VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18494 CVEsRSS

CVE-2026-89146High· 7.5PoC
3w ago

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL…

▾ Midnightlibp2p · libp2p-rendezvousEPSS 0.63%via NVD
CVE-2026-89566Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. Th…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-86812Medium· 6.5
3w ago

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose …

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose …

▾ SunlitEPSS 0.27%via NVD
CVE-2026-77490Medium· 6.1
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.41%via NVD
CVE-2026-89506Medium· 4.7
3w ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-49462Medium· 5.3
3w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped defau…

▾ Sunlitnl-portal · nl.nl-portal:appEPSS 0.40%via NVD
CVE-2026-89715Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing …

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing …

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-27378Medium· 5.3
3w ago

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

▾ Sunlitmagepeopleteam · advanced-partial-payment-or-deposit-for-woocommerceEPSS 0.29%via NVD
CVE-2026-89151Low· 3.5
3w ago

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

▾ SunlitForgejo · ForgejoEPSS 0.23%via NVD
CVE-2026-78130High· 7.5
3w ago

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

▾ Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-87983Critical· 9.2
3w ago

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during…

▾ Midnightmistralai · mistral-vibeEPSS 0.62%via NVD
CVE-2026-89447Medium· 4.4
3w ago

In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invo…

In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invo…

▾ SunlitLinux · LinuxEPSS 0.22%via NVD
CVE-2026-62138Medium· 6.5
3w ago

Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.

Contributor Cross Site Scripting (XSS) in Visual Composer Website Builder <= 45.16.1 versions.

▾ SunlitVisual Composer · visualcomposerEPSS 0.22%via NVD
CVE-2026-14559Critical· 9.8
3w ago

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only …

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only …

▾ MidnightEPSS 0.28%via NVD
CVE-2026-14563Critical· 9.8
3w ago

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in a…

The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in a…

▾ MidnightEPSS 0.28%via NVD
CVE-2026-18061Medium· 5.9
3w ago

Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files f…

Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files f…

▾ Sunlitamazon · advanced_jdbc_wrapperEPSS 0.27%via NVD
CVE-2026-38058High· 8.1
3w ago

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts

The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with va…

▾ TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.46%via NVD
CVE-2026-89518Medium· 5.5
3w ago

kernel: sched_ext: Fix this_rq() assumptions in dispatch kfuncs (CVE-2026-89518)

A flaw was found in the Linux kernel's `sched_ext` component. Under core scheduling, incorrect assumptions in dispatch kfuncs regarding `this_rq()` can lead to a deadlock. This occurs when an `rq` lock is acquired on a CPU different from t…

▾ SunlitRed Hat · LinuxEPSS 0.20%via CSAF
CVE-2026-89517Medium· 5.5
3w ago

kernel: sched_ext: Fix rq->core_pick corruption under core scheduling (CVE-2026-89517)

A flaw was found in the Linux kernel's `sched_ext` component, which handles core scheduling. When multiple selections on the same core interleave due to a dropped lock, they can corrupt the scheduling state. This corruption can lead to a N…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89516Medium· 5.5
3w ago

kernel: sched_ext: Don't BUG_ON a destroyed DSQ in process_deferred_reenq_users (CVE-2026-89516)

A flaw was found in the Linux kernel's `sched_ext` component. When a Deferred Scheduling Queue (DSQ) is destroyed, a pending deferred re-enqueue (DRU) operation might still attempt to access the destroyed DSQ. This can lead to a `BUG_ON` c…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.20%via CSAF
CVE-2026-89514Medium· 5.5
3w ago

kernel: scsi: fnic: Use GFP_ATOMIC for VLAN alloc under spinlock (CVE-2026-89514)

A flaw was found in the Linux kernel's Fibre Channel over Ethernet Network Interface Card (fnic) driver. The `fnic_fcoe_process_vlan_resp()` function attempts to allocate memory in a way that can cause the system to sleep while holding a s…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89509Medium· 5.5
3w ago

kernel: RDMA/ionic: Embed counter driver data in rdma_counter allocation (CVE-2026-89509)

A flaw was found in the Linux kernel's RDMA/ionic driver. This vulnerability arises from the driver's incorrect handling of `rdma_counter` allocations, specifically by not embedding counter driver data as required. This oversight can lead …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89505Medium· 5.5
3w ago

kernel: RDMA/uverbs: Guard legacy bundles without method_elm (CVE-2026-89505)

A flaw was found in the Linux kernel's RDMA/uverbs component. Malformed input from a provider in the legacy write path can cause the `uverbs_get_handler_fn()` function to dereference an uninitialized pointer. This can lead to a system cras…

▾ SunlitRed Hat · Red Hat Enterprise Linux 6EPSS 0.20%via CSAF
CVE-2026-89502Medium· 5.5
3w ago

kernel: ring-buffer: Free cpu_buffer::free_page with subbuf_order (CVE-2026-89502)

A flaw was found in the Linux kernel's ring-buffer component. When sub-buffers are configured with a specific memory allocation order greater than zero, the system attempts to free a memory page using an incorrect size. This memory managem…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via CSAF
CVE-2026-89661Medium· 5.5
3w ago

kernel: NFSD: Prevent post-shutdown use-after-free in unlock_filesystem (CVE-2026-89661)

A flaw was found in the Linux kernel's Network File System Daemon (NFSD). A local administrator with CAP_SYS_ADMIN capabilities can trigger a use-after-free vulnerability by writing to /proc/fs/nfsd/unlock_filesystem after the NFSD server …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.20%via CSAF
CVE-2026-89592Medium· 5.5
3w ago

kernel: accel/rocket: fix NULL dereference and integer overflow in rocket_job_push() (CVE-2026-89592)

A flaw was found in the `accel/rocket` component of the Linux kernel. This vulnerability arises from two issues: a missing null check after a memory allocation failure and an integer overflow when calculating memory requirements based on u…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89591Medium· 5.5
3w ago

kernel: accel/rocket: initialize job domain before cleanup paths (CVE-2026-89591)

A flaw was found in the Linux kernel's `accel/rocket` module. During error handling in the `rocket_ioctl_submit_job()` function, a cleanup routine may attempt to free a `job->domain` pointer that has not yet been initialized, leading to a …

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89590Medium· 5.5
3w ago

kernel: accel/rocket: Fix error path handling in rocket_job_run() (CVE-2026-89590)

A flaw was found in the `accel/rocket` driver within the Linux kernel. Incorrect error handling in the `rocket_job_run()` function can lead to resource leaks. This occurs when the system fails to properly release references to Direct Memor…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-89589Medium· 4.4
3w ago

In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks The CXL CPER work registration and unregistration helpers acquire cxl_cper_work_lock and cxl_cper_prot_err_w…

In the Linux kernel, the following vulnerability has been resolved: acpi/apei/ghes: Use raw_spinlock_t for CXL CPER work locks The CXL CPER work registration and unregistration helpers acquire cxl_cper_work_lock and cxl_cper_prot_err_w…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89578Medium· 5.5
3w ago

kernel: dm-io: clone the source bio instead of copying its biovec (CVE-2026-89578)

A flaw was found in the Linux kernel's device mapper I/O (dm-io) component. When handling DM_IO_BIO requests, incorrect sector-based accounting for misaligned direct I/O buffers could lead to an infinite loop. This issue can cause I/O oper…

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.21%via CSAF
CVEs tagged “cve.org” — page 359 · VulnSea