VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18480 CVEsRSS

CVE-2026-90710High· 7.3PoC
2w ago

A vulnerability was determined in taisan tarzan-cms 1.0.0

A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipu…

▾ Midnighttaisan · tarzan-cmsEPSS 0.50%via NVD
CVE-2026-85195High· 7.5
2w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options b…

▾ Twilightregularlabs.com · plg_system_articlesanywhereEPSS 0.42%via NVD
CVE-2026-85192Critical· 9.4
2w ago

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions…

▾ Midnightregularlabs.com · plg_system_conditionalcontentEPSS 0.67%via NVD
CVE-2026-85188Medium· 6.9
2w ago

Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditio…

Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditio…

▾ Sunlitregularlabs.com · plg_system_advancedmodulesEPSS 0.37%via NVD
CVE-2026-82777High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to…

▾ TwilightContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 1.9%via NVD
CVE-2026-82776Medium· 6.1
2w ago

Cross-site scripting vulnerability exists in CONPROSYS PAC Series

Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · Integrated Type CPS-PC341[][]-*-9201EPSS 0.26%via NVD
CVE-2026-82775Medium· 4.3
2w ago

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the dir…

▾ SunlitContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 0.45%via NVD
CVE-2026-82774High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may …

▾ TwilightContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 1.9%via NVD
CVE-2026-82773Medium· 6.1
2w ago

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series

Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · M2M Gateway Integrated Type CPS-MG341*EPSS 0.26%via NVD
CVE-2026-82772High· 8.8
2w ago

Buffer overflow vulnerability exists in Contec EC1000 series

Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

▾ TwilightContec Co., Ltd. · ECE1000EPSS 0.66%via NVD
CVE-2026-82771Medium· 5.4
2w ago

Cross-site scripting vulnerability exists in Contec EC1000 series

Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · ECE1000EPSS 0.24%via NVD
CVE-2026-82770High· 8.8
2w ago

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series

Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

▾ TwilightContec Co., Ltd. · RP-WAH-SR1EPSS 0.66%via NVD
CVE-2026-82769Medium· 5.4
2w ago

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series

Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · RP-WAH-SR1EPSS 0.24%via NVD
CVE-2026-82767Medium· 5.2
2w ago

Cross-site scripting vulnerability exists in SGA1000

Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · SGA1000EPSS 0.24%via NVD
CVE-2026-82766High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ TwilightContec Co., Ltd. · SGA1000EPSS 1.9%via NVD
CVE-2026-82764Medium· 4.3
2w ago

Cross-site request forgery vulnerability exists in multiple Contec products

Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.

▾ SunlitContec Co., Ltd. · FXA5000EPSS 0.19%via NVD
CVE-2026-82762High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be execute…

▾ TwilightContec Co., Ltd. · FXA5000EPSS 1.9%via NVD
CVE-2026-68955High· 7.8
2w ago

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries

The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the p…

▾ TwilightRakuten Kobo Inc. · The installer for Rakuten Kobo Desktop Application (Windows version)EPSS 0.18%via NVD
CVE-2026-16726Medium· 6.8
2w ago

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

▾ Sunlitpanasonic · PANATERM v6EPSS 0.11%via NVD
CVE-2026-90709Medium· 4.7PoC
2w ago

A security vulnerability has been detected in Yot CMS up to 3.3.1

A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code inje…

▾ TwilightYot · CMSEPSS 0.41%via NVD
CVE-2026-88852High· 7.5
2w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into sa…

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into sa…

▾ Twilightregularlabs.com · plg_system_snippetsEPSS 0.42%via NVD
CVE-2026-85196Medium· 5.3
2w ago

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

▾ Sunlitregularlabs.com · plg_system_articlesanywhereEPSS 0.44%via NVD
CVE-2026-82794High· 8.8
2w ago

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ TwilightContec Co., Ltd. · SV-CPT-MC310EPSS 1.9%via NVD
CVE-2026-82793High· 7.2
2w ago

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed o…

▾ TwilightContec Co., Ltd. · CAN-2-WFEPSS 0.63%via NVD
CVE-2026-82792Medium· 5.2
2w ago

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · CAN-2-WFEPSS 0.24%via NVD
CVE-2026-90713Low· 3.3PoC
2w ago

A security flaw has been discovered in vllm-project vLLM up to 0.29.0

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipula…

▾ Twilightvllm-project · vLLMEPSS 0.16%via NVD
CVE-2026-85190High· 7.5
2w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A cr…

▾ Twilightregularlabs.com · plg_system_quickindexEPSS 0.42%via NVD
CVE-2026-82791High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may b…

▾ TwilightContec Co., Ltd. · CAN-2-WFEPSS 1.9%via NVD
CVE-2026-90714Medium· 6.3PoC
2w ago

A weakness has been identified in marcobambini Gravity up to 0.9.7

A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruption. The attack is …

▾ Twilightmarcobambini · GravityEPSS 0.47%via NVD
CVE-2026-82790Medium· 5.4
2w ago

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · PC-HELPER Wireless I/O DIO-0404RY-LWFEPSS 0.24%via NVD
CVEs tagged “cve.org” — page 331 · VulnSea