VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18504 CVEsRSS

CVE-2026-49836Medium· 4.6PoC
3w ago

psd-tools is a Python package for working with Adobe Photoshop PSD files

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …

▾ Twilightpsd-tools · psd-toolsEPSS 0.19%via NVD
CVE-2026-49837Medium· 5.9
3w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the f…

▾ Sunlitosrg · gobgpEPSS 0.33%via NVD
CVE-2026-49838Medium· 5.9
3w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …

▾ Sunlitosrg · gobgpEPSS 0.41%via NVD
CVE-2026-49313Medium· 5.5
3w ago

Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

▾ SunlitHuawei · HarmonyOSEPSS 0.11%via NVD
CVE-2026-71801Critical· 9.8PoC
3w ago

An issue was discovered in s-pms SPMS-Server through v1.0

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A r…

▾ AbyssalEPSS 0.79%via NVD
CVE-2026-87875Medium· 4.3PoC
3w ago

Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backen…

▾ TwilightRed Hat · cups-mainEPSS 0.39%via CVEORG
CVE-2026-56711High· 7.0
3w ago

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the pri…

▾ TwilightVideoLAN · VLC media playerEPSS 0.12%via NVD
CVE-2026-80914High· 8.8
3w ago

Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready iso_conn_ready() looks up the BIS listener socket with iso_get_sock(), which takes a reference,…

▾ TwilightLinux · LinuxEPSS 0.39%via CVEORG
CVE-2026-79516Medium· 4.0PoC
3w ago

An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.

An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.

▾ TwilightEPSS 0.13%via CVEORG
CVE-2026-75308Medium· 6.1PoC
3w ago

yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS)

yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks file type validation. Attackers can upload files of any type, including HTML, JSP, and other executable files.

▾ TwilightEPSS 0.25%via CVEORG
CVE-2026-71616Medium· 6.2PoC
3w ago

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object()

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.

▾ TwilightEPSS 0.16%via CVEORG
CVE-2026-71614High· 8.4PoC
3w ago

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e409339…

▾ MidnightEPSS 0.22%via CVEORG
CVE-2026-52482High· 7.5
3w ago

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spawns /app/sh_for_telnet

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spawns /app/sh_for_telnet

▾ TwilightEPSS 0.53%via CVEORG
CVE-2026-38998Medium· 6.5
3w ago

A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and …

A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and …

▾ SunlitEPSS 0.44%via CVEORG
CVE-2026-87734High· 7.5PoC
3w ago

An issue was discovered in the utcp package before 0.0.6 for OCaml

An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.

▾ MidnightOCaml · utcpEPSS 0.51%via CVEORG
CVE-2026-80124Medium· 5.5
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.14%via CVEORG
CVE-2026-80175Low· 3.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged at…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.14%via CVEORG
CVE-2026-78491High· 8.2
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.27%via CVEORG
CVE-2026-87810Medium· 5.3PoC
3w ago

Siyuan before v3.8.2 Information Disclosure via fullTextSearchBlock

Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers…

▾ Twilightsiyuan-note · siyuanEPSS 0.34%via CVEORG
CVE-2026-87795High· 8.2PoC
3w ago

com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795)

A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.63%via CSAF
CVE-2026-80174Medium· 5.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially expl…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.27%via CVEORG
CVE-2026-79635High· 7.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially …

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.31%via CVEORG
CVE-2026-87997Medium· 4.3PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id…

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-87016High· 8.1PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that…

▾ Midnightopenwebui · open_webuiEPSS 0.60%via NVD
CVE-2026-79515Medium· 4.3PoC
3w ago

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-79514Medium· 6.5PoC
3w ago

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

▾ Twilightgpac · gpacEPSS 0.54%via NVD
CVE-2026-79513Medium· 6.5PoC
3w ago

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767…

▾ Twilightgpac · gpacEPSS 0.37%via NVD
CVE-2026-71809High· 8.1PoC
3w ago

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

▾ MidnightEPSS 0.59%via NVD
CVE-2026-87929Critical· 9.8PoC
3w ago

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can …

▾ AbyssalMaxSite · MaxSite CMSEPSS 0.53%via NVD
CVE-2026-87872Medium· 6.8
3w ago

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re…

▾ SunlitRed Hat · ansible-collection-community-generalEPSS 0.14%via NVD
CVEs tagged “cve.org” — page 383 · VulnSea