VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18493 CVEsRSS

CVE-2026-82795Medium· 5.4
2w ago

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ SunlitContec Co., Ltd. · SV-CPT-MC310EPSS 0.24%via NVD
CVE-2026-82768High· 8.1
2w ago

Path traversal vulnerability exists in SGA1000

Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

▾ TwilightContec Co., Ltd. · SGA1000EPSS 0.49%via NVD
CVE-2026-82765High· 8.1
2w ago

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

▾ TwilightContec Co., Ltd. · FXA5000EPSS 0.49%via NVD
CVE-2026-71198High· 7.0
2w ago

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the imp…

▾ TwilightOpenStack · GlanceEPSS 0.45%via NVD
CVE-2023-50459Medium· 5.4
2w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend user…

▾ SunlitTYPO3 · femanagerEPSS 0.42%via NVD
CVE-2026-55073Medium· 6.2PoC
2w ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through t…

▾ TwilightKozea · WeasyPrintEPSS 0.22%via NVD
CVE-2026-54529Medium· 5.3
2w ago

SQLAdmin is a flexible Admin interface for SQLAlchemy models

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_l…

▾ Sunlitsmithyhq · sqladminEPSS 0.38%via NVD
CVE-2026-61534Critical· 9.1PoC
2w ago

Yayson is a library for serializing and reading JSON API data in JavaScript

Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/stor…

▾ Abyssalyayson · yaysonEPSS 0.84%via NVD
CVE-2026-59960High· 7.5
2w ago

Argos JavaScript provides official Argos SDKs for JavaScript

Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseComm…

▾ Twilightargos-ci · argos-javascriptEPSS 0.64%via NVD
CVE-2026-55416High· 8.8
2w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and group…

▾ Twilightpimcore · pimcoreEPSS 0.65%via NVD
CVE-2026-53495Medium· 6.8
2w ago

containerd is an open-source container runtime

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …

▾ Sunlitcontainerd · containerdEPSS 0.16%via NVD
CVE-2025-24890Medium· 6.8PoC
2w ago

gitoxide is an implementation of git written in Rust

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered e…

▾ TwilightGitoxideLabs · gitoxideEPSS 0.19%via NVD
CVE-2026-84445High· 8.7
2w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…

▾ Twilightgrpc · grpc-goEPSS 0.64%via NVD
CVE-2026-55451High· 8.3PoC
2w ago

gettext-converter provides gettext resource conversion utilities for JavaScript

gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number sign…

▾ Midnightlocize · gettext-converterEPSS 0.57%via NVD
CVE-2026-54150Medium· 6.9
2w ago

next-video is a library for adding video to Next.js applications

next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/…

▾ Sunlitmuxinc · next-videoEPSS 0.42%via NVD
CVE-2026-54155High· 7.7
2w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not ve…

▾ Twilightnode-opcua · node-opcuaEPSS 0.42%via NVD
CVE-2026-54156High· 7.5
2w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer…

▾ Twilightnode-opcua · node-opcuaEPSS 0.78%via NVD
CVE-2026-54175High· 7.6
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.55%via NVD
CVE-2026-54176Medium· 6.5
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccount…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.65%via NVD
CVE-2026-54177Medium· 6.6
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields methods uploadFi…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.93%via NVD
CVE-2026-54178High· 8.1
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDi…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.56%via NVD
CVE-2026-54180High· 7.6
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder …

▾ TwilightLaravel-Backpack · CRUDEPSS 0.46%via NVD
CVE-2026-54181Medium· 5.4
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.31%via NVD
CVE-2026-54182High· 8.1
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::mak…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.78%via NVD
CVE-2026-57570Medium· 6.5
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling t…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.44%via NVD
CVE-2026-55244Medium· 5.0PoC
2w ago

ASTEVAL is an evaluator of Python expressions and statements

ASTEVAL is an evaluator of Python expressions and statements. Prior to 1.0.9, FROM_PY in asteval/astutils.py exposes BaseException, SystemExit, KeyboardInterrupt, and GeneratorExit to expressions evaluated by asteval.Interpreter.eval(), …

▾ Twilightlmfit · astevalEPSS 0.18%via NVD
CVE-2026-55253High· 7.7
2w ago

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph

LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search()…

▾ Twilightlangchain-ai · langchain-mongodbEPSS 0.53%via NVD
CVE-2026-55236Medium· 5.9
2w ago

langgraph-api implements the LangGraph API for rapid development and testing

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-creation path authorizes the assistant attached to a run by dispatching assistants.search with an incomplete value inste…

▾ Sunlitlangchain-ai · langgraph-apiEPSS 0.26%via NVD
CVE-2026-55235Medium· 5.9
2w ago

langgraph-api implements the LangGraph API for rapid development and testing

langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a run or cron to specify a relative webhook target that is delivered through an in-process loopback transport, and the a…

▾ Sunlitlanggraph-api · langgraph-apiEPSS 0.36%via NVD
CVE-2026-54723Medium· 6.5
2w ago

devpi is a Python package index staging server and packaging, testing, and release tool

devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +…

▾ Sunlitdevpi · devpiEPSS 0.43%via NVD
CVEs tagged “cve.org” — page 336 · VulnSea