VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18480 CVEsRSS

CVE-2026-90700Medium· 6.3PoC
2w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/pro_edit1.php. Such manipulation of the argument prodcode leads to sql injection. The attack ca…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90698Medium· 5.3PoC
2w ago

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43

A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_command_asciiauth of the file proto_text.c of the component mcmc Tokenizer. The manipulation results in out-of-bounds…

▾ TwilightRed Hat · memcachedEPSS 0.86%via NVD
CVE-2026-90697Medium· 4.3PoC
2w ago

A vulnerability was identified in SourceCodester Inventory Management System 1.0

A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file invoice.php. The manipulation of the argument ID leads to authorization bypass. It is possible to initiate the att…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.41%via NVD
CVE-2026-90695Low· 3.5PoC
2w ago

A vulnerability was found in SourceCodester Inventory Management System 1.0

A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /api/vendors_handler.php of the component Vendor Management. Performing a manipulation re…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-90693Critical· 9.9PoC
2w ago

A flaw has been found in D-Link DIR-878 120B05

A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the a…

▾ AbyssalD-Link · DIR-878EPSS 0.91%via NVD
CVE-2026-90692Critical· 9.9
2w ago

A vulnerability was detected in D-Link DIR-878 120B05

A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer ov…

▾ MidnightD-Link · DIR-878EPSS 0.91%via NVD
CVE-2026-90691High· 8.3PoC
2w ago

A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is the function FileOperationsManager of the file hexstrike_server.py of the component API Files Endpoi…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.62%via NVD
CVE-2026-90690High· 7.3PoC
2w ago

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected element is the function subprocess.Popen of the file hexstrike_server.py of the component API Tools Endpoint. Executing a m…

▾ Midnight0x4m4 · HexStrike AIEPSS 2.1%via NVD
CVE-2026-85125Medium· 5.4
2w ago

The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation

The Android application "YAMAP -Social Trekking GPS App" contains an improper access control vulnerability in its WebView implementation. The in-app browser may cause information leakage from the app or redirect users to unintended websi…

▾ SunlitYAMAP INC. · YAMAP -Social Trekking GPS AppEPSS 0.34%via NVD
CVE-2026-82796Medium· 5.4
2w ago

SolarView Compact contains a cross-site scripting vulnerability in Image Management

SolarView Compact contains a cross-site scripting vulnerability in Image Management. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ SunlitContec Co., Ltd. · SV-CPT-MC310EPSS 0.24%via NVD
CVE-2026-82789High· 8.8
2w ago

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS)

An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

▾ TwilightContec · CONPROSYS HMI System(CHS)EPSS 0.55%via NVD
CVE-2024-23176Medium· 5.4PoC
2w ago

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2

An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

▾ TwilightRed Hat · MassMessageEPSS 0.21%via NVD
CVE-2023-51769Medium· 6.1
2w ago

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

▾ SunlitFrappe · FrappeEPSS 0.19%via NVD
CVE-2026-90895High· 8.4
2w ago

Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web applicat…

Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application, causing several authorization inconsistencies. The patch shows that CLI access could differ from the web applicat…

▾ TwilightMISP · MISPEPSS 0.15%via NVD
CVE-2026-90894High· 7.8
2w ago

Parallels Desktop runs prl_disp_service as root

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. No Parallels signature. No admin group. After login, Pr…

▾ TwilightParallels · Parallels DesktopEPSS 0.17%via NVD
CVE-2026-90893Medium· 5.1
2w ago

MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController

MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, setHomePage, and eventIndexColumnToggle were explicitly added to the Security component's unlockedActions list, which di…

▾ SunlitMISP · MISPEPSS 0.26%via NVD
CVE-2026-90705Medium· 6.6PoC
2w ago

A vulnerability was determined in D-Link DWR-M921 1.1.52

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command inj…

▾ TwilightD-Link · DWR-M921EPSS 2.3%via NVD
CVE-2026-90699Critical· 9.9PoC
2w ago

A weakness has been identified in D-Link DWR-M920 1.1.7

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated…

▾ AbyssalD-Link · DWR-M920EPSS 3.3%via NVD
CVE-2026-90694Low· 3.5PoC
2w ago

A vulnerability has been found in SourceCodester Inventory Management System 1.0

A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of the file /api/customers_handler.php of the component Customer Management Module. Such manipulation of the argument Custo…

▾ TwilightSourceCodester · Inventory Management SystemEPSS 0.35%via NVD
CVE-2026-89321Medium· 4.3
2w ago

Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}…

Publishing limits the compressed size of a VSIX (ovsx.publishing.max-content-size, 512 MB by default) but nothing limited how large an entry becomes when opened. On the first request to /vscode/unpkg/{namespace}/{extension}/{version}…

▾ SunlitEclipse Foundation · Eclipse OpenVSXEPSS 0.44%via NVD
CVE-2026-88932Medium· 5.3
2w ago

multer is a Node.js middleware for handling multipart/form-data uploads

multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup a…

▾ SunlitRed Hat · Red Hat Developer HubEPSS 0.53%via NVD
CVE-2026-87802Critical· 9.1
2w ago

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…

Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permission…

▾ MidnightApache Software Foundation · org.apache.syncope:syncope-sraEPSS 0.28%via NVD
CVE-2026-87785Critical· 9.1
2w ago

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after comp…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.55%via NVD
CVE-2026-87779High· 7.5
2w ago

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters

Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key va…

▾ TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.43%via NVD
CVE-2026-86460Critical· 9.8
2w ago

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. U…

Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. U…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-neo4jEPSS 0.60%via NVD
CVE-2026-72524High· 8.8
2w ago

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 …

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access or modify data they are not authorized to. This issue affects Apache Doris: from 3.1.0 through 3.1.*, from 4.0.0 …

▾ TwilightApache Software Foundation · Apache DorisEPSS 0.47%via NVD
CVE-2026-68570Medium· 6.5
2w ago

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apa…

Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access data they are not authorized to read, resulting in unauthorized disclosure of information. This issue affects Apa…

▾ SunlitApache Software Foundation · Apache DorisEPSS 0.38%via NVD
CVE-2026-14259Medium· 4.3
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or P…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board creation permissions when importing archive files which allows an authenticated non-guest team member to create Open or P…

▾ SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-11993Medium· 4.3
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce the limit of concurrent files being processed and handled failed files, which allows a user with permission to upload …

▾ SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-9812Medium· 6.5
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run prope…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run prope…

▾ SunlitMattermost · MattermostEPSS 0.37%via NVD
CVEs tagged “cve.org” — page 329 · VulnSea