VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18494 CVEsRSS

CVE-2026-87776High· 7.5
3w ago

compression is a Node.js and Express compression middleware

compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destro…

▾ Twilightcompression · compressionEPSS 0.61%via NVD
CVE-2026-86793Critical· 9.8PoC
3w ago

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling…

▾ AbyssalSGLang · SGLangEPSS 0.77%via NVD
CVE-2026-80469High· 8.3
3w ago

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code

An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is r…

▾ TwilightSICK AG · Sentio Creator Extension 'Device Manager'EPSS 0.39%via NVD
CVE-2026-73785High· 7.5
3w ago

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

▾ TwilightHewlett Packard Enterprise · HPE IceWall productsEPSS 0.57%via NVD
CVE-2026-73784High· 8.8
3w ago

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

▾ TwilightHewlett Packard Enterprise · HPE IceWall productsEPSS 0.30%via NVD
CVE-2026-19486High· 8.7
3w ago

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default s…

A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default s…

▾ TwilightGoogle Cloud · Gemini Enterprise Agent Platform App BuilderEPSS 0.27%via NVD
CVE-2026-89160Low· 3.7PoC
3w ago

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

▾ Twilightpcre · pcre2EPSS 0.27%via NVD
CVE-2026-89157Medium· 5.7PoC
3w ago

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

▾ Twilightpcre · pcre2EPSS 0.28%via NVD
CVE-2026-89156Low· 2.9
3w ago

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

▾ Sunlitpcre · pcre2EPSS 0.29%via NVD
CVE-2026-89145Medium· 4.2
3w ago

Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies()

Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin…

▾ Sunlitflextype · flextypeEPSS 0.18%via NVD
CVE-2026-81754High· 7.2
3w ago

The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 2.10.2 due to insufficient inp…

The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 2.10.2 due to insufficient inp…

▾ Twilightfernandot · Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner…EPSS 0.42%via NVD
CVE-2026-78132High· 7.5
3w ago

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

▾ Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-7438Medium· 6.4
3w ago

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient…

The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient…

▾ Sunlitboldthemes · Bold Timeline LiteEPSS 0.36%via NVD
CVE-2026-19985Medium· 6.1
3w ago

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input…

▾ Sunlitcomesio · Relevanssi – A Better SearchEPSS 0.26%via NVD
CVE-2026-18964Medium· 6.1
3w ago

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and in…

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and in…

▾ Sunlitpremio · Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – ChatyEPSS 0.22%via NVD
CVE-2026-18562Medium· 6.1
3w ago

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insuffic…

▾ Sunlitrealmag777 · HUSKY – Products Filter for WooCommerce ProfessionalEPSS 0.23%via NVD
CVE-2026-15462High· 7.5
3w ago

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data(…

▾ Twilightgingerplugins · Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message ButtonsEPSS 0.30%via NVD
CVE-2026-81906Medium· 6.3
3w ago

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete a…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.62%via NVD
CVE-2026-78126Medium· 5.9
3w ago

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

▾ Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-78123Medium· 5.9
3w ago

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

▾ Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-12215Medium· 5.3
3w ago

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `pro…

▾ Sunlitxootix · OTP Login & Register WoocommerceEPSS 0.32%via NVD
CVE-2026-11446Medium· 5.3
3w ago

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() pe…

▾ Sunlitarraytics · Booktics – Appointment Booking Calendar for Service BusinessesEPSS 0.24%via NVD
CVE-2025-15679High· 7.3
3w ago

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

▾ TwilightBull · BullSequana XH3406EPSS 0.11%via NVD
CVE-2025-15695Low· 3.5
3w ago

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScri…

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScri…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-50013High· 7.5
3w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy…

▾ TwilightSpectoLabs · hoverflyEPSS 0.47%via NVD
CVE-2026-50018Medium· 6.5PoC
3w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP con…

▾ TwilightSpectoLabs · hoverflyEPSS 0.54%via NVD
CVE-2026-49992Medium· 6.3
3w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exp…

▾ Sunlitkimai · kimaiEPSS 0.22%via NVD
CVE-2026-54174High· 8.3
3w ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…

▾ Twilightchainguard-dev · melangeEPSS 0.15%via NVD
CVE-2026-54072Critical· 9.3PoC
3w ago

Authorizer is an open-source, self-hostable authentication and authorization server

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` …

▾ Abyssalauthorizerdev · authorizerEPSS 0.46%via NVD
CVE-2026-49865Medium· 5.3PoC
3w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…

▾ Twilightkimai · kimaiEPSS 0.35%via NVD
CVEs tagged “cve.org” — page 369 · VulnSea