VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

12190 CVEsRSS

CVE-2026-73513High· 7.5
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's optional oghttp2 upstream HTTP/2 codec accepts a response trailer HEADERS frame without END_STRE…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-79320None
today

Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime

Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downstream application enables the experimental slot fixes option and uses scoped components, assigning a string to the te…

Sunlitvia NVD
CVE-2026-73549Medium· 5.3
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's Utility::copyInternetAddressAndPort and QUIC client-address paths reconstruct scoped IPv6 addres…

Sunlitenvoyproxy · envoyvia NVD
CVE-2026-48521Medium· 5.9PoC
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ProdClusterManagerFactory::allocateConnPool dereferences transport_socket_options while selectin…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-73547High· 7.5
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's ext_authz filter assumes that a request contains a :path pseudoheader when applying query_parame…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-73550High· 7.5
today

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy copies every decoded HTTP/2 Host header value before discarding it when :authority is already pres…

Twilightenvoyproxy · envoyvia NVD
CVE-2026-58271Medium· 6.8
today

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/app/sync/register` accepts credentials and a TOTP code to register a desktop sync client. On a failed TOT…

SunlitSync-in · servervia NVD
CVE-2026-91167Medium· 6.0
today

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/:id/roles/:role_id reaches api_update_user_role in warpgate-admin/src/api/users.rs through AdminContext but does not …

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-91166Medium· 5.7
today

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path in warpgate-web-ssh/src/manager.rs handles RCEvent::HostKeyUnknown without the presenting hop identity and instead pas…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-91165Low· 2.4
today

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO return path in warpgate-protocol-http/src/api/sso_provider_list.rs uses serde_json::to_string inside ReturnToSsoPost…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-91164Medium· 4.3
today

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authentication resolves ConfigProvider::validate_api_token into RequestAuthorization::UserToken without enforcing the owning…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-63330High· 7.7
today

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in warpgate-admin/src/api/recordings_detail.rs protects /@warpgate/admin/api/recordings/{uuid}/stream only with session aut…

Twilightwarp-tech · warpgatevia NVD
CVE-2026-63329Medium· 4.9
today

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate-protocol-http/src/proxy.rs forwards a client-supplied x-warpgate-username header before inject_own_headers appends t…

Sunlitwarp-tech · warpgatevia NVD
CVE-2026-61748Medium· 4.3
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and LabelPrint at POST /api/report/label/print/ require authentication but do not call users.permissions.check_user_permissio…

Sunlitinventree · InvenTreevia NVD
CVE-2026-61747Medium· 4.3
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mapping/ endpoints do not scope DataImportRow and DataImportColumnMap querysets to the owner of the associated DataImportSe…

Sunlitinventree · InvenTreevia NVD
CVE-2026-61746Medium· 5.3PoC
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and PluginSettingDetail set GlobalSettingsPermissions without the IsAuthenticated permission used by the project default an…

Twilightinventree · InvenTreevia NVD
CVE-2026-61744Medium· 6.5
today

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesized internal JSON barcode containing a lowercase model label and integer primary key, while BarcodeView uses IsAuthen…

Sunlitinventree · InvenTreevia NVD
CVE-2026-58491Critical· 9.3
today

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler i…

Midnightwarp-tech · warpgatevia NVD
CVE-2026-94411High· 8.8
today

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles

jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authenticated users to grant themselves arbitrary roles. Attackers can send a POST request with type=UserRole, their own us…

Twilightjishenghua · jshERPvia NVD
CVE-2026-82163Medium· 5.5
today

Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability

Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disc…

SunlitDell · Command | Intel vPro Out of Bandvia NVD
CVE-2026-94413Medium· 6.5
today

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user

jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve unsalted MD5 password digests for any user. Attackers can request arbitrary user information by supplying user IDs to…

Sunlitjishenghua · jshERPvia NVD
CVE-2026-94412High· 8.8PoC
today

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password

jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authenticated users to reset any other user's password. Attackers can submit a request with an arbitrary target user ID to …

Midnightjishenghua · jshERPvia NVD
CVE-2026-94496High· 8.3PoC
today

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles

jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to modify any role's data scope or delete roles. Attackers can exploit the /role/update and /role/delete endpoints to esca…

Midnightjishenghua · jshERPvia NVD
CVE-2026-94495High· 7.1
today

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration

jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authenticated users to modify tenant system configuration. Attackers can rewrite or delete tenant-wide settings covering co…

Twilightjishenghua · jshERPvia NVD
CVE-2026-94494Medium· 5.0PoC
today

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint

jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenants' records via the GET /tenant/info endpoint. Attackers can iterate the primary key to enumerate and access sensitive…

Twilightjishenghua · jshERPvia NVD
CVE-2026-94497High· 8.3
today

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types

jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resource types. Authenticated users can read, modify, and delete other users' business objects by submitting direct object …

Twilightjishenghua · jshERPvia NVD
CVE-2026-49810High· 7.8
today

Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability

Dell Command Powershell Provider (DCPP), versions prior to 2.10.2 contain an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leadin…

TwilightDell · Command Powershell Provider (DCPP)via NVD
CVE-2026-94403High· 8.8
today

A weakness has been identified in ColorFul iGameCenter 1.0.3.4

A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library ene.sys of the component IOCTL Handler. This manipulation causes untrusted pointer dereference. The attack can only be…

TwilightColorFul · iGameCentervia NVD
CVE-2026-94414Medium· 5.4PoC
today

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions

jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authenticated users to modify role button-permission definitions. Attackers can supply arbitrary roleId and btnStr parameter…

Twilightjishenghua · jshERPvia NVD
CVE-2026-82165Medium· 5.5
today

Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability

Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Inf…

SunlitDell · Command | Integration Suite for System Centervia NVD
CVEs tagged “cve.org” — page 4 · VulnSea