VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18482 CVEsRSS

CVE-2026-90961Critical· 9.3
2w ago

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() inp…

▾ MidnightMISP · MISPEPSS 0.64%via NVD
CVE-2026-90949High· 7.8
2w ago

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. …

▾ TwilightRed Hat · gimpEPSS 0.33%via NVD
CVE-2026-25687High· 8.1
2w ago

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…

▾ TwilightZscaler · Client ConnectorEPSS 0.38%via NVD
CVE-2026-15600High· 8.6
2w ago

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries without any sanitizat…

▾ TwilightAlior Bank · ratyEPSS 0.24%via NVD
CVE-2026-12985Medium· 6.8
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

▾ SunlitMattermost · MattermostEPSS 0.28%via NVD
CVE-2026-90957Medium· 5.1
2w ago

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the …

▾ SunlitMISP · MISPEPSS 0.40%via NVD
CVE-2026-90948High· 7.8
2w ago

A flaw was found in GIMP's ICO file loader

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocate…

▾ TwilightRed Hat · gimpEPSS 0.22%via NVD
CVE-2026-90941Medium· 4.3PoC
2w ago

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookI…

▾ Twilight201206030 · novel-plusEPSS 0.41%via NVD
CVE-2026-90940Medium· 5.3PoC
2w ago

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

▾ Twilight201206030 · novel-plusEPSS 0.55%via NVD
CVE-2026-90939Medium· 6.5PoC
2w ago

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations

novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks proper permission annotations. Authenticated attackers can retrieve password hashes and personal data including email add…

▾ Twilight201206030 · novel-plusEPSS 0.46%via NVD
CVE-2026-90788Medium· 4.7PoC
2w ago

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055

A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown functionality of the file /admin1.php/admin/template/index/path/.%40template%40default%40html%40label.html of the com…

▾ Twilightmagicblack · MacCMS10EPSS 2.2%via NVD
CVE-2026-90787High· 7.3PoC
2w ago

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e

A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is the function RegisterServlet.doPost of the file code/WebContent/register.html of the component Registration Workflow.…

▾ MidnightSoarkey · StudentManagementEPSS 0.54%via NVD
CVE-2026-90786Medium· 5.3PoC
2w ago

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3

A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the file src/compiler/semantics.c of the component Duplicate Symbol Handler. This manipulation causes reachable assertion. T…

▾ TwilightDvidelabs · flatccEPSS 0.72%via NVD
CVE-2026-90785Medium· 5.3PoC
2w ago

A vulnerability was found in Dvidelabs flatcc up to 0.6.3

A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/compiler/semantics.c of the component Struct Analysis. The manipulation results in reachable assertion. It is possible to…

▾ TwilightDvidelabs · flatccEPSS 0.72%via NVD
CVE-2026-86349Medium· 4.3
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU res…

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting depth in the server-side Markdown parser which allows an authenticated attacker to cause a denial of service (CPU res…

▾ SunlitMattermost · MattermostEPSS 0.36%via NVD
CVE-2026-86348Medium· 4.3
2w ago

Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.

Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenticated user to crash the plugin via a post-action request with an unexpected field type.. Mattermost Advisory ID: MMSA…

▾ SunlitMattermost · MattermostEPSS 0.36%via NVD
CVE-2026-84179Medium· 6.5
2w ago

Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo

Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and returned the result without redaction in the topology_conf field of TopologyPageInfo. The Storm UI copied that value verb…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.43%via NVD
CVE-2026-82920Medium· 5.5
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the access control policy update endpoint which allows a channel or team administrator to detach a system-assigned ABAC …

▾ SunlitMattermost · MattermostEPSS 0.26%via NVD
CVE-2026-82441Critical· 9.1
2w ago

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs

Description A submitted topology carries two lists of blobstore keys, `dependency_jars` and `dependency_artifacts`, which the client fills in after uploading the corresponding blobs. Nimbus performed no validation of their contents on t…

▾ MidnightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.27%via NVD
CVE-2026-82439Critical· 9.8
2w ago

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen

Description The DRPC server kept a map from function name to request queue and created an entry the first time a function name was seen. No code path ever removed an entry: request cleanup removed the request from its queue, and the shu…

▾ MidnightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.34%via NVD
CVE-2026-73370Critical· 9.8
2w ago

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate en…

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks performed by Reconciliation service's pull and push, being incomplete, could accept calls by administrator not provided with adequate en…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idm:syncope-core-idm-logicEPSS 0.51%via NVD
CVE-2026-73236High· 7.5
2w ago

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with…

Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm hierarchy and enforced via prefix matches. Due to incorrect implementation, two sibling Realms whose names begin with…

▾ TwilightApache Software Foundation · Apache SyncopeEPSS 0.36%via NVD
CVE-2026-73195High· 7.3
2w ago

Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes

Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet formula payload in one of their own plain attributes. When such users are included in a CSV export and the generated …

▾ TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.37%via NVD
CVE-2026-73191Medium· 6.1
2w ago

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is configured for CAS authentication, the target Apereo CAS instance's URL is calculated by unconditionally looking at client-…

▾ SunlitApache Software Foundation · org.apache.syncope:syncope-sraEPSS 0.31%via NVD
CVE-2026-7208Medium· 5.3
2w ago

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predic…

Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows authenticated attackers to interrupt active diagnostic processes by concurrently deleting output files written to predic…

▾ SunlitYealink · SIP-T33GEPSS 0.35%via NVD
CVE-2026-90938High· 8.6PoC
2w ago

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by th…

LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/plugin/ws) whose authentication is gated on plugin_debug_key, which defaults to an empty string and is never set by th…

▾ Midnightlangbot-app · LangBotEPSS 0.57%via NVD
CVE-2026-90935Medium· 4.3PoC
2w ago

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command

Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in the Mysqls.add API command. Attackers can supply a disallowed server index to create MySQL databases and users on for…

▾ Twilightfroxlor · froxlorEPSS 0.29%via NVD
CVE-2026-90933High· 7.1PoC
2w ago

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys

laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allows any authenticated user to read, overwrite, and delete premium module license keys. Attackers with low-privileged ac…

▾ Midnightlaradashboard · laradashboardEPSS 0.30%via NVD
CVE-2026-90930Medium· 6.8PoC
2w ago

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules

File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-de…

▾ Twilightfilebrowser · filebrowserEPSS 0.50%via NVD
CVE-2026-90928Medium· 6.5PoC
2w ago

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits

File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request co…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVEs tagged “cve.org” — page 334 · VulnSea