VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15493 CVEsRSS

CVE-2026-97326High· 7.3PoC
4d ago

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of…

▾ Midnightsongxinjianqwe · ChatEPSS 0.28%via NVD
CVE-2026-93354High· 8.1
4d ago

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registratio…

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registratio…

▾ TwilightGimanh · taskview-communityEPSS 0.27%via NVD
CVE-2026-88956Medium· 6.8
4d ago

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged syst…

▾ SunlitBotslab · G980HEPSS 0.22%via NVD
CVE-2026-88761Medium· 5.3
4d ago

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine t…

▾ SunlitBotslab · G980HEPSS 0.17%via NVD
CVE-2026-85496High· 8.8
4d ago

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active …

▾ TwilightBotslab · G980HEPSS 0.25%via NVD
CVE-2026-77967High· 8.1
4d ago

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a …

▾ TwilightBotslab · G980HEPSS 0.24%via NVD
CVE-2026-97324High· 7.3
4d ago

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderCon…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.28%via NVD
CVE-2026-96883High· 8.8
4d ago

pgcollection is an open source extension to PostgreSQL

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted S…

▾ TwilightAWS · pgcollectionEPSS 0.65%via NVD
CVE-2026-82372High· 8.5
4d ago

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or…

▾ TwilightBrocade · SANnavEPSS 0.17%via NVD
CVE-2026-48542Medium· 5.4
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

▾ Sunlitkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-97325Medium· 4.3PoC
4d ago

A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/syste…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.26%via NVD
CVE-2026-82164High· 7.1
4d ago

Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability

Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…

▾ TwilightDell · Trusted Device Client,EPSS 0.09%via NVD
CVE-2026-93291Critical· 9.4
4d ago

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

▾ MidnightEufy · Omni C20EPSS 0.24%via NVD
CVE-2026-48543Medium· 5.4PoC
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

▾ Twilightkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-48541Medium· 5.4
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

▾ Sunlitkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-93290Medium· 5.5
4d ago

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

▾ SunlitEufy · Omni C20EPSS 0.11%via NVD
CVE-2026-84399High· 8.8
4d ago

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established i…

▾ TwilightBotslab · G980HEPSS 0.19%via NVD
CVE-2026-48540Medium· 5.4PoC
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

▾ Twilightkrayin · laravel-crmEPSS 0.17%via NVD
CVE-2026-93289High· 7.5
4d ago

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

▾ TwilightEufy · Omni C20EPSS 0.68%via NVD
CVE-2026-82566High· 8.8
4d ago

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions…

▾ TwilightBotslab · G980HEPSS 0.28%via NVD
CVE-2026-97323Medium· 6.3PoC
4d ago

A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.40%via NVD
CVE-2026-97322Medium· 4.3
4d ago

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the c…

▾ SunlitYunaiV · ruoyi-vue-proEPSS 0.26%via NVD
CVE-2026-89325High· 7.8
4d ago

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Asse…

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Asse…

▾ TwilightRapid7 · Insight AgentEPSS 0.13%via NVD
CVE-2026-86860Critical· 9.3
4d ago

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what wa…

▾ MidnightServiceNow · ServiceNow AI PlatformEPSS 0.30%via NVD
CVE-2026-86859High· 8.7
4d ago

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform …

▾ TwilightServiceNow · ServiceNow AI PlatformEPSS 0.29%via NVD
CVE-2026-86858High· 8.7
4d ago

ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform

ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete insta…

▾ TwilightServiceNow · ServiceNow AI PlatformEPSS 0.27%via NVD
CVE-2026-82157High· 8.3
4d ago

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading t…

▾ TwilightDell · ThinOS 10EPSS 0.12%via NVD
CVE-2026-81473High· 8.1
4d ago

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

▾ TwilightDell · Rugged Control Center (RCC)EPSS 0.09%via NVD
CVE-2026-81455High· 8.6
4d ago

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

▾ TwilightDell · ThinOS 10EPSS 0.26%via NVD
CVE-2026-57440High· 7.5
4d ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (n…

▾ TwilightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.26%via NVD
CVEs tagged “cve.org” — page 38 · VulnSea