VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18496 CVEsRSS

CVE-2026-88277High· 8.8
3w ago

GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection

GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.65%via CVEORG
CVE-2026-68006Critical· 9.1
3w ago

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

▾ MidnightEPSS 0.53%via NVD
CVE-2026-89045Medium· 4.0PoC
3w ago

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method…

▾ Twilightluben · zstd-jniEPSS 0.18%via NVD
CVE-2026-88270Medium· 6.5
3w ago

GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service

GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.37%via CVEORG
CVE-2026-84063Medium· 6.5
3w ago

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allo…

▾ SunlitD-ZERO CO.,LTD. · BurgerEditorEPSS 0.43%via NVD
CVE-2026-84042High· 7.8
3w ago

A flaw was found in crun

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The iss…

▾ TwilightRed Hat · crunEPSS 0.10%via NVD
CVE-2026-73693High· 8.8
3w ago

FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in th…

▾ TwilightFileRun · FileRunEPSS 2.7%via CVEORG
CVE-2026-84819High· 7.1
3w ago

WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.

▾ TwilightGreg Winiarski · wpadvertsEPSS 0.25%via CVEORG
CVE-2026-84062Medium· 4.3
3w ago

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product.

▾ SunlitD-ZERO CO.,LTD. · BurgerEditorEPSS 0.30%via NVD
CVE-2026-81801High· 8.1
3w ago

WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

▾ TwilightUDX Usability Dynamics · wp-statelessEPSS 0.38%via CVEORG
CVE-2026-81794High· 7.5
3w ago

WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

▾ Twilightmlfactory · woo-shirt-product-designerEPSS 0.35%via CVEORG
CVE-2026-81787Medium· 6.5
3w ago

WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

▾ SunlitIDX Broker · idx-broker-platinumEPSS 0.42%via CVEORG
CVE-2026-81782Medium· 6.5
3w ago

WordPress WP Docs plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability

Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions.

▾ SunlitFahad Mahmood · wp-docsEPSS 0.22%via CVEORG
CVE-2026-52097Medium· 6.8
3w ago

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

▾ SunlitEPSS 0.55%via CVEORG
CVE-2026-4657Medium· 6.4
3w ago

Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field

The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta fi…

▾ Sunlitsunny_johal · Easy Google FontsEPSS 0.42%via CVEORG
CVE-2026-89043High· 7.4PoC
3w ago

passport-saml-encrypted through 0.1.13 XML Signature Wrapping via Assertion Prepending

passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SA…

▾ Midnightkrakenjs · passport-saml-encryptedEPSS 0.31%via CVEORG
CVE-2026-15461Medium· 5.3
3w ago

Type confusion in Zephyr HL78xx GNSS NMEA driver causes wild-pointer write from GNSS input

The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embeds a generic struct gnss_nmea0183_match_data match_data inside struct hl78xx_gnss_data. The generic NMEA0183 match he…

▾ Sunlitzephyrproject · zephyrEPSS 0.16%via CVEORG
CVE-2026-12682Medium· 5.4
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9…

▾ SunlitAnkaref Innovation and Technology Inc. · LIBRID/LIBREFEPSS 0.16%via NVD
CVE-2026-15796Medium· 6.4
3w ago

Builderall for WordPress <= 3.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'bg_video_service_url' Setting

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. Thi…

▾ Sunlitbuilderall · Builderall for WordPressEPSS 0.19%via CVEORG
CVE-2026-0309Medium· 4.0
3w ago

PAN-OS: Authenticated Command Injection in CLI with Luna HSM Configuration

A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have…

▾ SunlitPalo Alto Networks · Cloud NGFWEPSS 0.45%via CVEORG
CVE-2026-0307Medium· 5.9
3w ago

GlobalProtect App: Local Privilege Escalation Vulnerabilities

Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administr…

▾ SunlitPalo Alto Networks · GlobalProtect AppEPSS 0.10%via CVEORG
CVE-2026-88281Medium· 4.9
3w ago

GV-LPC2011/LPC2211 - ONVIF DeleteUsers Repeated-Element Stack Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenticated administrator to overflow a stack array and crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via CVEORG
CVE-2026-88280Medium· 4.9
3w ago

GV-LPC2011/LPC2211 - ONVIF SetUser Stack-Frame Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticated administrator to crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via CVEORG
CVE-2026-88011High· 8.1⚖ disputed
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy …

▾ Twilighttraefik · traefikEPSS 0.42%via NVD
CVE-2026-88279Medium· 4.9
3w ago

GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via CVEORG
CVE-2026-88278Critical· 9.8
3w ago

GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

▾ MidnightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.48%via CVEORG
CVE-2026-88007Critical· 9.1
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport …

▾ Midnighttraefik · traefikEPSS 0.60%via NVD
CVE-2026-81051Medium· 6.6
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection…

▾ Sunlitdell · thinosEPSS 0.20%via NVD
CVE-2026-88276High· 7.2
3w ago

GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection

GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.70%via CVEORG
CVE-2026-88275High· 7.2
3w ago

GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via CVEORG
CVEs tagged “cve.org” — page 379 · VulnSea