VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18498 CVEsRSS

CVE-2026-82095High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-18994High· 7.1
3w ago

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

▾ TwilightLenovo · File Manager ApplicationEPSS 0.10%via NVD
CVE-2026-89044Medium· 6.5
3w ago

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

▾ Sunlitnetty · nettyEPSS 0.28%via NVD
CVE-2026-88265Medium· 5.6
3w ago

A flaw was found in crun

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configura…

▾ SunlitRed Hat · crun-mainEPSS 0.12%via NVD
CVE-2026-88921Medium· 5.1
3w ago

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the con…

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the con…

▾ SunlitMISP · MISPEPSS 0.49%via NVD
CVE-2026-88892Medium· 5.0PoC
3w ago

In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts)

In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In packages/importer/src/providers/umami.ts, parseRemoteFile ca…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.28%via NVD
CVE-2026-45766High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffi…

▾ Twilightoisf · suricataEPSS 0.62%via NVD
CVE-2026-14873High· 8.0
3w ago

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating th…

▾ Twilightrubenw · Bulk Password ResetEPSS 0.23%via NVD
CVE-2022-26962Medium· 5.4
3w ago

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-81803High· 7.5
3w ago

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

▾ TwilightAteeq Rafeeq · computer-repair-shopEPSS 0.58%via NVD
CVE-2026-66674Medium· 5.6
3w ago

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

▾ SunlitElliot Sowers/ RelyWP · simple-cloudflare-turnstileEPSS 0.25%via NVD
CVE-2026-82092High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.77%via NVD
CVE-2026-82107Critical· 9.6
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.54%via NVD
CVE-2026-59679Critical· 9.0
3w ago

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…

▾ MidnightSUSE · libXfont2-2EPSS 0.40%via NVD
CVE-2026-80354High· 8.1
3w ago

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposin…

Authorization bypass through User-Controlled key vulnerability in Apache Camel K. An authorization vulnerability in custom resource resolution allows a tenant to reference secrets by name in the operator namespace, potentially exposin…

▾ Twilightapache · camelEPSS 0.50%via NVD
CVE-2026-45759High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata could repeatedly perform expensive parsing of large HTTP `Content-Disposit…

▾ Twilightoisf · suricataEPSS 0.84%via NVD
CVE-2026-88050Medium· 5.5PoC
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCo…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.15%via NVD
CVE-2026-45769High· 7.5PoC
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5,IKEv2 parser state could grow without bounds while storing client transforms. Repeat…

▾ Midnightoisf · suricataEPSS 1.8%via NVD
CVE-2026-36392Medium· 5.4PoC
3w ago

FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS)

FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject arbitrary JavaScript into an item's title, which is stored server-side and executed in the browser of any client use…

▾ TwilightEPSS 0.23%via NVD
CVE-2026-54054Medium· 6.5
3w ago

Transmute is a free, open-source, self-hosted file conversion and compression tool

Transmute is a free, open-source, self-hosted file conversion and compression tool. Prior to version 1.3.0, Transmute's URL import endpoint, `POST /api/files/url`, is vulnerable to Server-Side Request Forgery (SSRF). The HTTP downloader …

▾ Sunlittransmute-app · transmuteEPSS 0.35%via NVD
CVE-2026-45770High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, a Lua rule that registers too many flow variables can corrupt Lua…

▾ Twilightoisf · suricataEPSS 0.48%via NVD
CVE-2026-65639Critical· 9.5
3w ago

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…

OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplie…

▾ MidnightWebPros · ConfigServer Security & FirewallEPSS 1.4%via CVEORG
CVE-2026-65638Critical· 9.2
3w ago

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…

Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions o…

▾ MidnightWebPros · ConfigServer Security & FirewallEPSS 2.3%via CVEORG
CVE-2026-68487Critical· 9.9
3w ago

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

▾ MidnightWebPros · PleskEPSS 0.65%via CVEORG
CVE-2026-89046High· 8.2PoC
3w ago

zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)

A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.65%via CSAF
CVE-2026-88055Medium· 5.5PoC
3w ago

AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-…

▾ TwilightMintplex-Labs · anything-llmEPSS 0.28%via CVEORG
CVE-2026-88023High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · php_libraryEPSS 0.48%via NVD
CVE-2026-88022High· 7.7
3w ago

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This…

▾ Twilightmongodb · laravel_mongodbEPSS 0.43%via NVD
CVE-2026-85228High· 7.4
3w ago

ai.djl/api: Integer overflow in tensor buffer validation in Deep Java Library (CVE-2026-85228)

A flaw was found in Deep Java Library. Due to an integer overflow during tensor buffer validation, a remote, unauthenticated attacker can send a crafted tensor payload to trigger out-of-bounds memory access. Successful exploitation can all…

▾ TwilightRed Hat · Red Hat build of Debezium 3EPSS 0.54%via CSAF
CVE-2026-52098Critical· 9.8
3w ago

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

▾ Midnightflowiseai · flowiseEPSS 1.1%via NVD
CVEs tagged “cve.org” — page 376 · VulnSea