VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18498 CVEsRSS

CVE-2026-85217High· 8.6
3w ago

Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated…

▾ TwilightAutodesk · FusionEPSS 0.19%via CVEORG
CVE-2026-81049Medium· 4.4
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

▾ Sunlitdell · thinosEPSS 0.12%via NVD
CVE-2026-78374Medium· 6.9
3w ago

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no cap…

▾ Sunlitjoomlart.com · T4 Page Builder extension for JoomlaEPSS 0.54%via CVEORG
CVE-2026-78302High· 8.6
3w ago

Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rend…

▾ Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.44%via CVEORG
CVE-2026-78085Medium· 6.9
3w ago

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.50%via CVEORG
CVE-2026-78084Medium· 6.9
3w ago

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file remo…

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.33%via CVEORG
CVE-2026-78083High· 7.1
3w ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) end…

▾ Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.21%via CVEORG
CVE-2026-78082Critical· 9.3
3w ago

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting…

▾ Midnightjoomshaper.com · SP Property extension for JoomlaEPSS 0.51%via CVEORG
CVE-2026-88940Medium· 5.3PoC
3w ago

knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to loc…

▾ Twilightknowns-dev · knownsEPSS 0.56%via CVEORG
CVE-2026-88939High· 8.3PoC
3w ago

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project direct…

▾ Midnightknowns-dev · knownsEPSS 0.48%via NVD
CVE-2026-88937High· 8.8PoC
3w ago

knowns through 0.33.0 Path Traversal via Template Engine

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates t…

▾ Midnightknowns-dev · knownsEPSS 0.65%via CVEORG
CVE-2026-87958High· 8.1
3w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

▾ Twilightibm · db2EPSS 0.38%via NVD
CVE-2026-81550High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-81540High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.55%via NVD
CVE-2026-81265High· 7.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5.

IBM Langflow OSS 1.0.0 through 1.11.5.

▾ Twilightlangflow · langflowEPSS 0.39%via NVD
CVE-2026-81207High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.29%via NVD
CVE-2026-71647High· 7.5
3w ago

An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp

An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp

▾ TwilightEPSS 0.61%via NVD
CVE-2026-9225Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api…

▾ Sunlitlangflow · langflowEPSS 0.35%via NVD
CVE-2026-3096Medium· 4.7
3w ago

The product's web portals allow external links to be opened in a new browser tab

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navig…

▾ SunlitWSO2 · WSO2 API Control PlaneEPSS 0.29%via NVD
CVE-2026-81789High· 8.6
3w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

▾ TwilightStudio Wombat · Advanced Product Fields Extended for WooCommerceEPSS 0.53%via NVD
CVE-2026-49364Critical· 9.1
3w ago

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

▾ Midnightapache · artemisEPSS 0.57%via NVD
CVE-2026-80351Critical· 9.8
3w ago

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

▾ Midnightapache · camelEPSS 1.0%via NVD
CVE-2026-57822Medium· 6.5
3w ago

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

▾ Sunlitapache · artemisEPSS 0.70%via NVD
CVE-2026-88014Medium· 6.3
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.N…

▾ Sunlitrclone · rcloneEPSS 0.15%via NVD
CVE-2026-45747High· 7.5PoC
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lu…

▾ Midnightoisf · suricataEPSS 0.42%via NVD
CVE-2026-88008Critical· 9.1PoC⚖ disputed
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backen…

▾ Abyssaltraefik · traefikEPSS 0.49%via NVD
CVE-2026-87912Medium· 5.9
3w ago

Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials a…

▾ SunlitAWS · AWS Security Agent pluginEPSS 0.44%via CVEORG
CVE-2026-73699High· 7.2PoC
3w ago

FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a position…

▾ MidnightFileRun · FileRunEPSS 0.78%via CVEORG
CVE-2026-73698High· 7.2PoC
3w ago

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

▾ MidnightFileRun · FileRunEPSS 0.62%via NVD
CVE-2026-6285High· 7.5
3w ago

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.

▾ TwilightAnkaref Innovation and Technology Inc. · LIBRID/LIBREFEPSS 0.39%via NVD
CVEs tagged “cve.org” — page 378 · VulnSea