VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18354 CVEsRSS

CVE-2026-91143High· 7.2PoC
2w ago

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements

goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the aut…

▾ Midnightsnail007 · goproxyEPSS 0.47%via NVD
CVE-2026-90827Low· 3.3PoC
2w ago

A vulnerability was identified in GPAC 26.07.0

A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out l…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-91145High· 7.1PoC
2w ago

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering

Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated i…

▾ MidnightActiviti · ActivitiEPSS 0.42%via NVD
CVE-2026-91144High· 7.5
2w ago

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint

ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the…

▾ Twilightzfile-dev · zfileEPSS 0.51%via NVD
CVE-2026-73449Medium· 5.9
2w ago

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet throug…

On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet throug…

▾ SunlitArista Networks · EOSEPSS 0.24%via NVD
CVE-2026-91146Medium· 6.1
2w ago

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links

Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript:…

▾ Sunlitjointakahe · takaheEPSS 0.34%via NVD
CVE-2026-12944Critical· 9.6PoC
2w ago

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports

IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential…

▾ AbyssalIBM · Langflow OSSEPSS 0.43%via NVD
CVE-2026-90828Medium· 5.3PoC
2w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer…

▾ Twilightgnu · binutilsEPSS 0.19%via NVD
CVE-2026-76081Medium· 5.5
2w ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue s…

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.40%via NVD
CVE-2026-13277Medium· 4.7
2w ago

IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack

IBM Verify Identity Access could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoo…

▾ SunlitIBM · Verify Identity AccessEPSS 0.28%via NVD
CVE-2026-13276Medium· 6.1
2w ago

IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verif…

IBM Verify Identity Access 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verify Access 10.0.0 through 10.0.9.2 Interim Fix 001 and IBM Verify Identity Access Container 11.0.0 through 11.0.3 Interim Fix 001 and IBM Security Verif…

▾ SunlitIBM · Verify Identity AccessEPSS 0.24%via NVD
CVE-2026-81903Medium· 5.4
2w ago

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons

Concrete CMS versions 9.0.0 to 9.5.2 stored the Page Container icon value submitted through the dashboard without validating it against the set of known container icons. The unvalidated value was later concatenated into the src attribute…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.32%via NVD
CVE-2026-13272Medium· 5.4
2w ago

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

IBM Verify Identity Access is missing origin validation which could allow a remote attacker to perform operations as the victim and potentially launch further attacks against the systems.

▾ SunlitIBM · Verify Identity AccessEPSS 0.15%via NVD
CVE-2026-90818Medium· 4.3PoC
2w ago

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4

A security flaw has been discovered in netease-youdao LobsterAI 2026.6.15/2026.8.28/2026.9.3/2026.9.4. Impacted is the function OpenClawConfigSync.buildBrowserConfig of the file src/main/libs/openclawConfigSync.ts of the component Browse…

▾ Twilightnetease-youdao · LobsterAIEPSS 0.54%via NVD
CVE-2026-13260High· 7.5
2w ago

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

IBM Verify Identity Access could allow a remote attacker to cause a denial of service due to insufficient validation of incoming request resources.

▾ TwilightIBM · Verify Identity AccessEPSS 0.43%via NVD
CVE-2026-90819High· 7.3
2w ago

A weakness has been identified in a2aproject a2a-java 1.2.0

A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificatio…

▾ Twilighta2aproject · a2a-javaEPSS 0.66%via NVD
CVE-2026-13107High· 7.1
2w ago

IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.

IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default.

▾ TwilightIBM · Business Automation Workflow containers and traditionalEPSS 0.28%via NVD
CVE-2026-12767Medium· 6.5
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.11.5 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitati…

▾ SunlitIBM · Langflow OSSEPSS 0.22%via NVD
CVE-2026-84624Medium· 5.5
2w ago

A permissions issue was addressed with improved path validation

A permissions issue was addressed with improved path validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. A sandboxed app may be able …

▾ Sunlitapple · ipadosEPSS 0.18%via NVD
CVE-2026-12765Medium· 6.5
2w ago

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.10.2 is vulnerable to server-side request forgery (SSRF). This may allow an unauthenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitati…

▾ SunlitIBM · Langflow OSSEPSS 0.22%via NVD
CVE-2026-81902High· 8.1
2w ago

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks)

Concrete CMS 9 through 9.5.2 did not validate a CSRF token in the orphaned block removal panel action (removeOrphanedBlocks). A remote attacker could craft a request that, when loaded by an authenticated user holding edit permission on t…

▾ Twilightconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-12766Medium· 5.4
2w ago

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF)

IBM Langflow OSS 1.0.0 through 1.11.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating…

▾ SunlitIBM · Langflow OSSEPSS 0.18%via NVD
CVE-2026-12763Medium· 4.2
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow an authenticated attacker to access another user's MCP server context due to improper cache key isolation in the MCP Tools component.

▾ SunlitIBM · Langflow OSSEPSS 0.15%via NVD
CVE-2026-90820Medium· 4.3
2w ago

A security vulnerability has been detected in a2aproject a2a-java 1.2.0

A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandl…

▾ Sunlita2aproject · a2a-javaEPSS 0.39%via NVD
CVE-2026-81901High· 8.7
2w ago

In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization

In Concrete CMS 9.2.0 through 9.5.2, the REST API page update endpoint (PUT /ccm/api/1.0/pages/{cID}) did not enforce page-property, page-template, or page-type authorization. A user granted only content-editing rights on a page could th…

▾ Twilightconcretecms · concrete_cmsEPSS 0.38%via NVD
CVE-2026-84576Medium· 5.5
2w ago

This issue was addressed with improved checks

This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to access sensitive user data.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-84537Medium· 6.6
2w ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to cause unexpected system termination or corrupt kernel memory.

▾ Sunlitapple · macosEPSS 0.16%via NVD
CVE-2026-84521Medium· 5.5
2w ago

A use after free issue was addressed with improved memory management

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, visionOS 27. An app may be able to c…

▾ Sunlitapple · ipadosEPSS 0.15%via NVD
CVE-2026-84632High· 7.3
2w ago

The issue was addressed with improved memory handling

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. Processing a mali…

▾ Twilightapple · ipadosEPSS 0.17%via NVD
CVE-2026-84560Medium· 6.1
2w ago

An authorization issue was addressed with improved state management

An authorization issue was addressed with improved state management. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, visionOS 27, watchOS 27. An app may gain unauthorized access to Bluetooth.

▾ Sunlitapple · ipadosEPSS 0.14%via NVD
CVEs tagged “cve.org” — page 311 · VulnSea