VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18496 CVEsRSS

CVE-2026-85979High· 8.6
3w ago

Affected versions of Puppet Enterprise contain a command injection vulnerability

Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, …

▾ TwilightPerforce Software · Puppet EnterpriseEPSS 1.3%via NVD
CVE-2026-78133High· 7.5
3w ago

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

▾ Twilightstrongswan · strongswanEPSS 0.43%via NVD
CVE-2026-78127Low· 3.7
3w ago

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

▾ Sunlitstrongswan · strongswanEPSS 0.35%via NVD
CVE-2026-89262High· 7.5PoC
3w ago

MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary commen…

▾ Midnightmoxi624 · MoguBlogEPSS 0.54%via CVEORG
CVE-2026-89251Medium· 6.5PoC
3w ago

AVideo Missing Authorization via AD_Server log.php Wallet Credit

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign vid…

▾ TwilightWWBN · AVideoEPSS 0.18%via CVEORG
CVE-2026-89246Medium· 5.4PoC
3w ago

WWBN AVideo CSV Formula Injection via myComments.download.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated…

▾ TwilightWWBN · AVideoEPSS 0.24%via CVEORG
CVE-2026-89099High· 7.5
3w ago

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-…

▾ Twilightmongodb · mongodbEPSS 0.32%via NVD
CVE-2026-89013High· 7.5PoC
3w ago

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can…

▾ MidnightDolibarr · DolibarrEPSS 1.6%via NVD
CVE-2026-8304Medium· 5.5
3w ago

Information Disclosure in TUBITAK BILGEM's Pardus About

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus About: from 1.2.1 before 1.2.5.

▾ SunlitTUBITAK BILGEM Software Technologies Research Institute · Pardus AboutEPSS 0.14%via CVEORG
CVE-2026-81909Medium· 5.9
3w ago

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the orphaned-block alias route, allowing an authenticated editor to disclose and force-delete arbitrary blocks

Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the t…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.44%via CVEORG
CVE-2026-79396Critical· 9.8PoC
3w ago

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowi…

Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowi…

▾ AbyssalEPSS 0.58%via NVD
CVE-2026-79394High· 7.5
3w ago

An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthentica…

An insecure default configuration in the embedded Happytime RTSP server within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier ships with authentication disabled, allowing remote unauthentica…

▾ TwilightEPSS 0.60%via NVD
CVE-2026-79362High· 8.8
3w ago

Certain Woltlab products are affected by RCE via Cache Poisoning

Certain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticated low-privileged user can inject PHP into executable cache files generated by WoltLab Suite Core…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-71646High· 7.5
3w ago

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manage…

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the FastExplorationFSM::optTimerCallback() in swarm_exploration/exploration_manage…

▾ TwilightEPSS 0.49%via NVD
CVE-2026-18495Medium· 6.1
3w ago

A flaw was found in libtiff

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causin…

▾ SunlitRed Hat · libtiff-mainEPSS 0.12%via NVD
CVE-2026-15439Medium· 6.5
3w ago

GamiPress <= 7.9.7 - Authenticated (Subscriber+) SQL Injection

The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts) in versions up to, and including, 7.9.7. The …

▾ Sunlitrubengc · GamiPress – Gamification plugin to reward points, badges & ranks in WordPress, now with AIEPSS 0.23%via CVEORG
CVE-2025-69904Medium· 4.9
3w ago

Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input

Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive syste…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-89261Medium· 6.5PoC
3w ago

MoguBlog through 6.2 Missing Authentication for Elasticsearch Index Management Endpoints

MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints t…

▾ Twilightmoxi624 · MoguBlogEPSS 0.83%via CVEORG
CVE-2026-89241Medium· 6.1PoC
3w ago

WWBN AVideo Reflected XSS via confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can c…

▾ TwilightWWBN · AVideoEPSS 0.26%via CVEORG
CVE-2026-89012Medium· 6.5PoC
3w ago

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denyl…

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denyl…

▾ TwilightDolibarr · DolibarrEPSS 0.46%via NVD
CVE-2026-85083Medium· 6.8
3w ago

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication

The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modificatio…

▾ SunlitCareCam · ANJIA AJL33PC0801 FirmwareEPSS 0.29%via NVD
CVE-2026-81861Medium· 5.9PoC
3w ago

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

▾ TwilightSchneider Electric · SCADAPack 47xEPSS 0.54%via NVD
CVE-2026-79393High· 7.5
3w ago

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to ca…

A heap-based buffer overflow vulnerability in the WS-Addressing Action transformation function in the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote unauthenticated attackers to ca…

▾ TwilightEPSS 0.74%via NVD
CVE-2026-3869Critical· 9.2
3w ago

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running…

CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running…

▾ MidnightSchneider Electric · Modicon M580EPSS 0.54%via NVD
CVE-2026-9160Medium· 4.3
3w ago

CSTI in Arma Digital's Website Template

Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted…

▾ SunlitArma Digital Media Inc. · Website TemplateEPSS 0.28%via CVEORG
CVE-2026-89329Medium· 6.2
3w ago

A flaw was found in `multipathd`

A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` list…

▾ SunlitRed Hat · device-mapper-multipathEPSS 0.16%via NVD
CVE-2026-82535Medium· 6.1
3w ago

Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypas…

Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypas…

▾ Sunlitchamilo · chamilo-lmsEPSS 0.47%via NVD
CVE-2026-81913Medium· 6.1
3w ago

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter

Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft a single link on the site's own domain that sends a user to an arbitrary external site immediately after authenticat…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.29%via NVD
CVE-2026-81912Medium· 5.7
3w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard/users/groups/bulkupdate/confirm() endpoint moved the selected group tree nodes without validating an action token, s…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.19%via NVD
CVE-2026-81911Medium· 5.4
3w ago

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog

Concrete CMS versions 9.0.0 to 9.5.2 is vulnerable to Stored XSS in Board Custom Slot dialog. The custom_slot save_template endpoint authorizes the request only against the target board instance (canEditBoardContents()) and then persists…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVEs tagged “cve.org” — page 364 · VulnSea