VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18495 CVEsRSS

CVE-2026-90780High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes

SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90779High· 7.5
2w ago

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters

SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to …

▾ TwilightRed Hat · sippEPSS 0.80%via NVD
CVE-2026-90778High· 7.5
2w ago

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more

SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversize…

▾ TwilightSIPp · sippEPSS 0.86%via NVD
CVE-2026-90777High· 8.8PoC
2w ago

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files

ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code dur…

▾ Midnightespnet · espnetEPSS 0.73%via NVD
CVE-2026-90776High· 7.5PoC
2w ago

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments

Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separ…

▾ Midnightnodemailer · nodemailerEPSS 0.68%via NVD
CVE-2026-90524High· 7.3PoC
2w ago

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09

A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation resul…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.69%via NVD
CVE-2026-90523High· 7.3PoC
2w ago

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09

A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java o…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.50%via NVD
CVE-2026-90522High· 7.3PoC
2w ago

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d

A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manip…

▾ Midnightjaychouchannel · Tourism-Management-SystemEPSS 0.50%via NVD
CVE-2026-90521Medium· 6.3PoC
2w ago

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132

A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipul…

▾ Twilightjaychouchannel · Tourism-Management-SystemEPSS 0.39%via NVD
CVE-2026-90520Medium· 6.3PoC
2w ago

A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64

A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization I…

▾ Twilightjaychouchannel · Tourism-Management-SystemEPSS 0.37%via NVD
CVE-2026-90519Medium· 6.3PoC
2w ago

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0

A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remo…

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.37%via NVD
CVE-2026-90517Medium· 5.3PoC
2w ago

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0

A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack ma…

▾ TwilightPHPGurukul · Bank Locker Management SystemEPSS 0.57%via NVD
CVE-2026-90582Medium· 5.3PoC
2w ago

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0

A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consum…

▾ Twilightevanchiu · serverless-todoEPSS 0.70%via NVD
CVE-2026-90581Medium· 6.3PoC
2w ago

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2

A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote explo…

▾ Twilightcym1102 · nginxWebUIEPSS 0.41%via NVD
CVE-2026-90579High· 7.3PoC
2w ago

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2

A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing a…

▾ Midnightcheshire-cat-ai · Cheshire Cat AIEPSS 0.65%via NVD
CVE-2026-90578Medium· 5.3PoC
2w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local e…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90577Medium· 5.3PoC
2w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffe…

▾ TwilightEPSS 0.18%via NVD
CVE-2026-90576Low· 3.3PoC
2w ago

A security vulnerability has been detected in GPAC up to f1219cde

A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90575Low· 3.7PoC
2w ago

A weakness has been identified in PHPGurukul Small CRM 4.0

A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. I…

▾ TwilightPHPGurukul · Small CRMEPSS 0.48%via NVD
CVE-2026-90574Medium· 6.3PoC
2w ago

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0

A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The …

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90573Low· 3.3PoC
2w ago

A vulnerability was identified in GPAC up to f1219cde

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is …

▾ TwilightEPSS 0.17%via NVD
CVE-2026-90572Medium· 4.7PoC
2w ago

A vulnerability was determined in davenardella snap7 up to 1.4.3

A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to mem…

▾ Twilightdavenardella · snap7EPSS 0.42%via NVD
CVE-2026-90571Medium· 4.3
2w ago

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c

A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performi…

▾ SunlitExrick · xmallEPSS 0.47%via NVD
CVE-2026-90570Low· 2.4
2w ago

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0

A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Su…

▾ Sunlitlinlinjava · litemallEPSS 0.37%via NVD
CVE-2026-90569Low· 2.4
2w ago

A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0

A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. Th…

▾ Sunlitlinlinjava · litemallEPSS 0.37%via NVD
CVE-2026-90568Low· 3.5
2w ago

A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2

A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of …

▾ Sunlitmoxi624 · Mogu Blog v2EPSS 0.33%via NVD
CVE-2026-90567Low· 3.5
2w ago

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1

A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of th…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.35%via NVD
CVE-2026-90566High· 7.3PoC
2w ago

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registratio…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.47%via NVD
CVE-2026-90565Medium· 5.3PoC
2w ago

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid resul…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.53%via NVD
CVE-2026-90564Low· 3.5
2w ago

A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1

A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.35%via NVD
CVEs tagged “cve.org” — page 341 · VulnSea