VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18506 CVEsRSS

CVE-2026-87877High· 7.7PoC
3w ago

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointer…

▾ Midnightluben · zstd-jniEPSS 0.20%via NVD
CVE-2026-85102Critical· 9.8CISA KEVPoC
3w ago

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

▾ Hadalcheckpoint · gaia_embeddedEPSS 7.5%via NVD
CVE-2026-87736Medium· 4.3
3w ago

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml

An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC public key out-of-bounds read for compressed points.

▾ SunlitOCaml · mirage-crypto-ecEPSS 0.36%via NVD
CVE-2026-78489Medium· 5.9
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.20%via NVD
CVE-2026-78493Medium· 5.5
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

▾ Sunlitdell · secure_connect_gatewayEPSS 2.5%via NVD
CVE-2026-87812Medium· 6.8
3w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in Bazaar package cards where the iconURL metadata is inserted directly into HTML img src attributes without escaping. Attackers can inject malicious URLs with eve…

▾ Sunlitsiyuan-note · siyuanEPSS 0.36%via NVD
CVE-2026-80918None
3w ago

In the Linux kernel, the following vulnerability has been resolved: HID: core: fix number/pointer type confusion on long items When fetch_item() is called by hid_scan_report() on an item with HID_ITEM_TAG_LONG, it stores a pointer to t…

In the Linux kernel, the following vulnerability has been resolved: HID: core: fix number/pointer type confusion on long items When fetch_item() is called by hid_scan_report() on an item with HID_ITEM_TAG_LONG, it stores a pointer to t…

▾ SunlitLinux · LinuxEPSS 0.18%via NVD
CVE-2026-79967Medium· 5.6
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.15%via NVD
CVE-2024-58380Medium· 6.5
3w ago

PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided

PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an inven…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2026-81644Medium· 4.3
3w ago

DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

▾ SunlitHuawei · HarmonyOSEPSS 0.23%via NVD
CVE-2026-79966Low· 3.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

▾ Sunlitdell · secure_connect_gatewayEPSS 0.14%via NVD
CVE-2026-87807High· 7.5
3w ago

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing pu…

▾ Twilightsiyuan-note · siyuanEPSS 0.45%via NVD
CVE-2026-79617High· 7.1PoC
3w ago

Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

▾ MidnightTÜBİTAK BİLGEM Software Technologies Research Institute · Pardus LightDM GreeterEPSS 0.14%via NVD
CVE-2026-86198Medium· 4.2
3w ago

PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling

PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedl…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2026-21090High· 7.8⚖ disputed
3w ago

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21113Medium· 5.5
3w ago

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

▾ Sunlitsamsung · visual_voicemailEPSS 0.08%via NVD
CVE-2026-75927High· 7.2
3w ago

PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant

The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCa…

▾ Twilightpublishpress · User Role Editor – PublishPress Capabilities: Access Control and User RolesEPSS 0.64%via CVEORG
CVE-2026-19946Medium· 4.3
3w ago

Awesome Support <= 6.3.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Denial via 'user_id' Parameter

The Awesome Support plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 6.3.9. This is due to a missing capability check on the wpas_do_mr_deny_user() function, which unlike its counterpart wpas_…

▾ Sunlitawesomesupport · Awesome Support – WordPress HelpDesk & Support PluginEPSS 0.24%via CVEORG
CVE-2026-19797Medium· 6.1
3w ago

User Access Manager <= 2.3.18 - Reflected Cross-Site Scripting via 'tab_group_section' Parameter

The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_group_section' parameter in all versions up to, and including, 2.3.18 due to insufficient input sanitization and output escaping. T…

▾ Sunlitgm_alex · User Access ManagerEPSS 0.21%via CVEORG
CVE-2026-8615Medium· 4.3
3w ago

ilGhera Reviso Exporter for WooCommerce <= 1.2.3 - Missing Authorization to Authenticated (Subscriber+) Agreement Grant Token Deletion via disconnect_callback Function

The Reviso Exporter for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the disconnect_callback() function in versions up to, and inc…

▾ Sunlitghera74 · ilGhera Reviso Exporter for WooCommerceEPSS 0.34%via CVEORG
CVE-2026-77187Medium· 6.4
3w ago

My Calendar <= 3.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes

The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'before' and 'after' Shortcode Attributes in all versions up to, and including, 3.8.3 due to insufficient input sanitization…

▾ Sunlitjoedolson · My Calendar – Accessible Event ManagerEPSS 0.33%via CVEORG
CVE-2026-15406High· 7.5
3w ago

Eventin <= 4.1.22 - Authenticated (Custom+) Local File Inclusion via 'event_layout' Parameter

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This mak…

▾ Twilightarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.66%via CVEORG
CVE-2026-87923Medium· 4.3PoC
3w ago

Rizwan17 inventory-management-system List DBOperation.php cross site scripting

A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this issue is some unknown functionality of the file includes/DBOperation.php of the component List Handle…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.47%via CVEORG
CVE-2026-40635Medium· 5.4
3w ago

Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability

Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tamper…

▾ Sunlitdell · powerscale_onefsEPSS 0.39%via NVD
CVE-2026-86200Medium· 5.3
3w ago

PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT

PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.64%via NVD
CVE-2026-79963High· 7.4
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potent…

▾ Twilightdell · secure_connect_gatewayEPSS 0.27%via NVD
CVE-2026-79970Medium· 5.6
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with remote access cou…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.17%via NVD
CVE-2026-80171Medium· 4.7
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit …

▾ Sunlitdell · secure_connect_gatewayEPSS 0.12%via NVD
CVE-2026-79693Low· 3.4
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit thi…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.13%via CVEORG
CVE-2026-87811High· 7.3PoC
3w ago

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScrip…

▾ Midnightsiyuan-note · siyuanEPSS 0.37%via NVD
CVEs tagged “cve.org” — page 385 · VulnSea