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package ch…

SunlitProxmox · pmg-apivia NVD
CVE-2026-79319None
today

Stencil core 4.43.5 is vulnerable to Incorrect Access Control.

Stencil core 4.43.5 is vulnerable to Incorrect Access Control.

Sunlitvia NVD
CVE-2026-79318None
today

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

Sunlitvia NVD
CVE-2026-73546High· 7.4PoC
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values …

Midnightenvoyproxy · envoyvia NVD
CVE-2026-73512High· 7.5
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream r…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-58269High· 8.1
today

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full a…

TwilightSync-in · servervia NVD
CVE-2026-62247Medium· 6.5
today

Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets

Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authorization does not correctly honor the per-extension presence.read row-level security policy when a private-channel clien…

Sunlitsupabase · realtimevia NVD
CVE-2026-52835High· 7.0PoC
today

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handler and the database_file branch of import_database in plexpy/webserve.py join the attacker-controlled config_file.file…

MidnightTautulli · Tautullivia NVD
CVE-2026-54915Medium· 5.4
today

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /auth/redirect endpoint in plexpy/webauth.py removes forward slashes from the user-controlled redirect_uri parameter but …

SunlitTautulli · Tautullivia NVD
CVE-2026-49995Medium· 4.8
today

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron field stored in the newsletters table is inserted by data/interfaces/default/newsletter_config.html into a JavaScript str…

SunlitTautulli · Tautullivia NVD
CVE-2026-45381Medium· 5.1
today

Tautulli is a Python based monitoring and tracking tool for Plex Media Server

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual…

SunlitTautulli · Tautullivia NVD
CVE-2026-81469High· 7.8
today

Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability

Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and …

TwilightDell · Inventory Collector Clientvia NVD
CVE-2026-55897High· 8.8PoC
today

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the lu…

Midnightopenwrt · lucivia NVD
CVE-2026-55159High· 8.8
today

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carr…

Twilightopenwrt · luci-app-adblock-fastvia NVD
CVE-2026-73548High· 7.5
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy forwards data for a configured non-WebSocket HTTP upgrade before the upstream accepts the upgrade.…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-50572Medium· 5.9
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HTTP external-authorization client can retain a stale request callback after a request is reject…

Sunlitenvoyproxy · envoyvia NVD
CVE-2026-73552High· 7.5
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy HTTP RBAC accepts RFC-valid opaque header bytes but evaluates safe_regex values with RE2's UTF-8 s…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-49811High· 8.4
today

Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability

Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…

TwilightDell · Command | Monitor (DCM)via NVD
CVE-2026-85219Low· 3.7
today

Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.

Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause unconstrained memory usage.

SunlitThinkst Applied Research · opencanaryvia NVD
CVEs tagged “cve.org” — page 3 · VulnSea