VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18480 CVEsRSS

CVE-2026-90685Low· 2.8PoC
2w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is requi…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-90684Low· 2.8PoC
2w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field_count of the file scenegraph/base_scenegraph.c of the component MP4Box. Executing a manipulation can lead to reachable asserti…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-90683Low· 3.3PoC
2w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in reachable assertion. Attacking locall…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90682Medium· 5.3PoC
2w ago

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3

A security vulnerability has been detected in Matthias-Wandel jhead up to 3.3. This impacts the function ProcessGpsInfo of the file gpsinfo.c of the component WebP EXIF Handler. Such manipulation of the argument TAG_GPS_LAT/TAG_GPS_LONG …

▾ TwilightMatthias-Wandel · jheadEPSS 0.17%via NVD
CVE-2026-90680Critical· 9.9
2w ago

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/…

▾ MidnightD-Link · DIR-823GEPSS 0.91%via NVD
CVE-2026-90622Low· 3.3PoC
2w ago

A security flaw has been discovered in GNU libredwg 0.13.4

A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to …

▾ TwilightGNU · libredwgEPSS 0.17%via NVD
CVE-2023-37252Low· 3.1PoC
2w ago

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.

▾ TwilightMediaWiki · CheckUserEPSS 0.24%via NVD
CVE-2023-34854Medium· 6.6
2w ago

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

HotelDruid before 3.0.6 has insufficient file upload sanitation in the backup/restore function.

▾ Sunlitdigitaldruid · HotelDruidEPSS 0.23%via NVD
CVE-2023-32778Low· 3.3
2w ago

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1

An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. An attacker can execute arbitrary code via ZIP upload.

▾ SunlitILIAS · ILIASEPSS 0.22%via NVD
CVE-2023-28148High· 7.2
2w ago

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

A bodyclass XSS issue was discovered in Paessler PRTG before 23.3.86.1520.

▾ TwilightPaessler · PRTG Network MonitorEPSS 0.21%via NVD
CVE-2023-24291Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the record length parameter.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24287Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the "M" command.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24285Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which is triggered when an unusually long move is executed.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24284Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the is_markable() function.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.12%via NVD
CVE-2023-24035Low· 3.5
2w ago

An issue was discovered in Nagios XI before 5.9.3

An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in t…

▾ SunlitNagios · Nagios XIEPSS 0.77%via NVD
CVE-2023-24034Low· 3.1
2w ago

An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3

An issue was discovered in twilio_ajax_handler.php in Nagios XI before 5.9.3. An attacker can force a user to visit a malicious site by using a open redirect vulnerability.

▾ SunlitNagios · Nagios XIEPSS 0.53%via NVD
CVE-2023-22632Low· 2.7
2w ago

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the FTP Server Count Sensor.

▾ SunlitPaessler · PRTG Network MonitorEPSS 0.22%via NVD
CVE-2023-22631Low· 2.7
2w ago

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.

PRTG Network Monitor before 23.1.82 allows remote attackers to write to files via the HTTP XML/REST Sensor.

▾ SunlitPaessler · PRTG Network MonitorEPSS 0.22%via NVD
CVE-2026-90688Medium· 6.5PoC
2w ago

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC

A vulnerability was identified in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. This issue affects the function formIPMacBindAdd of the component HTTP Handler. Such manipulation of the argument IPMacBindRule leads to stack-based buffer overf…

▾ TwilightTenda · W20EEPSS 0.71%via NVD
CVE-2026-90687Medium· 6.3PoC
2w ago

A vulnerability was determined in GPAC up to f1219cde

A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is poss…

▾ TwilightEPSS 0.51%via NVD
CVE-2026-25832Low· 3.7
2w ago

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

▾ SunlitTrustedFirmware · Mbed TLSEPSS 0.28%via NVD
CVE-2025-26790Low· 3.7
2w ago

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.

Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.

▾ SunlitWithSecure · AtlantEPSS 0.33%via NVD
CVE-2023-50461High· 8.8
2w ago

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3

An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured …

▾ TwilightTYPO3 · direct_mailEPSS 0.33%via NVD
CVE-2023-50460Medium· 5.4
2w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any f…

▾ SunlitTYPO3 · femanagerEPSS 0.24%via NVD
CVE-2023-46273High· 8.8
2w ago

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

▾ Twilightextremenetworks · IQ EngineEPSS 0.31%via NVD
CVE-2023-46035Medium· 5.9
2w ago

The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.

The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.

▾ Sunlitfnando · svg_optimizerEPSS 0.36%via NVD
CVE-2023-45858High· 8.6
2w ago

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

A directory traversal was identified in Paessler PRTG before 23.4.88.1429 that made it possible to read local files.

▾ TwilightPaessler · PRTG Network MonitorEPSS 0.66%via NVD
CVE-2023-45023Medium· 4.2
2w ago

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

The femanager extension 7 before 7.2.2 for TYPO3 has Incorrect Access Control: it lacks a check for permissions for the invitation component.

▾ SunlitTYPO3 · femanagerEPSS 0.14%via NVD
CVE-2023-37366Low· 2.8
2w ago

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…

An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem Exynos 9810, Exynos 9610, Exynos 9820, Exynos 980, Exynos 850, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, Exynos 1380, Exynos 1330, Exyn…

▾ SunlitSamsung · Exynos 850 firmwareEPSS 0.09%via NVD
CVE-2026-90702Critical· 9.1PoC
2w ago

A flaw has been found in D-Link DWR-M921 1.1.52

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The explo…

▾ AbyssalD-Link · DWR-M921EPSS 3.6%via NVD
CVEs tagged “cve.org” — page 328 · VulnSea