VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18495 CVEsRSS

CVE-2026-90563Low· 3.5
2w ago

A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0

A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out rem…

▾ Sunlitmaliangnansheng · bbs-springbootEPSS 0.36%via NVD
CVE-2026-90529Low· 3.5
2w ago

A vulnerability has been found in DataEase up to 2.10.25/2.10.26

A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-90528Low· 3.5
2w ago

A flaw has been found in TDuckApp tduck-platform up to 5.3

A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argu…

▾ SunlitTDuckApp · tduck-platformEPSS 0.35%via NVD
CVE-2026-90527Medium· 4.3
2w ago

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1

A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content…

▾ Sunlitquequnlong · shiyi-blogEPSS 0.47%via NVD
CVE-2026-90526High· 7.3PoC
2w ago

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0

A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Re…

▾ MidnightSourceCodester · School Registration and Fee SystemEPSS 0.43%via NVD
CVE-2026-90525Medium· 6.3PoC
2w ago

A weakness has been identified in itsourcecode Sales and Inventory System 1.0

A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The atta…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-36453High· 7.4
2w ago

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1

Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

▾ TwilightRhymix · RhymixEPSS 0.27%via NVD
CVE-2026-29811High· 7.7
2w ago

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

▾ TwilightCyberPanel · CyberPanelEPSS 0.34%via NVD
CVE-2026-29810Medium· 4.3
2w ago

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

▾ SunlitCyberPanel · CyberPanelEPSS 0.31%via NVD
CVE-2025-70820Low· 3.5
2w ago

Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

▾ SunlitZettlab · D6 UltraEPSS 0.18%via NVD
CVE-2025-70819Medium· 6.3
2w ago

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

▾ SunlitZettlab · D6 UltraEPSS 0.11%via NVD
CVE-2025-64059Low· 1.8PoC
2w ago

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor

Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

▾ Twilightgetgrav · GravEPSS 0.30%via NVD
CVE-2025-45480Low· 3.0
2w ago

Floodlight 71fe8a7 allows disruption of host communication via link spoofing

Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

▾ Sunlitprojectfloodlight · FloodlightEPSS 0.15%via NVD
CVE-2026-90603High· 7.3
2w ago

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-prox…

▾ TwilightAnil-matcha · Open-Generative-AIEPSS 0.50%via NVD
CVE-2026-90602Low· 3.5
2w ago

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cro…

▾ SunlitAnil-matcha · Open-Generative-AIEPSS 0.36%via NVD
CVE-2026-90601High· 7.3PoC
2w ago

A vulnerability was found in getzep graphiti up to 0.30.2

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launche…

▾ Midnightgetzep · graphitiEPSS 0.69%via NVD
CVE-2026-90600Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0

A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated rem…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90599Medium· 4.3PoC
2w ago

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-site request forg…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.24%via NVD
CVE-2026-90598Medium· 6.3PoC
2w ago

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2

A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Performing a manipu…

▾ Twilightjaygajera17 · E-commerce-project-springBootEPSS 0.39%via NVD
CVE-2026-90597Medium· 6.3PoC
2w ago

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0

A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql injection. The att…

▾ Twilightitsourcecode · Sales and Inventory SystemEPSS 0.33%via NVD
CVE-2026-90596Medium· 6.5PoC
2w ago

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit

A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is possible to be c…

▾ TwilightEPSS 0.58%via NVD
CVE-2026-90595Medium· 6.3PoC
2w ago

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0

A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The manipulation res…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CVE-2026-90594Medium· 6.3PoC
2w ago

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0

A vulnerability was identified in wxiaoqi Spring-Cloud-Platform 3.0.1/3.1.0. This vulnerability affects the function PermissionService.checkUserPermission of the file /rpc/service/PermissionService.java of the component Permission Servic…

▾ Twilightwxiaoqi · Spring-Cloud-PlatformEPSS 0.37%via NVD
CVE-2026-90593High· 7.3
2w ago

A vulnerability was determined in embedded-graphics up to 0.8.2

A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of the file src/image/image_raw.rs. Executing a manipulation of the argument width can lead to integer overflow. The atta…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-90584Medium· 5.3PoC
2w ago

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1

A weakness has been identified in TooTallNate Java-WebSocket up to 1.6.1. The impacted element is the function processFrameContinuousAndNonFin of the file Draft_6455.java of the component Fragmentation Handler. Executing a manipulation c…

▾ TwilightTooTallNate · Java-WebSocketEPSS 0.72%via NVD
CVE-2026-90583Medium· 4.3PoC
2w ago

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf

A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulatio…

▾ Twilightkagisearch · smallwebEPSS 0.49%via NVD
CVE-2026-52297Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-52296Low· 2.9⚖ disputed
2w ago

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.

▾ SunlitFFmpeg · FFmpegEPSS 0.15%via NVD
CVE-2026-38332Low· 2.9
2w ago

TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

▾ Sunlitcdcseacave · TinyEXIFEPSS 0.15%via NVD
CVE-2026-37008High· 8.1PoC
2w ago

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275

CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's co…

▾ MidnightCrewAI · CrewAIEPSS 0.16%via NVD
CVEs tagged “cve.org” — page 342 · VulnSea