Tagged “cve.org”
CVEs tagged cve.org, newest first.
18493 CVEsRSS
CVE-2026-55866Low· 3.7SpiceDB is an open source database system for creating and managing security-critical application permissions
SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or…
CVE-2026-47256Medium· 5.3PoCOpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs
OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter r…
CVE-2026-55093Medium· 6.1PoCTract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit
Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.16, 0.22.2, and 0.23.1, tract-nnef uses unchecked usize multiplication in nnef/src/tensors.rs read_tensor for attacker-controlled tensor di…
CVE-2026-90679Medium· 4.3Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification
Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an …
CVE-2026-90678High· 7.5An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5
An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3 frontend: HAProxy must be built with QUIC support and configured with a QUIC bind listener, and the affected traffic…
CVE-2026-90668High· 7.5The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request w…
The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which allows remote attackers to cause a denial of service (memory consumption and unresponsive server) via an HTTP request w…
CVE-2026-90651High· 8.1Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default
Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from socket.yml, the …
CVE-2026-90498High· 7.3PoCA vulnerability was identified in lenve vhr 1.0-SNAPSHOT
A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The …
CVE-2026-90497Low· 3.5PoCA vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11
A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the function getTitle of the file application/views/task/add_task.php of the component Task Title Output. Executing a manipulati…
CVE-2026-90496Medium· 4.7PoCA vulnerability was found in Fengoffice Feng Office up to 3.11.13.11
A vulnerability was found in Fengoffice Feng Office up to 3.11.13.11. Affected is the function update_system_module_order/update_dimension_order of the file application/controllers/MoreController.class.php of the component Reorder Handle…
CVE-2026-90495High· 7.3PoCA vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11
A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance->findAll of the file application/models/CompanyWebsite.class.php of the component Legacy API. Such manipulation of th…
CVE-2026-90494Medium· 5.3A flaw has been found in restify node-restify up to 12.0.0
A flaw has been found in restify node-restify up to 12.0.0. This affects the function serveStatic in the library /lib/plugins/static.js. This manipulation causes path traversal. The attack can be initiated remotely. The vendor was contac…
CVE-2026-90493High· 8.8PoCA vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper acces…
CVE-2026-90492Medium· 6.3A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0
A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os com…
CVE-2026-90491Medium· 6.3PoCA weakness has been identified in sanjevirau gsubs up to 1.0.3
A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code inj…
CVE-2026-90490Medium· 6.3PoCA security flaw has been discovered in lenve vhr 1.0-SNAPSHOT
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remot…
CVE-2026-90489Low· 3.5PoCA vulnerability was identified in Xuxueli xxl-job up to 3.5.0
A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack can be executed r…
CVE-2026-90488Medium· 6.3PoCA vulnerability was determined in Xuxueli xxl-job up to 3.4.2
A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation causes code injection.…
CVE-2026-90509High· 7.3PoCA weakness has been identified in dromara orion-visor up to 2.5.7
A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The …
CVE-2026-90504High· 7.3PoCA vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46
A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted element is the function authorized. The manipulation of the argument SECRET_KEY leads to missing authentication. The a…
CVE-2026-90503Low· 2.3A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714
A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information d…
CVE-2026-90502Low· 3.5PoCA vulnerability was detected in stilleshan ServerStatus 1.0/2.0
A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/main.cpp of the component Stats Generation. Performing a manipulation of the argument custom results in cross site sc…
CVE-2026-90501Medium· 6.3PoCA security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. …
CVE-2026-90500Medium· 6.3PoCA weakness has been identified in lenve vhr 1.0-SNAPSHOT
A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upl…
CVE-2026-90499Medium· 5.4PoCA security flaw has been discovered in lenve vhr 1.0-SNAPSHOT
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper…
CVE-2026-90775Medium· 6.5PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index
PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out…
CVE-2026-90774High· 7.5PoCrustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks
rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header …
CVE-2026-90773Low· 3.2procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column
procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line argum…
CVE-2026-90772High· 7.6PoCAmundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components
Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerro…
CVE-2026-90771Low· 3.7PoC⚖ disputedjoi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code
joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the retur…