VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18352 CVEsRSS

CVE-2026-90851Medium· 6.3PoC
2w ago

A flaw has been found in PHPGurukul Hostel Management System 3.0

A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the a…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90850Low· 2.4PoC
2w ago

A vulnerability was detected in PHPGurukul Hostel Management System 3.0

A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be lau…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90849High· 7.3PoC
2w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User le…

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.43%via NVD
CVE-2026-90848Medium· 4.3
2w ago

A weakness has been identified in Governikus AusweisApp up to 2.5.4

A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The…

▾ SunlitGovernikus · AusweisAppEPSS 0.45%via NVD
CVE-2026-91752High· 7.5PoC
2w ago

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarO…

▾ MidnightGNU · libextractorEPSS 0.74%via NVD
CVE-2026-91751High· 8.3PoC
2w ago

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal seq…

▾ Midnightflextype · flextypeEPSS 0.54%via NVD
CVE-2026-91750Medium· 6.5PoC
2w ago

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation…

▾ TwilightTencent · WeKnoraEPSS 0.44%via NVD
CVE-2026-90847Critical· 9.1PoC
2w ago

A vulnerability was determined in EFM ipTIME C200E 1.094

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the at…

▾ AbyssalEFM · ipTIME C200EEPSS 3.4%via NVD
CVE-2026-90846High· 7.3PoC
2w ago

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is …

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90845Low· 3.5PoC
2w ago

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. …

▾ TwilightPHPGurukul · Daily Expense Tracker SystemEPSS 0.35%via NVD
CVE-2026-90844High· 7.3PoC
2w ago

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injec…

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90843High· 8.3PoC
2w ago

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipul…

▾ MidnightSabyasachiRana · WebMapEPSS 2.2%via NVD
CVE-2026-85657Medium· 5.4
2w ago

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

▾ Sunlitpublishpress · Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress AuthorsEPSS 0.24%via NVD
CVE-2026-85575Medium· 6.4
2w ago

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

▾ Sunlitroxnor · ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgetsEPSS 0.26%via NVD
CVE-2026-90842Low· 3.7PoC
2w ago

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/c…

▾ TwilightPHPGurukul · Blood Donor Management SystemEPSS 0.31%via NVD
CVE-2026-90841High· 7.3PoC
2w ago

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.43%via NVD
CVE-2026-90840High· 7.3PoC
2w ago

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to i…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.69%via NVD
CVE-2026-59971Critical· 10.0
2w ago

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_se…

▾ Midnightdesigncomputer · mysql_mcp_serverEPSS 0.42%via NVD
CVE-2026-59973High· 8.5PoC
2w ago

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISp…

▾ Midnightagentfront · frontmcpEPSS 0.39%via NVD
CVE-2026-56831Medium· 6.5PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…

▾ Twilightshopperlabs · shopperEPSS 0.43%via NVD
CVE-2026-56830Medium· 6.5
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …

▾ Sunlitshopperlabs · shopperEPSS 0.39%via NVD
CVE-2026-56829High· 8.1PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56827High· 8.1PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56825High· 8.1PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, …

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-59965High· 7.1PoC
2w ago

Payload Plugins is a collection of plugins designed to enhance Payload CMS

Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts a…

▾ Midnightjhb-software · payload-pluginsEPSS 0.38%via NVD
CVE-2026-59160High· 8.8PoC
2w ago

Yeger is a monorepo for npm packages maintained under the yeger scope

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by defaul…

▾ MidnightDerYeger · yegerEPSS 0.49%via NVD
CVE-2026-59157Medium· 6.5
2w ago

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…

▾ Sunlitncarlier · webhookdEPSS 0.60%via NVD
CVE-2026-55864High· 7.8
2w ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validati…

▾ Twilightgeonetwork · core-geonetworkEPSS 0.59%via NVD
CVE-2026-50024Medium· 5.3
2w ago

GitHacker is a tool that restores Git repositories from exposed .git directories

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs…

▾ SunlitWangYihang · GitHackerEPSS 0.45%via NVD
CVE-2026-44282Medium· 4.8
2w ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_titl…

▾ Sunlitdecidim · decidimEPSS 0.39%via NVD
CVEs tagged “cve.org” — page 306 · VulnSea