VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18496 CVEsRSS

CVE-2026-81052Medium· 6.8
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code ex…

▾ Sunlitdell · thinosEPSS 0.18%via NVD
CVE-2026-0303Low· 2.4PoC
3w ago

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

A code execution vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can allow arbitrary code execution when Checkov scans a directory that contains an attacker-controlled configuration file.

▾ TwilightPalo Alto Networks · Checkov by Prisma CloudEPSS 0.19%via NVD
CVE-2026-78303Medium· 6.9
3w ago

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing pote…

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.43%via NVD
CVE-2026-63427High· 7.8
3w ago

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

An authentication bypass vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

▾ TwilightLenovo · Software FixEPSS 0.19%via NVD
CVE-2026-75624High· 8.8
3w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.27 could allow a remote authenticated attacker to bypass security restrictions due to incorrect authorization.

▾ Twilightibm · app_connect_enterpriseEPSS 0.50%via NVD
CVE-2026-88268Medium· 6.5
3w ago

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a valid user to crash the SSVR service.

▾ SunlitGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.41%via NVD
CVE-2026-88052High· 7.8
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. u…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.18%via NVD
CVE-2026-81048Critical· 9.6
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially expl…

▾ Midnightdell · thinosEPSS 2.4%via NVD
CVE-2026-88887High· 8.6
3w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the foll…

▾ Twilightrenovatebot · renovateEPSS 0.41%via NVD
CVE-2026-88872High· 7.1PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sendin…

▾ MidnightWWBN · AVideoEPSS 0.19%via NVD
CVE-2026-88865High· 8.1
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exc…

▾ TwilightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-88054Medium· 5.5PoC
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED laye…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2026-81468Critical· 9.1
3w ago

Dell ThinOS 10, versions prior to 2605_10

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploi…

▾ Midnightdell · thinosEPSS 2.0%via NVD
CVE-2026-88033High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · java_driverEPSS 0.46%via NVD
CVE-2026-12683Medium· 5.4
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9…

▾ SunlitAnkaref Innovation and Technology Inc. · LIBRID/LIBREFEPSS 0.16%via NVD
CVE-2026-87870Medium· 6.4
3w ago

Ninja Forms - Scheduled Exports <= 3.0.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting via REST API Parameters

The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization …

▾ SunlitSaturday Drive · Ninja Forms - Scheduled ExportsEPSS 0.26%via CVEORG
CVE-2026-85645Medium· 6.1
3w ago

Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting

The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the bulk_action parameter in all versions up to, and including, 1.15.46 due to insufficie…

▾ Sunlit10web · Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form BuilderEPSS 0.38%via CVEORG
CVE-2026-84816High· 7.1
3w ago

WordPress WPCS plugin <= 1.3.2 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.

▾ TwilightRealMag777 · currency-switcherEPSS 0.25%via CVEORG
CVE-2026-15823Medium· 4.3
3w ago

Builderall for WordPress <= 3.0.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'ba_cheetah_data[post_id]' Parameter

The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_cheetah_disable AJA…

▾ Sunlitbuilderall · Builderall for WordPressEPSS 0.20%via CVEORG
CVE-2026-89042Critical· 9.1
3w ago

passport-saml-encrypted through 0.1.13 Authentication Bypass via Missing Signature Verification

passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses …

▾ Midnightkrakenjs · passport-saml-encryptedEPSS 0.39%via CVEORG
CVE-2026-89011High· 7.1
3w ago

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path …

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path …

▾ Twilightisomorphic-git · isomorphic-gitEPSS 0.44%via NVD
CVE-2026-88959High· 8.8
3w ago

Anchor CMS through 0.12.7 Privilege Escalation via Missing Authorization on Admin User-Management Endpoints

Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or use…

▾ Twilightanchorcms · anchorcms/anchor-cmsEPSS 0.52%via CVEORG
CVE-2026-88899Critical· 9.8PoC
3w ago

knowns before 0.31.0 External Control of Agent Working Directory via x-opencode-directory Header

knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project roo…

▾ Abyssalknowns-dev · knownsEPSS 0.81%via CVEORG
CVE-2026-88062Critical· 9.5PoC
3w ago

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand v…

▾ Abyssaldiegosouzapw · OmniRouteEPSS 1.4%via NVD
CVE-2026-88057Medium· 6.1
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compi…

▾ Sunlitangular · angularEPSS 0.26%via NVD
CVE-2026-88047High· 7.8
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whit…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.11%via NVD
CVE-2026-88017High· 7.3
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the se…

▾ Twilightrclone · rcloneEPSS 0.23%via NVD
CVE-2026-88012Medium· 5.3
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connectio…

▾ Sunlittraefik · traefikEPSS 0.52%via NVD
CVE-2026-77807High· 7.5
3w ago

AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress <= 11.0.4 - Unauthenticated Arbitrary File Read via 'user[name]' Parameter

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This ma…

▾ Twilightacyba · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPressEPSS 0.93%via CVEORG
CVE-2026-45768High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of respons…

▾ Twilightoisf · suricataEPSS 0.70%via NVD
CVEs tagged “cve.org” — page 371 · VulnSea