VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18482 CVEsRSS

CVE-2026-78336High· 7.5
2w ago

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains al…

▾ TwilightApache Software Foundation · org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logicEPSS 0.43%via NVD
CVE-2026-78330Critical· 9.8
2w ago

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.64%via NVD
CVE-2026-78318Medium· 6.1
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

▾ SunlitApache Software Foundation · org.apache.syncope.client.idrepo:syncope-client-idrepo-common-uiEPSS 0.26%via NVD
CVE-2026-77883Medium· 4.9
2w ago

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

▾ SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-apiEPSS 0.39%via NVD
CVE-2026-90715High· 7.3PoC
2w ago

A security vulnerability has been detected in marcobambini Gravity up to 0.9.7

A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The atta…

▾ Midnightmarcobambini · GravityEPSS 0.64%via NVD
CVE-2024-58383High· 7.3PoC
2w ago

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. O…

▾ Midnightfroxlor · froxlorEPSS 0.10%via NVD
CVE-2026-90937Critical· 9.9
2w ago

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal new…

▾ Midnightfroxlor · froxlorEPSS 0.45%via NVD
CVE-2026-90936Medium· 4.3PoC
2w ago

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying a…

▾ Twilightfroxlor · froxlorEPSS 0.31%via NVD
CVE-2026-90934Medium· 4.3
2w ago

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by ex…

▾ Sunlitespocrm · espocrmEPSS 0.30%via NVD
CVE-2026-90932High· 7.2PoC
2w ago

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file…

▾ Midnightlaradashboard · laradashboardEPSS 0.82%via NVD
CVE-2026-90931Medium· 5.4PoC
2w ago

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user incl…

▾ Twilightlaradashboard · laradashboardEPSS 0.24%via NVD
CVE-2026-90929High· 8.1
2w ago

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go)

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a tar…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-90927Medium· 6.5PoC
2w ago

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-90716Medium· 5.5PoC
2w ago

A vulnerability was detected in marcobambini Gravity up to 0.9.7

A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bou…

▾ Twilightmarcobambini · GravityEPSS 0.36%via NVD
CVE-2026-77181Critical· 9.8
2w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

▾ MidnightApache Software Foundation · org.apache.syncope.core.am:syncope-core-am-logicEPSS 0.51%via NVD
CVE-2026-77051Critical· 9.8
2w ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.60%via NVD
CVE-2026-73668Critical· 9.8
2w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idm:syncope-core-idm-logicEPSS 0.51%via NVD
CVE-2026-73579Critical· 9.8
2w ago

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-commonEPSS 0.51%via NVD
CVE-2026-90955Medium· 4.6
2w ago

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLoga…

▾ SunlitMISP · MISPEPSS 0.16%via NVD
CVE-2026-78299Critical· 9.1
2w ago

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

▾ MidnightEclipse Foundation · Eclipse Embedded CDT (C/C++ Development Tools)EPSS 0.54%via NVD
CVE-2026-75030Critical· 9.8
2w ago

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idrepo:syncope-core-idrepo-logicEPSS 0.62%via NVD
CVE-2026-75015Medium· 4.9
2w ago

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators…

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators…

▾ SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.39%via NVD
CVE-2026-73470Critical· 9.8
2w ago

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.51%via NVD
CVE-2026-90792Medium· 4.3PoC
2w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereferen…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-90681Low· 3.3PoC
2w ago

A weakness has been identified in Matthias-Wandel jhead up to 3.3

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The expl…

▾ TwilightMatthias-Wandel · jheadEPSS 0.16%via NVD
CVE-2026-90620High· 7.3PoC
2w ago

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation cau…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.65%via NVD
CVE-2026-90614Medium· 6.3
2w ago

A weakness has been identified in FedML-AI FedML up to 0.9.6

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backen…

▾ SunlitFedML-AI · FedMLEPSS 0.43%via NVD
CVE-2026-90609Low· 3.3PoC
2w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be p…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-73178High· 7.5
2w ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. Thes…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. Thes…

▾ TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.43%via NVD
CVE-2023-50462Medium· 5.3
2w ago

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to…

▾ SunlitTYPO3 · content_consentEPSS 0.27%via NVD
CVEs tagged “cve.org” — page 332 · VulnSea