VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

19060 CVEsRSS

CVE-2026-75940Critical· 9.1
3w ago

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

▾ MidnightLenovo · Health ApplicationEPSS 0.40%via NVD
CVE-2026-82097High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.64%via NVD
CVE-2026-85310Medium· 6.5
3w ago

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

import_contacts Path Traversal in Groundhogg <= 4.7.1 versions.

▾ SunlitAdrian Tobey · groundhoggEPSS 0.44%via NVD
CVE-2026-87925High· 7.3PoC
3w ago

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipula…

▾ MidnightRizwan17 · inventory-management-systemEPSS 0.43%via NVD
CVE-2026-45761Low· 3.3
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a crafted rule using mixed-case frame syntax could trigger a heap buffer overflow w…

▾ Sunlitoisf · suricataEPSS 0.18%via NVD
CVE-2026-88048High· 7.1PoC
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During Fu…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.17%via NVD
CVE-2026-88004High· 7.4
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing a…

▾ Twilighttraefik · traefikEPSS 0.45%via NVD
CVE-2026-88763Medium· 5.9
3w ago

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message …

▾ SunlitRed Hat · skupper-routerEPSS 0.41%via NVD
CVE-2026-19136High· 7.8
3w ago

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

A potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese market, that could allow operating system commands to be executed if a local user opens a specially cr…

▾ TwilightLenovo · Tianxi AI Agent PC ApplicationEPSS 0.87%via NVD
CVE-2026-88029High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal i…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal i…

▾ Twilightmongodb · python_driverEPSS 0.48%via NVD
CVE-2026-45764Critical· 9.1
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in S…

▾ Midnightoisf · suricataEPSS 0.63%via NVD
CVE-2026-88006Medium· 6.5
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without running the OAuth role managem…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-57967Critical· 9.8⚖ disputed
3w ago

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 thr…

An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 thr…

▾ Midnightapache · artemisEPSS 1.1%via NVD
CVE-2026-0304Medium· 4.8
3w ago

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.

▾ SunlitPalo Alto Networks · Cortex XDR Broker VMEPSS 0.22%via NVD
CVE-2026-76652Medium· 4.8
3w ago

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8

An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8. Due to insufficient validation of user-supplied file information, an authenticated remote…

▾ SunlitTP-Link Systems Inc. · TL-MR6400 v8EPSS 0.73%via NVD
CVE-2026-88005Medium· 6.5
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI's OAuth token exchange endpoint issues a session for a provider access token without applying the email domain allow…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-82095High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-18994High· 7.1
3w ago

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files wi…

▾ TwilightLenovo · File Manager ApplicationEPSS 0.10%via NVD
CVE-2026-89044Medium· 6.5
3w ago

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encod…

▾ Sunlitnetty · nettyEPSS 0.28%via NVD
CVE-2026-88265Medium· 5.6
3w ago

A flaw was found in crun

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configura…

▾ SunlitRed Hat · crun-mainEPSS 0.12%via NVD
CVE-2026-88921Medium· 5.1
3w ago

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the con…

MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for rendering MISP element references (attributes, objects, and tags) into inline HTML during PDF report export via the con…

▾ SunlitMISP · MISPEPSS 0.49%via NVD
CVE-2026-88892Medium· 5.0PoC
3w ago

In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts)

In OpenPanel through 2.3.0, the data importer fetches a caller-supplied URL with plain fetch instead of the project's existing SSRF guard (apps/api/src/utils/safe-fetch.ts). In packages/importer/src/providers/umami.ts, parseRemoteFile ca…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.33%via NVD
CVE-2026-45766High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, certain NFS parser state structures were insufficiently bounded. Crafted NFS traffi…

▾ Twilightoisf · suricataEPSS 0.62%via NVD
CVE-2026-14873High· 8.0
3w ago

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating th…

▾ Twilightrubenw · Bulk Password ResetEPSS 0.23%via NVD
CVE-2022-26962Medium· 5.4
3w ago

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-81803High· 7.5
3w ago

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.

▾ TwilightAteeq Rafeeq · computer-repair-shopEPSS 0.58%via NVD
CVE-2026-66674Medium· 5.6
3w ago

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions.

▾ SunlitElliot Sowers/ RelyWP · simple-cloudflare-turnstileEPSS 0.25%via NVD
CVE-2026-82092High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.77%via NVD
CVE-2026-82107Critical· 9.6
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.54%via NVD
CVE-2026-59679Critical· 9.0
3w ago

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…

fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the…

▾ MidnightSUSE · libXfont2-2EPSS 0.40%via NVD
CVEs tagged “cve.org” — page 393 · VulnSea