VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18494 CVEsRSS

CVE-2026-87987Critical· 10.0
3w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabl…

▾ Midnightmistralai · mistral-vibeEPSS 0.56%via NVD
CVE-2026-87986Critical· 10.0
3w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded comman…

▾ Midnightmistralai · mistral-vibeEPSS 0.56%via NVD
CVE-2026-87984Critical· 9.3
3w ago

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permi…

▾ Midnightmistralai · mistral-vibeEPSS 0.50%via NVD
CVE-2026-8303High· 7.8
3w ago

Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus-softwareEPSS 0.14%via NVD
CVE-2026-8301High· 7.8
3w ago

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardu…

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardu…

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus Boot RepairEPSS 0.84%via NVD
CVE-2026-7863High· 8.4
3w ago

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus S…

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus S…

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus SoftwareEPSS 0.95%via NVD
CVE-2026-89258Medium· 6.3
3w ago

Hugo is a static site generator

Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who…

▾ Sunlitgohugoio · hugoEPSS 0.47%via NVD
CVE-2026-89255High· 8.7PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated att…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89253High· 8.7PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() val…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89248Medium· 5.3PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebR…

▾ TwilightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-89247Medium· 6.1PoC
3w ago

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script e…

▾ TwilightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-89212High· 8.6
3w ago

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1…

▾ TwilightPerforce · AkanaEPSS 0.44%via NVD
CVE-2026-87020High· 8.1
3w ago

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

▾ TwilightOrthanc · DICOM ServerEPSS 0.56%via NVD
CVE-2026-82583High· 8.3
3w ago

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary fil…

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary fil…

▾ TwilightNextGen Healthcare · Mirth ConnectEPSS 0.45%via NVD
CVE-2026-82578High· 7.5
3w ago

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

▾ TwilightNextGen Healthcare · Mirth ConnectEPSS 0.41%via NVD
CVE-2026-78224High· 8.2
3w ago

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

▾ TwilightNextGen Healthcare · Mirth ConnectEPSS 0.44%via NVD
CVE-2026-71644Critical· 9.8
3w ago

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops p…

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops p…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-71641High· 7.5
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergen…

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergen…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-15710Medium· 6.8
3w ago

An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141

An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the…

▾ SunlitNetskope · Endpoint DLPEPSS 0.10%via NVD
CVE-2026-89242High· 7.2PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated …

▾ MidnightWWBN · AVideoEPSS 0.28%via NVD
CVE-2026-89179Medium· 4.3
3w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, there…

▾ SunlitHowyar · WeenyGeniusEPSS 0.16%via NVD
CVE-2026-89178High· 8.8
3w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing stude…

▾ TwilightHowyar · WeenyGeniusEPSS 0.36%via NVD
CVE-2026-89177High· 8.8
3w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmit…

▾ TwilightHowyar · WeenyGeniusEPSS 0.36%via NVD
CVE-2026-89176High· 8.8
3w ago

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a stud…

▾ TwilightHowyar · WeenyGeniusEPSS 0.40%via NVD
CVE-2026-89175Medium· 5.3
3w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system confi…

▾ SunlitKingdom Communication Associated · EH3040EPSS 0.54%via NVD
CVE-2026-89174High· 7.5
3w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

▾ TwilightKingdom Communication Associated · EH3040EPSS 0.51%via NVD
CVE-2026-89173Medium· 5.3
3w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.

▾ SunlitKingdom Communication Associated · EH3040EPSS 0.44%via NVD
CVE-2026-89162Low· 2.9
3w ago

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

▾ Sunlitpcre · pcre2EPSS 0.16%via NVD
CVE-2026-89148Medium· 5.4PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequ…

▾ TwilightWWBN · AVideoEPSS 0.16%via NVD
CVE-2026-87908High· 7.5
3w ago

multiparty is a Node.js library for parsing multipart/form-data request bodies

multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipar…

▾ Twilightmultiparty · multipartyEPSS 0.51%via NVD
CVEs tagged “cve.org” — page 368 · VulnSea