VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18493 CVEsRSS

CVE-2026-90770High· 8.8
2w ago

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation

Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions …

▾ Twilightopenspug · spugEPSS 1.3%via NVD
CVE-2026-90769High· 7.7PoC
2w ago

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services

Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata,…

▾ Midnightlfnovo · open-notebookEPSS 0.41%via NVD
CVE-2026-90768High· 8.1
2w ago

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users

CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary…

▾ Twilightkevoreilly · CAPEv2EPSS 0.43%via NVD
CVE-2026-90767Medium· 6.5PoC
2w ago

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files

Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with opti…

▾ Twilightfroxlor · FroxlorEPSS 0.43%via NVD
CVE-2026-90562High· 8.1PoC
2w ago

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint

LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace t…

▾ Midnightlangbot-app · LangBotEPSS 0.73%via NVD
CVE-2026-90561High· 8.7
2w ago

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text

Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store m…

▾ Twilightstrapi · strapiEPSS 0.43%via NVD
CVE-2026-90516High· 7.3PoC
2w ago

A vulnerability was found in SourceCodester School Registration and Fee System 1.0

A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql inj…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90515High· 7.3PoC
2w ago

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0

A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead …

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90514High· 7.3PoC
2w ago

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0

A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is poss…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90513Medium· 6.5
2w ago

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d

A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation …

▾ Sunlitsimalexan · api-lambda-send-email-sesEPSS 0.76%via NVD
CVE-2026-90511Medium· 6.3PoC
2w ago

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea

A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface…

▾ TwilightGongShengyue · OnlineBooksEPSS 0.32%via NVD
CVE-2026-90510High· 8.3PoC
2w ago

A security vulnerability has been detected in dromara orion-visor up to 2.5.7

A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/jav…

▾ Midnightdromara · orion-visorEPSS 0.50%via NVD
CVE-2026-90508Low· 3.4PoC
2w ago

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Pe…

▾ TwilightChengdu Qilu Technology · LudashiEPSS 0.16%via NVD
CVE-2026-90507Medium· 6.3PoC
2w ago

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was identified in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. Affected is the function get_surge_subscription of the file services/subscription.py of the component Subscription Handler. Such ma…

▾ Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.38%via NVD
CVE-2026-90506Medium· 5.0PoC
2w ago

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was determined in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This impacts an unknown function of the component Save Account Job. This manipulation causes race condition. The attack may be init…

▾ Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.25%via NVD
CVE-2026-90505Medium· 5.0PoC
2w ago

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46

A vulnerability was found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. This affects the function doUpdateLicenseKey. The manipulation results in race condition. The attack can be launched remotely. The attac…

▾ Twilightvvbbnn00 · WARP-Clash-APIEPSS 0.25%via NVD
CVE-2026-89080High· 7.5
2w ago

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypa…

The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an account's completed email two-factor enrolment, allowing an attacker who already knows the account's password to bypa…

▾ TwilightEPSS 0.34%via NVD
CVE-2026-88995Medium· 5.3
2w ago

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, i…

The Bookit — Booking & Appointment Calendar WordPress plugin before 2.6.0.1 does not properly restrict the data returned by an availability-check request, allowing unauthenticated users to retrieve other customers' appointment details, i…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-88912Medium· 4.2
2w ago

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, …

The rtMedia for WordPress, BuddyPress and bbPress WordPress plugin before 4.7.12 does not check ownership before changing the privacy level of an activity and its attached media, relying only on a nonce shared with every logged-in user, …

▾ SunlitEPSS 0.19%via NVD
CVE-2026-88764Medium· 5.4
2w ago

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-price…

The Simple Membership WordPress plugin before 4.7.8 does not validate that the membership level supplied in a PayPal payment notification matches the level configured for the paid payment button, allowing members to pay for a lower-price…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-86407Low· 3.7
2w ago

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, …

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, …

▾ SunlitEPSS 0.28%via NVD
CVE-2026-86406High· 7.5
2w ago

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated …

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated …

▾ TwilightEPSS 0.32%via NVD
CVE-2026-80072Medium· 4.7
2w ago

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which …

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which …

▾ SunlitEPSS 0.29%via NVD
CVE-2026-80071High· 7.2
2w ago

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level acces…

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level acces…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-77773Medium· 5.3
2w ago

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entrie…

The Contact Form to Chat Apps | Click to Chat to Order WordPress plugin before 2.15.8 does not perform any capability, nonce or session check on one of its public AJAX actions, allowing unauthenticated users to read the submitted entrie…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-90783High· 7.8
2w ago

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic

MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cau…

▾ TwilightMoritz Bunkus · MKVToolNixEPSS 0.20%via NVD
CVE-2026-90782Medium· 5.3PoC
2w ago

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificati…

S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificati…

▾ TwilightSysterel · S2OPCEPSS 0.57%via NVD
CVE-2026-90781Medium· 4.4PoC
2w ago

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…

▾ TwilightALSA Project · alsa-libEPSS 0.17%via NVD
CVE-2026-90780High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90779High· 7.5
2w ago

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to …

▾ TwilightRed Hat · sippEPSS 0.80%via NVD
CVEs tagged “cve.org” — page 340 · VulnSea