VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

18506 CVEsRSS

CVE-2026-87813High· 7.3PoC
3w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing ma…

▾ Midnightsiyuan-note · siyuanEPSS 0.37%via NVD
CVE-2026-21112Medium· 5.5
3w ago

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.

▾ Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-57825Medium· 5.7
3w ago

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

▾ SunlitOCaml · opamEPSS 0.47%via NVD
CVE-2026-87035Medium· 4.3
3w ago

Tanium addressed an information disclosure vulnerability in Comply.

Tanium addressed an information disclosure vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.30%via NVD
CVE-2026-87823High· 8.2PoC
3w ago

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near…

▾ Midnightluben · zstd-jniEPSS 0.43%via NVD
CVE-2026-61915Medium· 4.2
3w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two o…

▾ Sunlitcyrus · imapEPSS 0.26%via NVD
CVE-2026-88001Medium· 5.0PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when A…

▾ Twilightopenwebui · open_webuiEPSS 0.38%via NVD
CVE-2026-79974Medium· 6.4
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.30%via NVD
CVE-2025-71417Medium· 6.5
3w ago

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple co…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.31%via NVD
CVE-2026-78485High· 7.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated a…

▾ Twilightdell · secure_connect_gatewayEPSS 0.37%via NVD
CVE-2026-82563High· 7.6
3w ago

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of fir…

▾ TwilightSoftish · EarVision Android applicationEPSS 0.24%via NVD
CVE-2026-21091High· 7.8⚖ disputed
3w ago

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21102Medium· 6.7⚖ disputed
3w ago

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

▾ Sunlitsamsung · androidEPSS 0.12%via NVD
CVE-2026-86773Medium· 5.4PoC
3w ago

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authoriz…

▾ Twilightsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-21106Medium· 5.1
3w ago

Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.

Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.

▾ SunlitSamsung Mobile · Samsung Cloud AssistantEPSS 0.10%via NVD
CVE-2026-71805Critical· 9.8PoC
3w ago

An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0

An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /a…

▾ AbyssalEPSS 0.65%via NVD
CVE-2026-79962Medium· 5.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. An unaut…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.31%via NVD
CVE-2026-87032Medium· 4.3
3w ago

Tanium addressed an information disclosure vulnerability in Tanium Server.

Tanium addressed an information disclosure vulnerability in Tanium Server.

▾ SunlitTanium · Tanium ServerEPSS 0.29%via NVD
CVE-2026-61909Low· 3.5
3w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contact…

▾ Sunlitcyrus · imapEPSS 0.20%via NVD
CVE-2026-79735Medium· 4.4
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentiall…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.32%via NVD
CVE-2026-87924Medium· 6.5PoC
3w ago

A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoice Generation. Su…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.76%via NVD
CVE-2026-86758Medium· 6.5
3w ago

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys

Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all lic…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.41%via NVD
CVE-2026-86744Low· 2.2
3w ago

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths

Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset checkout paths. Api\AssetsController::checkout() and Assets\AssetCheckoutController::store() call Asset::availableForChec…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.27%via NVD
CVE-2026-88000Medium· 6.5PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py t…

▾ Twilightopenwebui · open_webuiEPSS 0.59%via NVD
CVE-2026-83530Medium· 4.3⚖ disputed
3w ago

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be …

A user could provide an expression whose string length is longer than the ParserExpressionSizeLimit() configured on the CEL environment, and a memory allocation would occur proportional to the size of the input before the limit would be …

▾ Sunlitgoogle · common_expression_languageEPSS 0.15%via NVD
CVE-2026-86763Low· 3.5
3w ago

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route)

Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewire\Importer, mounted at the imports.index route). The component only checked the broad 'import' ability at mount time,…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.27%via NVD
CVE-2026-87013Medium· 4.3PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/v1/folders/{id}/update/parent allowed a user to place a folder under itself or one of its descendants, while the fo…

▾ Twilightopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-79738High· 7.5
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Twilightdell · secure_connect_gatewayEPSS 0.41%via NVD
CVE-2026-87017Medium· 4.3
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built-in knowledge search tool passed the caller's readable knowledge identifiers through a metadata filter, but the searc…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-21095Critical· 9.8
3w ago

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

Heap-based buffer overflow in DNG decoder of libimagecodec.quram.so prior to SMR Sep-2026 Release 1 allows remote attackers to execute arbitrary code.

▾ Midnightsamsung · androidEPSS 0.46%via NVD
CVEs tagged “cve.org” — page 386 · VulnSea