VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15493 CVEsRSS

CVE-2026-56792Medium· 4.4
4d ago

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

▾ SunlitDell · Rugged Control Center (RCC)EPSS 0.09%via NVD
CVE-2026-13016Critical· 9.3
4d ago

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the…

▾ MidnightServiceNow · ServiceNow AI PlatformEPSS 0.27%via NVD
CVE-2026-77293High· 7.1PoC
4d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/se…

▾ Midnightmauriceboe · TREKEPSS 0.38%via NVD
CVE-2026-85738Medium· 6.3
4d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that encode an IPv4 destination. An authenticated user who c…

▾ Sunlitliketrek · TREKEPSS 0.30%via NVD
CVE-2026-77321Medium· 4.3
4d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is registered for scoped OAuth MCP tokens without requiring trips:read and returns core trip summary data regardless of th…

▾ Sunlitmauriceboe · TREKEPSS 0.20%via NVD
CVE-2026-77320Medium· 5.3
4d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns days, assignments, dayNotes, and places through GET /api/shared/:token even when the trip owner disables share_map. …

▾ Sunlitmauriceboe · TREKEPSS 0.23%via NVD
CVE-2026-97320Medium· 6.3PoC
4d ago

A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowledgeDocumentServiceImpl.readUrl of the file AiKnowledgeDocumentServiceImpl.java of the component AI Knowledge Module. …

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.20%via NVD
CVE-2026-48070High· 7.1
4d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directo…

▾ Twilightdocmost · docmostEPSS 0.37%via NVD
CVE-2026-96747Medium· 5.0
4d ago

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host

The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value ending in ".sock" as a local Unix domain socket path rather than a remote host. A user with write access to the encrypt…

▾ SunlitMongoDB · Python DriverEPSS 0.13%via NVD
CVE-2026-48073Medium· 4.3
4d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authenticated user who can edit an exportable page can embed a forged attachmentId that belongs to a restricted page in the …

▾ Sunlitdocmost · docmostEPSS 0.19%via NVD
CVE-2026-77294High· 8.1PoC
4d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlled llm_base_url through the settings API when the LLM_PARSING feature is enabled. Write permission to the target trip …

▾ Midnightmauriceboe · TREKEPSS 0.31%via NVD
CVE-2026-65827Medium· 6.5
4d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated workspace member with edit rights to a space can upload an archive to the page-import feature whose ZIP extraction routine …

▾ Sunlitdocmost · docmostEPSS 0.29%via NVD
CVE-2026-13248High· 8.8
4d ago

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticat…

An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows an authenticat…

▾ TwilightHoneywell · PD45 Industrial PrinterEPSS 0.44%via NVD
CVE-2026-61825High· 8.7
4d ago

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in `SharpEditorFormField`: attacker-controlled content be…

▾ Twilightcode16 · sharpEPSS 0.22%via NVD
CVE-2026-52850Medium· 4.3
4d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member who does not belong to a private space can call the transclusion / sync-block lookup API with a known sourcePageId a…

▾ Sunlitdocmost · docmostEPSS 0.19%via NVD
CVE-2026-97321Medium· 6.3PoC
4d ago

A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function GoViewDataServiceImpl.getDataBySQL of the file yudao-module-report/src/main/java/cn/iocoder/yudao/module/report/serv…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.23%via NVD
CVE-2026-96749High· 8.4
4d ago

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data

An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may occur when a single document is built from an unusually large amount of caller-supplied data. Size arithmetic is perf…

▾ TwilightMongoDB · Python DriverEPSS 0.13%via NVD
CVE-2026-96748Medium· 6.5
4d ago

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters

PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separated on its delimiters. When an application places a hostname value supplied by an unauthenticated party into a conne…

▾ SunlitMongoDB · Python DriverEPSS 0.26%via NVD
CVE-2026-82371High· 8.5
4d ago

Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens

Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals with file read access to retrieve administrative switch credentials and active session tokens. An attacker with access …

▾ TwilightBrocade · SANnavEPSS 0.13%via NVD
CVE-2026-48072Medium· 5.3
4d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image endpoint accepts attacker-controlled fileName path segments and resolves them against local storage without confineme…

▾ Sunlitdocmost · docmostEPSS 0.33%via NVD
CVE-2026-86857High· 8.4
4d ago

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an authenticated user to access data within the ServiceNow AI Platform th…

▾ TwilightServiceNow · ServiceNow AI PlatformEPSS 0.24%via NVD
CVE-2026-61823High· 7.3
4d ago

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces

code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before 9.22.5 contain a stored cross-site scripting vulnerability in the rich-text editor because the HTML sanitizer permit…

▾ Twilightcode16 · sharpEPSS 0.21%via NVD
CVE-2026-52853Medium· 5.2
4d ago

Docmost is open-source collaborative wiki and documentation software

Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN can use the workspace invitation flow to invite an external email address with the OWNER role because the role ceilin…

▾ Sunlitdocmost · docmostEPSS 0.21%via NVD
CVE-2026-13249Critical· 9.8PoC
4d ago

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring aut…

An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring aut…

▾ AbyssalHoneywell · PD45 Industrial PrinterEPSS 0.57%via NVD
CVE-2026-62286Medium· 4.3
4d ago

Dozzle is a realtime log viewer for docker containers

Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a restricted user's label filter to container lists but not to the container-stat and container-event channels returne…

▾ Sunlitamir20 · github.com/amir20/dozzleEPSS 0.34%via NVD
CVE-2026-93405Medium· 6.1
4d ago

Mailspring is a fast, cross-platform, open-source email client

Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markdown, DOCX, and XLSX attachments with Snarkdown, Mammoth, and SheetJS and inserts the resulting HTML into the preview …

▾ SunlitFoundry376 · MailspringEPSS 0.22%via NVD
CVE-2026-81508Medium· 4.3
4d ago

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field from the received media buffer before validating…

▾ Sunlitespressif · esp-idfEPSS 0.21%via NVD
CVE-2026-71540High· 7.5
4d ago

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. From 3.9.0 until 4.14.7, wazuh-clusterd in framework/wazuh/core/cluster/common.py allocates a payload buffer using the…

▾ Twilightwazuh · wazuhEPSS 0.35%via NVD
CVE-2026-61816High· 7.5PoC
4d ago

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Starting in version 2.0.0 and prior to version 3.0.6 and 4.0.2, an uncontrol…

▾ Midnightzbateson · zbateson/mail-mime-parserEPSS 0.39%via NVD
CVE-2026-61815High· 7.2
4d ago

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822

zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading messages in Internet Message Format RFC 822. Prior to version 3.0.6 and 4.0.2, CRLF (carriage-return / line-feed) header …

▾ Twilightzbateson · mail-mime-parserEPSS 0.18%via NVD
CVEs tagged “cve.org” — page 39 · VulnSea