VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18480 CVEsRSS

CVE-2026-90898Critical· 9.8PoC
2w ago

Bifrost registers MCP clients through its management API

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_conf…

▾ Abyssalmaximhq · github.com/maximhq/bifrost/transportsEPSS 0.62%via NVD
CVE-2026-90891Medium· 5.5
2w ago

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restri…

▾ SunlitASRock · ASRock Polychrome SYNC/RGB for MBEPSS 0.13%via NVD
CVE-2026-90890Medium· 5.5
2w ago

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc

ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unval…

▾ SunlitASRock · ASRock Polychrome SYNC/RGB for MBEPSS 0.14%via NVD
CVE-2026-90708High· 7.3PoC
2w ago

A weakness has been identified in Yot CMS up to 3.3.1

A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injectio…

▾ MidnightYot · CMSEPSS 0.41%via NVD
CVE-2026-90707High· 8.3
2w ago

A security flaw has been discovered in Open5GS up to 2.7.x

A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-90689High· 8.8
2w ago

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC

A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuthWhiteUser. Performing a manipulation of the argument webAuthWhiteUserIndex results in stack-based buffer overflow. Th…

▾ TwilightTenda · W20EEPSS 0.85%via NVD
CVE-2026-89180High· 7.5
2w ago

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

▾ TwilightThinking Software Technology · EFenceEPSS 0.56%via NVD
CVE-2026-8821High· 7.1
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrar…

▾ TwilightMattermost · MattermostEPSS 0.29%via NVD
CVE-2026-82788Medium· 6.1
2w ago

Cross-site scripting vulnerability exists in CPSL-08P1EN

Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · CPSL-08P1ENEPSS 0.26%via NVD
CVE-2026-82787Critical· 9.8
2w ago

Missing authentication for critical function vulnerability exists in CPSL-08P1EN

Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.

▾ MidnightContec Co., Ltd. · CPSL-08P1ENEPSS 0.67%via NVD
CVE-2026-82786Medium· 6.3
2w ago

Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.30%via NVD
CVE-2026-82785Medium· 4.3
2w ago

Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.49%via NVD
CVE-2026-82784Medium· 6.5
2w ago

Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*

Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values an…

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.34%via NVD
CVE-2026-82783Medium· 4.2
2w ago

Plaintext storage of a password issue exists in CONPROSYS nano Series

Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.18%via NVD
CVE-2026-82782Medium· 4.3
2w ago

Out-of-bounds write vulnerability exists in CONPROSYS nano Series

Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.46%via NVD
CVE-2026-82781Medium· 5.4
2w ago

Cross-site scripting vulnerability exists in CONPROSYS nano Series

Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*EPSS 0.24%via NVD
CVE-2026-82780High· 8.8
2w ago

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series

Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.

▾ TwilightContec Co., Ltd · CPS-TM341G5MB-ADSC1-931EPSS 0.61%via NVD
CVE-2026-82779High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to …

▾ TwilightContec Co., Ltd · CPS-TM341G5MB-ADSC1-931EPSS 1.9%via NVD
CVE-2026-82778Medium· 4.3
2w ago

An exposure of information through directory listing issue exists in CONPROSYS PAC Series

An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

▾ SunlitContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 0.45%via NVD
CVE-2026-82763Medium· 5.4
2w ago

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series

Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · FXA5000EPSS 0.24%via NVD
CVE-2026-82232Critical· 9.8
2w ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging u…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.60%via NVD
CVE-2026-5132Medium· 6.5
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP me…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP me…

▾ SunlitMattermost · MattermostEPSS 0.41%via NVD
CVE-2026-20773High· 8.5
2w ago

A role-based access control issue was identified in the administrative expression evaluation functionality

A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissi…

▾ TwilightPing Identity · PingFederateEPSS 0.21%via NVD
CVE-2026-15814Medium· 6.5
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server me…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount of memory allocated when decoding uploaded image files which allows an authenticated user to cause excessive server me…

▾ SunlitMattermost · MattermostEPSS 0.24%via NVD
CVE-2026-14344Medium· 4.3
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-creation permission which allows an unauthorized authenticated user to create boards via the board duplicate, boards-…

▾ SunlitMattermost · MattermostEPSS 0.15%via NVD
CVE-2026-13417Medium· 4.3
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash th…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type of `fields.properties` on block creation which allows an authenticated user with editor access to a board to crash th…

▾ SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-12882Medium· 4.3
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown autolinks with unmatched trailing closing parentheses in linear time, which allows an authenticated user with permission…

▾ SunlitMattermost · MattermostEPSS 0.21%via NVD
CVE-2026-12518High· 8.5
2w ago

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

▾ TwilightLogitech · Logi Options+EPSS 0.11%via NVD
CVE-2026-10556Medium· 5.3
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entries in Microsoft Graph webhook notification payloads, which allows an unauthenticated attacker to crash the Microsoft…

▾ SunlitMattermost · MattermostEPSS 0.25%via NVD
CVE-2026-10542Medium· 5.0
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpo…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel action ownership which allows channel managers to update actions in other channels via the channel action update endpo…

▾ SunlitMattermost · MattermostEPSS 0.13%via NVD
CVEs tagged “cve.org” — page 330 · VulnSea