VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18479 CVEsRSS

CVE-2026-91081Medium· 5.8
2w ago

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-tim…

▾ Sunlitsuitenumerique · docsEPSS 0.43%via NVD
CVE-2026-91080High· 7.5PoC
2w ago

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with inva…

▾ Midnightadnanh · webhookEPSS 0.66%via NVD
CVE-2026-91079High· 8.5
2w ago

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which …

▾ Twilighthcengineering · platformEPSS 0.37%via NVD
CVE-2026-90946High· 7.5PoC
2w ago

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary director…

▾ MidnightAsyncFuncAI · deepwiki-openEPSS 0.51%via NVD
CVE-2026-90945Critical· 9.8PoC
2w ago

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrativ…

▾ Abyssalcrawlab-team · crawlabEPSS 0.77%via NVD
CVE-2026-90944High· 8.2PoC
2w ago

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with fo…

▾ Midnightkrayin · laravel-crmEPSS 0.66%via NVD
CVE-2026-90942Critical· 9.6PoC
2w ago

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key…

▾ Abyssalcasdoor · casdoorEPSS 0.28%via NVD
CVE-2026-90807Medium· 6.3PoC
2w ago

A vulnerability was found in nanocoai NanoClaw up to 2.1.17

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link…

▾ Twilightnanocoai · NanoClawEPSS 0.43%via NVD
CVE-2026-90806Medium· 6.3
2w ago

A vulnerability has been found in DjangoCRM django-crm up to 1.2

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing au…

▾ SunlitDjangoCRM · django-crmEPSS 0.37%via NVD
CVE-2026-86836High· 8.4
2w ago

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a dir…

▾ TwilightEclipse Foundation · Eclipse AnkaiosEPSS 0.11%via NVD
CVE-2026-85921High· 8.2
2w ago

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_26h1EPSS 0.35%via NVD
CVE-2026-85892High· 7.8
2w ago

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · edge_chromiumEPSS 0.20%via NVD
CVE-2026-73494High· 7.4
2w ago

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org…

▾ Twilighthttp4s · blazeEPSS 0.63%via NVD
CVE-2026-57583Low· 3.3
2w ago

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts

OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6…

▾ SunlitOpenZeppelin · contracts-wizardEPSS 0.19%via NVD
CVE-2026-57581Medium· 5.3
2w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMi…

▾ Sunlitriganti · dotvvmEPSS 0.59%via NVD
CVE-2026-57578Critical· 9.2
2w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewMod…

▾ Midnightriganti · dotvvmEPSS 0.62%via NVD
CVE-2026-57577High· 8.2
2w ago

DotVVM is an open source MVVM framework for web applications

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtrackin…

▾ Twilightriganti · dotvvmEPSS 0.58%via NVD
CVE-2026-70658High· 7.4PoC
2w ago

Pay is a payments engine for Ruby on Rails 6.0 and higher

Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 H…

▾ Midnightpay-rails · payEPSS 0.58%via NVD
CVE-2026-19542Medium· 5.6
2w ago

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an expl…

▾ SunlitThe GNU C Library · glibcEPSS 0.23%via NVD
CVE-2026-90805High· 7.3PoC
2w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd ca…

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.43%via NVD
CVE-2026-91021Medium· 5.4
2w ago

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values

Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allow…

▾ SunlitTrilium · Trillium NotesEPSS 0.23%via NVD
CVE-2026-19499High· 7.7
2w ago

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path tha…

▾ TwilightThe GNU C Library · glibcEPSS 0.30%via NVD
CVE-2026-59178Critical· 9.8
2w ago

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software

ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and…

▾ Midnightesphome · device-builderEPSS 0.78%via NVD
CVE-2026-90804Medium· 4.8PoC
2w ago

A vulnerability was detected in GNU Binutils 2.47

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument…

▾ Twilightgnu · binutilsEPSS 0.20%via NVD
CVE-2026-90803Medium· 5.3PoC
2w ago

A security vulnerability has been detected in GNU Binutils 2.47

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads …

▾ Twilightgnu · binutilsEPSS 0.20%via NVD
CVE-2026-90802Medium· 4.4PoC
2w ago

A weakness has been identified in GNU Binutils 2.47

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has b…

▾ Twilightgnu · binutilsEPSS 0.18%via NVD
CVE-2026-90801Medium· 5.3PoC
2w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local…

▾ Twilightgnu · binutilsEPSS 0.21%via NVD
CVE-2026-90796Medium· 6.3PoC
2w ago

A vulnerability was identified in itsourcecode Leave Management System 1.0

A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated r…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-61701High· 8.8
2w ago

Laravel MagicLink creates links for authentication without a password or for accessing private content

Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them t…

▾ Twilightcesargb · laravel-magiclinkEPSS 0.76%via NVD
CVE-2026-57579High· 7.5PoC
2w ago

Alchemy is an open source content management system engine written in Ruby on Rails

Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested endpoint implemented by Api::PagesController#nested in app/control…

▾ MidnightAlchemyCMS · alchemy_cmsEPSS 0.65%via NVD
CVEs tagged “cve.org” — page 325 · VulnSea