VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18493 CVEsRSS

CVE-2026-54542Low· 3.7
2w ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to 1.6.0, a malicious state-sync peer can crash a syncing node by sending a crafted TrieChunk whose proof contains a Tr…

▾ Sunlitnimiq · core-rs-albatrossEPSS 0.44%via NVD
CVE-2026-53718Medium· 6.4
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, an HTTPRoute can use an extension-managed custom backendRef to reference a backend resour…

▾ Sunlitenvoyproxy · gatewayEPSS 0.41%via NVD
CVE-2026-53716Medium· 6.5
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, getFileFromGZ in internal/wasm/httpfetcher.go calls io.ReadAll on a gzip.Reader without l…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53719Medium· 6.5
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, translateSecurityPolicyForRoute in internal/gatewayapi/securitypolicy.go dereferences a n…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53717Medium· 6.5
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, internal/wasm/imagefetcher.go follows tenant-controlled EnvoyExtensionPolicy spec.wasm[].…

▾ Sunlitenvoyproxy · gatewayEPSS 0.71%via NVD
CVE-2026-53715Medium· 5.3
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, HTTPServer.ServeHTTP in internal/wasm/httpserver.go reads the plain mappingPath2Cache map…

▾ Sunlitenvoyproxy · gatewayEPSS 0.47%via NVD
CVE-2026-53713Critical· 9.1
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, to_absolute_normalized_path in internal/gatewayapi/luavalidator/security.lua does not col…

▾ Midnightenvoyproxy · gatewayEPSS 0.43%via NVD
CVE-2026-53714High· 7.4
2w ago

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway

Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.7.4 and 1.8.1, the xDS gRPC server in GatewayNamespaceMode, configured through provider.kubernetes.deplo…

▾ Twilightenvoyproxy · gatewayEPSS 0.35%via NVD
CVE-2026-50270High· 7.5
2w ago

dd-trace-java is a Datadog APM client for Java

dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply…

▾ TwilightDataDog · dd-trace-javaEPSS 0.79%via NVD
CVE-2026-50276High· 7.5
2w ago

dd-trace-rb is Datadog's client library for Ruby

dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits app…

▾ TwilightDataDog · dd-trace-rbEPSS 0.79%via NVD
CVE-2026-54452Medium· 6.3
2w ago

safeurl is a server-side request forgery protection library

safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIP…

▾ Sunlitdoyensec · safeurlEPSS 0.52%via NVD
CVE-2026-54447High· 8.4
2w ago

garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities

garminconnect is a Python 3 API wrapper for Garmin Connect that retrieves statistics and manages activities. Prior to 0.3.5, garminconnect/client.py Client.dump creates the OAuth token directory and garmin_tokens.json without explicit ow…

▾ Twilightcyberjunky · python-garminconnectEPSS 0.15%via NVD
CVE-2026-54087High· 7.6
2w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline s…

▾ TwilightEasyCorp · EasyAdminBundleEPSS 0.40%via NVD
CVE-2026-54628High· 8.6PoC
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without …

▾ Midnightjulien040 · anyqueryEPSS 0.60%via NVD
CVE-2026-54629High· 7.5
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, a…

▾ Twilightjulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-50157Medium· 6.5
2w ago

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs

Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bear…

▾ Sunlitauth0 · symfonyEPSS 0.51%via NVD
CVE-2026-50006Critical· 9.1PoC
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server forwards unauthenticated SQL from its MySQL-compatible server port to SQLite without restricting ATTACH DATABASE filesystem targets. A remote attacke…

▾ Abyssaljulien040 · anyqueryEPSS 0.97%via NVD
CVE-2026-54334Critical· 9.8
2w ago

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, ReadCLen() in uefi_firmware/compression/Tiano/Decompress.c reads Number from GetBits(Sd, CBIT) with CBIT …

▾ Midnighttheopolis · uefi-firmware-parserEPSS 0.80%via NVD
CVE-2026-54333Critical· 9.8
2w ago

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files

UEFI Firmware Parser parses BIOS, Intel ME, and UEFI firmware structures including volumes, file systems, and files. Prior to 1.14, MakeTable() in uefi_firmware/compression/Tiano/Decompress.c does not validate that bit-length values read…

▾ Midnighttheopolis · uefi-firmware-parserEPSS 0.80%via NVD
CVE-2026-47253High· 7.3PoC
2w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll wi…

▾ Midnightjulien040 · anyqueryEPSS 0.44%via NVD
CVE-2026-47701High· 7.7
2w ago

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector

The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocator TargetAllocator instances with targetAllocator.prometheusCR.enabled set to true preserve a selected ServiceMonitor …

▾ Twilightopen-telemetry · opentelemetry-operatorEPSS 0.46%via NVD
CVE-2026-34151High· 8.2
2w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix w…

▾ Twilightxwiki · xwiki-platformEPSS 1.1%via NVD
CVE-2026-49250High· 8.7
2w ago

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property

Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or U…

▾ Twilightedmundhung · conformEPSS 0.51%via NVD
CVE-2026-44162Low· 2.7
2w ago

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd

fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_l…

▾ Sunlitfluent · fluent-plugin-s3EPSS 0.48%via NVD
CVE-2026-55832Medium· 6.1PoC
2w ago

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit

Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tens…

▾ Twilightsonos · tractEPSS 0.19%via NVD
CVE-2026-55091High· 7.5
2w ago

flat-to-nested converts a hierarchy from a flat representation to a nested representation

flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp…

▾ Twilightjoaonuno · flat-to-nested-jsEPSS 0.50%via NVD
CVE-2026-55795Medium· 6.9
2w ago

Craft Commerce is an ecommerce platform for Craft CMS

Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controllers/CartController.php activates its RateLimiter only when the number POST or GET parameter is supplied. An unauthent…

▾ Sunlitcraftcms · commerceEPSS 0.51%via NVD
CVE-2026-55837Medium· 6.8PoC
2w ago

dbt-mcp is a Model Context Protocol server for interacting with dbt

dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user com…

▾ Twilightdbt-labs · dbt-mcpEPSS 0.27%via NVD
CVE-2026-55846Medium· 6.2PoC
2w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/ma…

▾ Twilightallure-framework · allure2EPSS 0.18%via NVD
CVE-2026-55847Medium· 6.1
2w ago

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTra…

▾ Sunlitallure-framework · allure2EPSS 0.34%via NVD
CVEs tagged “cve.org” — page 338 · VulnSea