Tagged “cve.org”
CVEs tagged cve.org, newest first.
18495 CVEsRSS
CVE-2026-90563Low· 3.5A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0
A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out rem…
CVE-2026-90529Low· 3.5A vulnerability has been found in DataEase up to 2.10.25/2.10.26
A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic…
CVE-2026-90528Low· 3.5A flaw has been found in TDuckApp tduck-platform up to 5.3
A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argu…
CVE-2026-90527Medium· 4.3A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1
A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content…
CVE-2026-90526High· 7.3PoCA security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0
A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Re…
CVE-2026-90525Medium· 6.3PoCA weakness has been identified in itsourcecode Sales and Inventory System 1.0
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The atta…
CVE-2026-36453High· 7.4Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1
Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.
CVE-2026-29811High· 7.7CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.
CVE-2026-29810Medium· 4.3CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.
CVE-2025-70820Low· 3.5Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.
CVE-2025-70819Medium· 6.3Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.
Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.
CVE-2025-64059Low· 1.8PoCGrav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor
Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.
CVE-2025-45480Low· 3.0Floodlight 71fe8a7 allows disruption of host communication via link spoofing
Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.
CVE-2026-90603High· 7.3A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0
A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-prox…
CVE-2026-90602Low· 3.5A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0
A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cro…
CVE-2026-90601High· 7.3PoCA vulnerability was found in getzep graphiti up to 0.30.2
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launche…
CVE-2026-90600Medium· 6.3PoCA vulnerability has been found in itsourcecode Sales and Inventory System 1.0
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated rem…
CVE-2026-90599Medium· 4.3PoCA flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2
A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forg…
CVE-2026-90598Medium· 6.3PoCA vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2
A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipu…
CVE-2026-90597Medium· 6.3PoCA security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The att…
CVE-2026-90596Medium· 6.5PoCA weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit
A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be c…
CVE-2026-90595Medium· 6.3PoCA security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0
A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation res…
CVE-2026-90594Medium· 6.3PoCA vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0
A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Servic…
CVE-2026-90593High· 7.3A vulnerability was determined in embedded-graphics up to 0.8.2
A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The atta…
CVE-2026-90584Medium· 5.3PoCA weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1
A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation c…
CVE-2026-90583Medium· 4.3PoCA security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf
A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulatio…
CVE-2026-52297Low· 2.9⚖ disputedFFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
CVE-2026-52296Low· 2.9⚖ disputedFFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
CVE-2026-38332Low· 2.9TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.
TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.
CVE-2026-37008High· 8.1PoCCrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275
CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's co…