VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18498 CVEsRSS

CVE-2026-16172Medium· 6.0
3w ago

Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client

Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds …

▾ SunlitNetskope · Endpoint DLPEPSS 0.11%via NVD
CVE-2026-88882High· 8.6
3w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.11.2 (and Mend Renovate CE/EE images and charts before 15.4.0, and mend-renovate-enterprise-edition helm chart before 10.4.0), when listing new package versions from …

▾ Twilightrenovatebot · renovateEPSS 0.41%via NVD
CVE-2026-88009High· 8.2
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path eval…

▾ Twilighttraefik · traefikEPSS 0.44%via NVD
CVE-2026-17038Medium· 6.9
3w ago

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations bey…

▾ SunlitdrEryk · drEryk GabinetEPSS 0.26%via NVD
CVE-2026-0302Low· 1.1
3w ago

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

An OS command injection vulnerability in Palo Alto Networks Checkov by Prisma® Cloud enables a local user to execute arbitrary commands in the processes running Checkov.

▾ SunlitPalo Alto Networks · Checkov by Prisma CloudEPSS 0.82%via NVD
CVE-2026-45767Medium· 4.4
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a malicious rule could potentially overwrite any file on the file system on rule lo…

▾ Sunlitoisf · suricataEPSS 0.40%via NVD
CVE-2026-11813High· 7.8
3w ago

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

▾ TwilightLenovo · FileZ ClientEPSS 0.10%via NVD
CVE-2026-88897Medium· 5.9
3w ago

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes

Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST API routes. Attackers with access to web server, proxy, or monitoring logs can recover valid API token pairs that grant…

▾ Sunlitflextype · flextypeEPSS 0.56%via NVD
CVE-2026-19596Medium· 5.9
3w ago

An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon

An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Horizon. When OpenNMS collects XML from a source whose response is attacker-controlled (for example a compromised monitor…

▾ SunlitThe OpenNMS Group · MeridianEPSS 0.21%via NVD
CVE-2026-16174High· 8.7
3w ago

Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems

Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to …

▾ TwilightNetskope · Endpoint DLPEPSS 0.13%via NVD
CVE-2026-88894Medium· 5.4PoC
3w ago

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target

Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the checkout target. Unlike the single, bulk, API, accessory, license and consumable checkout paths, App\Services\Predefine…

▾ Twilightsnipeitapp · snipe-itEPSS 0.26%via NVD
CVE-2026-80352Critical· 9.8
3w ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentia…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentia…

▾ Midnightapache · camelEPSS 0.84%via NVD
CVE-2026-88058Medium· 6.1PoC⚖ disputed
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server se…

▾ Twilightangular · angularEPSS 0.28%via NVD
CVE-2026-68488Critical· 9.9
3w ago

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

▾ MidnightWebPros · PleskEPSS 0.40%via NVD
CVE-2026-75940Critical· 9.1
3w ago

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

▾ MidnightLenovo · Health ApplicationEPSS 0.40%via NVD
CVE-2026-82097High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.64%via NVD
CVE-2026-85310Medium· 6.5
3w ago

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

▾ SunlitAdrian Tobey · groundhoggEPSS 0.44%via NVD
CVE-2026-87925High· 7.3PoC
3w ago

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipula…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-45761Low· 3.3
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow w…

▾ Sunlitoisf · suricataEPSS 0.18%via NVD
CVE-2026-88048High· 7.1PoC
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During Fu…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.17%via NVD
CVE-2026-88004High· 7.4
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing a…

▾ Twilighttraefik · traefikEPSS 0.45%via NVD
CVE-2026-88763Medium· 5.9
3w ago

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message …

▾ SunlitRed Hat · skupper-routerEPSS 0.41%via NVD
CVE-2026-19136High· 7.8
3w ago

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

▾ TwilightLenovo · Tianxi AI Agent PC ApplicationEPSS 0.87%via NVD
CVE-2026-88029High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal i…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal i…

▾ Twilightmongodb · python_driverEPSS 0.48%via NVD
CVE-2026-45764Critical· 9.1
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in S…

▾ Midnightoisf · suricataEPSS 0.63%via NVD
CVE-2026-88006Medium· 6.5
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role managem…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-57967Critical· 9.8⚖ disputed
3w ago

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 thr…

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 thr…

▾ Midnightapache · artemisEPSS 1.1%via NVD
CVE-2026-0304Medium· 4.8
3w ago

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

▾ SunlitPalo Alto Networks · Cortex XDR Broker VMEPSS 0.22%via NVD
CVE-2026-76652Medium· 4.8
3w ago

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote…

▾ SunlitTP-Link Systems Inc. · TL-MR6400 v8EPSS 0.73%via NVD
CVE-2026-88005Medium· 6.5
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allow…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVEs tagged “cve.org” — page 375 · VulnSea