VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18504 CVEsRSS

CVE-2026-88279Medium· 4.9
3w ago

GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service

GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via CVEORG
CVE-2026-88278Critical· 9.8
3w ago

GV-LPCLPC2011/2211 - ONVIF WS-Security PasswordDigest Replay

GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

▾ MidnightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.48%via CVEORG
CVE-2026-88007Critical· 9.1
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport …

▾ Midnighttraefik · traefikEPSS 0.60%via NVD
CVE-2026-81051Medium· 6.6
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection…

▾ Sunlitdell · thinosEPSS 0.20%via NVD
CVE-2026-88276High· 7.2
3w ago

GV-LPCLPC2011/2211 - Wireless WEP Key1-Key4 Command Injection

GeoVision GV-LPC2211 V1.13 allows administrator-controlled WEP key values containing shell syntax to execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.70%via CVEORG
CVE-2026-88275High· 7.2
3w ago

GV-LPC2011/LPC2211 - Wireless WPA-PSK Command Injection

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled WPA-PSK containing shell syntax to execute arbitrary commands as root when wireless configuration is applied.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via CVEORG
CVE-2026-85543Medium· 4.3PoC
3w ago

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.

Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated low-privileged users to obtain device Wi-Fi configuration information through these interfaces.

▾ TwilightHikvision · Wi-Fi series cameraEPSS 0.27%via NVD
CVE-2026-88886High· 7.8
3w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.14.7 (and in Mend Renovate CE/EE distributions before 15.4.0, and the mend-renovate-enterprise-edition Helm chart before 10.4.0), the manager/gradle-wrapper module do…

▾ Twilightrenovatebot · renovateEPSS 0.23%via NVD
CVE-2026-88898Medium· 6.5PoC
3w ago

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces

AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoint path, allowing authenticated users to publish content into other tenants' namespaces. Attackers can write published…

▾ TwilightAppFlowy-IO · AppFlowy-CloudEPSS 0.39%via NVD
CVE-2026-81805High· 8.1
3w ago

Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.

▾ TwilightSiteSkite · siteskiteEPSS 0.37%via NVD
CVE-2026-81799High· 7.5
3w ago

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 versions.

▾ TwilightWP Swings · woo-refund-and-exchange-liteEPSS 0.35%via NVD
CVE-2026-81795High· 7.1
3w ago

Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.

Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.

▾ TwilightDenis Botić · page-visits-counter-liteEPSS 0.25%via NVD
CVE-2026-81791Medium· 6.5
3w ago

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions.

▾ SunlitAshan Perera · eventon-liteEPSS 0.22%via NVD
CVE-2026-81788Medium· 6.3
3w ago

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions.

▾ SunlitIDX Broker · idx-broker-platinumEPSS 0.26%via NVD
CVE-2026-81785Medium· 6.5
3w ago

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions.

▾ SunlitThemekraft · buddyformsEPSS 0.33%via NVD
CVE-2026-81783High· 7.1
3w ago

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.

▾ Twilightmailmunch · mailmunchEPSS 0.40%via NVD
CVE-2026-78536Medium· 6.5
3w ago

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions.

▾ Sunlitrobokassa · robokassaEPSS 0.33%via NVD
CVE-2026-66632Medium· 6.5
3w ago

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions.

▾ SunlitElliot Sowers/ RelyWP · simple-cloudflare-turnstileEPSS 0.28%via NVD
CVE-2026-84821High· 7.5
3w ago

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

▾ TwilightEpsiloncool · fulltext-searchEPSS 0.39%via NVD
CVE-2026-75584High· 7.5
3w ago

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bps…

▾ Twilightnasa-jpl · ION-DTNEPSS 0.61%via NVD
CVE-2026-64838High· 8.3PoC
3w ago

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequenc…

▾ MidnightICEcoder · icecoder/icecoderEPSS 0.52%via NVD
CVE-2026-64837High· 8.8
3w ago

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters i…

▾ TwilightICEcoder · icecoder/icecoderEPSS 0.81%via NVD
CVE-2026-64836High· 8.8
3w ago

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, whi…

▾ TwilightICEcoder · icecoder/icecoderEPSS 0.61%via NVD
CVE-2026-88889High· 7.8
3w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attacke…

▾ Twilightrenovatebot · renovateEPSS 1.0%via NVD
CVE-2026-88883High· 7.7⚖ disputed
3w ago

Renovate is an automated dependency update tool

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for …

▾ Twilightrenovatebot · renovateEPSS 0.39%via NVD
CVE-2026-88881High· 8.6
3w ago

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

▾ Twilightrenovatebot · renovateEPSS 0.41%via NVD
CVE-2026-88879High· 8.2⚖ disputed
3w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three disti…

▾ Twilighttraefik · traefikEPSS 0.29%via NVD
CVE-2026-88878Medium· 5.3⚖ disputed
3w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by defau…

▾ Sunlittraefik · traefikEPSS 0.42%via NVD
CVE-2026-88876High· 7.5PoC
3w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

▾ MidnightWWBN · AVideoEPSS 0.44%via NVD
CVE-2026-88875Medium· 4.3
3w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and A…

▾ SunlitWWBN · AVideoEPSS 0.31%via NVD
CVEs tagged “cve.org” — page 380 · VulnSea