VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18498 CVEsRSS

CVE-2026-15418Low· 2.4
3w ago

CP210x Memory Leakage

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Window…

▾ SunlitSilicon Labs · silabser.sys driverEPSS 0.15%via CVEORG
CVE-2026-88026Medium· 6.5
3w ago

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

▾ Sunlitmongodb · c#_driverEPSS 0.38%via NVD
CVE-2026-88025High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

▾ Twilightmongodb · c#_driverEPSS 0.48%via NVD
CVE-2026-68527Medium· 5.9
3w ago

Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog

Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied i…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.47%via CVEORG
CVE-2026-15419High· 7.0
3w ago

CP210x Driver Memory Corruption results in Arbitrary Code Execution

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

▾ TwilightSilicon Labs · silabser.sys driverEPSS 0.17%via CVEORG
CVE-2026-15417Medium· 6.9
3w ago

CP210x Denial of Service

In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.

▾ SunlitSilicon Labs · silabser.sys driverEPSS 0.13%via CVEORG
CVE-2026-9338Medium· 5.3
3w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially …

▾ Sunlitibm · websphere_application_serverEPSS 0.49%via NVD
CVE-2026-9336Medium· 6.5
3w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server …

▾ Sunlitibm · websphere_application_serverEPSS 0.77%via NVD
CVE-2026-89049Critical· 9.9
3w ago

Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms …

▾ MidnightAWS · Amazon SSM AgentEPSS 0.66%via CVEORG
CVE-2026-88034High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal iden…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal iden…

▾ Twilightmongodb · c++_driverEPSS 0.46%via NVD
CVE-2026-87090High· 8.3
3w ago

Consul vulnerable to an authorization bypass in the catalog node-write path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker wit…

▾ TwilightHashiCorp · ConsulEPSS 0.37%via CVEORG
CVE-2026-87933High· 8.6PoC
3w ago

cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)

A flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…

▾ MidnightRed Hat · Red Hat Satellite 6EPSS 0.53%via CSAF
CVE-2026-87106Medium· 6.5
3w ago

Consul vulnerable to a denial of service in the native RPC listener

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal …

▾ SunlitHashiCorp · ConsulEPSS 0.41%via CVEORG
CVE-2026-89054High· 8.2
3w ago

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the ship…

▾ TwilightThe OpenNMS Group · HorizonEPSS 0.51%via NVD
CVE-2026-88060Medium· 6.1PoC⚖ disputed
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server se…

▾ Twilightangular · angularEPSS 0.36%via NVD
CVE-2026-88021High· 7.5
3w ago

Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentio…

▾ TwilightHashiCorp · ConsulEPSS 0.34%via CVEORG
CVE-2026-87107Medium· 5.4
3w ago

Consul vulnerable to an authorization bypass in the catalog deregistration path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permiss…

▾ SunlitHashiCorp · ConsulEPSS 0.31%via CVEORG
CVE-2026-81804High· 7.5
3w ago

WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

▾ TwilightZain Hassan · zhbackupEPSS 0.42%via CVEORG
CVE-2026-79591High· 7.8PoC
3w ago

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

▾ MidnightEPSS 0.17%via NVD
CVE-2026-9667Medium· 5.3
3w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

▾ Sunlitibm · websphere_application_serverEPSS 0.43%via NVD
CVE-2026-81784High· 8.1
3w ago

WordPress Wise Chat plugin <= 3.4 - PHP Object Injection vulnerability

Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.

▾ TwilightMarcin · wise-chatEPSS 0.44%via CVEORG
CVE-2026-18386Medium· 4.9
3w ago

WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter

The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with a…

▾ Sunlitcssimmon · WP BackItUp Community EditionEPSS 0.73%via CVEORG
CVE-2026-15889Medium· 6.4
3w ago

Aruba HiSpeed Cache <= 3.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possibl…

▾ Sunlitarubadev · Aruba HiSpeed CacheEPSS 0.15%via CVEORG
CVE-2026-79590Medium· 6.5PoC
3w ago

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functio…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-71645High· 7.5
3w ago

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine

▾ TwilightEPSS 0.61%via NVD
CVE-2026-71643High· 7.5
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component

▾ TwilightEPSS 0.61%via NVD
CVE-2026-71642Medium· 4.0
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()

▾ SunlitEPSS 0.18%via NVD
CVE-2026-71640Critical· 9.1PoC
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

▾ AbyssalEPSS 0.63%via NVD
CVE-2026-82079High· 7.0
3w ago

Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted netw…

▾ TwilightNintendo · Nintendo SwitchEPSS 0.25%via CVEORG
CVE-2026-19583Critical· 9.9
3w ago

Velociraptor Required Permissions bypass by using client monitoring queries

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howe…

▾ MidnightRapid7 · VelociraptorEPSS 0.60%via CVEORG
CVEs tagged “cve.org” — page 377 · VulnSea