VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18496 CVEsRSS

CVE-2026-45762High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's IP defragmentation tracker lookup did not verify that an existing tracke…

▾ Twilightoisf · suricataEPSS 0.61%via NVD
CVE-2026-2310High· 7.8
3w ago

IBM webMethods Integration Server is vulnerable to an XML external entity injection (XXE) attack when processing XML data

IBM webMethods Integration Server 11.1 IBM webMethods Integration is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information…

▾ TwilightIBM · webMethods Integration ServerEPSS 0.19%via CVEORG
CVE-2026-88924High· 7.0PoC
3w ago

A flaw was found in the admin backend of gvfs

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory…

▾ MidnightGNOME · gvfsEPSS 0.17%via NVD
CVE-2026-80378High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.38%via NVD
CVE-2026-80380High· 7.1
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.20%via NVD
CVE-2026-80436High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.38%via NVD
CVE-2026-88273High· 7.2
3w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via NVD
CVE-2026-88032Medium· 5.9
3w ago

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able t…

▾ Sunlitmongodb · java_driverEPSS 0.26%via NVD
CVE-2026-84939Critical· 9.1
3w ago

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

▾ Midnightapache · freemarkerEPSS 0.85%via NVD
CVE-2026-88061Medium· 5.8
3w ago

career-ops is an open-source AI-assisted job search and application management tool

career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or …

▾ Sunlitsantifer · career-opsEPSS 0.38%via NVD
CVE-2026-88271High· 8.8
3w ago

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.42%via NVD
CVE-2026-79725Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

▾ Sunlitlangflow · langflowEPSS 0.41%via NVD
CVE-2026-88871Medium· 4.3PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script …

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-87931Critical· 9.6
3w ago

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation lead…

▾ MidnightBehavioral Technology Group · Pavlok Behavioral Conditioning WearableEPSS 0.60%via NVD
CVE-2026-87913Medium· 5.9
3w ago

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state…

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state…

▾ SunlitAWS · AWS Security Agent MCP serverEPSS 0.44%via NVD
CVE-2026-88274High· 7.2
3w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via NVD
CVE-2026-81210High· 7.7
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained t…

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.34%via NVD
CVE-2026-88283Medium· 4.9
3w ago

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via NVD
CVE-2026-85544Medium· 6.1
3w ago

Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…

Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…

▾ SunlitHikvision · DS-KV9503EPSS 0.41%via NVD
CVE-2026-67593Critical· 9.1
3w ago

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects …

▾ Midnightapache · artemisEPSS 0.86%via NVD
CVE-2026-49362High· 7.5
3w ago

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…

▾ Twilightapache · artemisEPSS 0.82%via NVD
CVE-2026-81796High· 7.3
3w ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

▾ TwilightWEN Solutions · wp-travelEPSS 0.40%via NVD
CVE-2026-88880High· 8.6
3w ago

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify…

▾ Twilightrenovatebot · renovateEPSS 0.50%via NVD
CVE-2026-88044Critical· 9.1PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…

▾ Abyssalrclone · rcloneEPSS 0.49%via NVD
CVE-2026-88015Medium· 5.3PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.De…

▾ Twilightrclone · rcloneEPSS 0.36%via NVD
CVE-2026-88013Low· 3.7PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…

▾ Twilightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-88045High· 7.5PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentL…

▾ Midnightrclone · rcloneEPSS 0.63%via NVD
CVE-2026-89087High· 7.3
3w ago

The cstruct package before 6.3.0 for OCaml mishandles indexes.

The cstruct package before 6.3.0 for OCaml mishandles indexes.

▾ TwilightOCaml · cstructEPSS 0.32%via NVD
CVE-2026-79723Medium· 5.0
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

▾ Sunlitlangflow · langflowEPSS 0.35%via NVD
CVE-2026-81551High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.64%via NVD
CVEs tagged “cve.org” — page 372 · VulnSea