VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18496 CVEsRSS

CVE-2026-89094Critical· 9.9
3w ago

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

▾ MidnightForgejo · ForgejoEPSS 0.85%via NVD
CVE-2026-0310High· 7.2
3w ago

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service …

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service …

▾ TwilightPalo Alto Networks · Cloud NGFWEPSS 0.37%via NVD
CVE-2026-87993High· 7.7
3w ago

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

▾ TwilightHashiCorp · ToolingEPSS 0.38%via NVD
CVE-2026-88790Medium· 4.8PoC
3w ago

A security vulnerability has been detected in proma-ai Proma up to 0.19.37

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File Preview Service. Such manipulatio…

▾ Twilightproma-ai · PromaEPSS 0.17%via NVD
CVE-2026-88035Medium· 4.7
3w ago

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection setting…

▾ Sunlitmongodb · c_driverEPSS 0.10%via NVD
CVE-2026-19584High· 7.7
3w ago

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…

▾ TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CVE-2026-88264Medium· 5.6
3w ago

A flaw was found in crun

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected …

▾ Sunlitcontainers · crunEPSS 0.12%via NVD
CVE-2026-88056Critical· 9.1PoC
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processe…

▾ Abyssalangular · angularEPSS 0.54%via NVD
CVE-2026-88884Medium· 5.8
3w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updat…

▾ Sunlitrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-79987High· 8.8
3w ago

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

▾ Twilightcraftcms · craftcms/cmsEPSS 0.65%via NVD
CVE-2026-76653Medium· 5.3
3w ago

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and mod…

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and mod…

▾ SunlitTP-Link Systems Inc. · TL-MR6400 v8EPSS 0.47%via NVD
CVE-2026-88877Critical· 9.8PoC
3w ago

Traefik is a HTTP reverse proxy and load balancer

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-…

▾ Abyssaltraefik · traefikEPSS 0.65%via NVD
CVE-2026-88027High· 7.1
3w ago

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

▾ Twilightmongodb · laravel_mongodbEPSS 0.27%via NVD
CVE-2026-88030High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · ruby_driverEPSS 0.48%via NVD
CVE-2026-88051High· 7.8PoC
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a c…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.17%via NVD
CVE-2026-88893High· 7.5
3w ago

OpenPanel through 2.3.0 share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers

OpenPanel through 2.3.0 share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes an…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.43%via NVD
CVE-2026-88891High· 8.3PoC
3w ago

OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data

OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports…

▾ MidnightOpenpanel-dev · openpanelEPSS 0.37%via NVD
CVE-2026-88915High· 7.1
3w ago

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed …

▾ TwilightMISP · MISPEPSS 0.35%via NVD
CVE-2026-88272High· 7.2
3w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.54%via NVD
CVE-2026-88885High· 7.0
3w ago

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters …

▾ Twilightrenovatebot · renovateEPSS 0.89%via NVD
CVE-2026-88016High· 7.1PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and l…

▾ Midnightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-82100Critical· 9.6
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.61%via NVD
CVE-2026-81046Critical· 9.4
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within…

▾ Midnightdell · thinosEPSS 0.55%via NVD
CVE-2026-88028Medium· 6.5
3w ago

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

▾ Sunlitmongodb · laravel_mongodbEPSS 0.42%via NVD
CVE-2026-88031High· 8.1
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

▾ Twilightmongodb · go_driverEPSS 0.48%via NVD
CVE-2026-80424Critical· 9.1
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.51%via NVD
CVE-2026-88049Medium· 5.5PoC⚖ disputed
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStep…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2026-45751Medium· 5.9
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's inspection-buffer helper could leave an inspection pointer referencing f…

▾ Sunlitoisf · suricataEPSS 0.32%via NVD
CVE-2026-16172Medium· 6.0
3w ago

Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client

Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds …

▾ SunlitNetskope · Endpoint DLPEPSS 0.11%via NVD
CVE-2026-88882High· 8.6
3w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from …

▾ Twilightrenovatebot · renovateEPSS 0.41%via NVD
CVEs tagged “cve.org” — page 374 · VulnSea