VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20166 CVEsRSS

CVE-2026-6642Medium· 6.4
3w ago

Media Library Assistant <= 3.35 - Authenticated (Author+) Stored Cross-Site Scripting via Bulk Edit Preset Export/Import

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset fi…

▾ Sunlitdglingren · Media Library AssistantEPSS 0.36%via CVEORG
CVE-2026-62136Medium· 5.3
3w ago

WordPress Flexible Quantity – Measurement Price Calculator for WooCommerce plugin <= 2.3.21 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Flexible Quantity – Measurement Price Calculator for WooCommerce <= 2.3.21 versions.

▾ Sunlitwpdesk · flexible-quantity-measurement-price-calculator-for-woocommerceEPSS 0.29%via CVEORG
CVE-2026-62114Medium· 5.3
3w ago

WordPress Passster plugin <= 4.3.13 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Passster <= 4.3.13 versions.

▾ SunlitWP Chill · content-protectorEPSS 0.31%via CVEORG
CVE-2026-62109High· 7.6
3w ago

WordPress Sky Addons for Elementor plugin <= 3.8.4 - SQL Injection vulnerability

Editor SQL Injection in Sky Addons for Elementor <= 3.8.4 versions.

▾ TwilightwowDevs · sky-elementor-addonsEPSS 0.38%via CVEORG
CVE-2026-62102High· 8.8
3w ago

WordPress Gato GraphQL plugin <= 19.2.3 - Privilege Escalation vulnerability

Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

▾ TwilightGato GraphQL · Gato GraphQLEPSS 0.42%via CVEORG
CVE-2026-62088Medium· 5.3
3w ago

WordPress ElasticPress plugin <= 5.3.4 - Sensitive Data Exposure vulnerability

Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

▾ Sunlit10up · elasticpressEPSS 0.33%via CVEORG
CVE-2026-19991High· 8.1
3w ago

UsersWP <= 1.2.70 - Authenticated (Subscriber+) Arbitrary File Deletion

The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from…

▾ Twilightstiofansisland · UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WPEPSS 0.41%via CVEORG
CVE-2026-18561High· 7.5
3w ago

Unlimited Elements For Elementor <= 2.0.16 - Unauthenticated SQL Injection

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the …

▾ Twilightunitecms · Unlimited Elements For ElementorEPSS 0.33%via CVEORG
CVE-2026-50025Medium· 6.9
3w ago

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it

Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mousehole's HTTP/WebSocket management boundary is reachable without application-layer authentication or browser/LAN prove…

▾ Sunlitt-mart · mouseholeEPSS 0.26%via NVD
CVE-2026-48490Medium· 6.9
3w ago

ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform

ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in versions prior to 1.8.8 allows an attacker to trigger a stack-based buffer overflow when concatenating floating-point…

▾ Sunlitarduino · ArduinoCore-avrEPSS 0.67%via NVD
CVE-2026-82617Critical· 9.8
3w ago

The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers

The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these …

▾ Midnightapache · opennlpEPSS 0.77%via NVD
CVE-2026-67211High· 7.5
3w ago

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4

OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain t…

▾ Twilightapache · opennlpEPSS 0.74%via NVD
CVE-2026-54166High· 7.1
3w ago

Shelf is a platform for tracking physical assets

Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Content Import feat…

▾ TwilightShelf-nu · shelf.nuEPSS 0.43%via NVD
CVE-2026-54165Medium· 6.4PoC
3w ago

Dobase is an open-source, self-hosted workspace with installable tools

Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored DOM-based cross-site scripting (XSS) vulnerability in the public, unauthenticated shared-folder image gallery. A…

▾ Twilightsmgdkngt · dobaseEPSS 0.55%via NVD
CVE-2026-47773High· 7.2
3w ago

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt mem…

▾ Twilightarduino-libraries · ArduinoBLEEPSS 0.15%via NVD
CVE-2026-90460High· 7.6PoC
3w ago

An issue was discovered in OpenStack Keystone before 29.0.3

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or d…

▾ MidnightOpenStack · KeystoneEPSS 0.55%via NVD
CVE-2026-54241High· 7.4
3w ago

libde265 is an open source implementation of the h.265 video codec

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and …

▾ Twilightstrukturag · libde265EPSS 0.39%via NVD
CVE-2026-54240High· 7.4
3w ago

libde265 is an open source implementation of the h.265 video codec

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflo…

▾ Twilightstrukturag · libde265EPSS 0.39%via NVD
CVE-2026-45057Medium· 4.9
3w ago

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself i…

▾ Sunlitmatrix-org · matrix-sdk-uiEPSS 0.23%via NVD
CVE-2026-45056Medium· 6.9⚖ disputed
3w ago

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the…

▾ Sunlitmatrix-org · matrix-rust-sdkEPSS 0.31%via NVD
CVE-2026-44715High· 8.7
3w ago

OpenMRS is an open source electronic medical record system platform

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, w…

▾ Twilightopenmrs · org.openmrs.module:legacyui-apiEPSS 0.41%via NVD
CVE-2026-54258Medium· 6.5PoC
3w ago

ZoneMinder is a free, open source closed-circuit television software application

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to …

▾ TwilightZoneMinder · zoneminderEPSS 0.34%via NVD
CVE-2026-54248Medium· 6.5
3w ago

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided …

▾ Sunlitkimdre · doco-cdEPSS 0.40%via NVD
CVE-2026-49846High· 7.5
3w ago

libks provides foundational support for signalwire C products

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. Th…

▾ Twilightsignalwire · libksEPSS 0.50%via NVD
CVE-2026-90461Medium· 6.3
3w ago

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

▾ SunlitOpenStack · IronicEPSS 0.33%via NVD
CVE-2026-90450Medium· 4.3
3w ago

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered…

▾ SunlitCISA · MalcolmEPSS 0.18%via NVD
CVE-2026-90449Medium· 6.5
3w ago

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. A…

▾ SunlitCISA · MalcolmEPSS 0.20%via NVD
CVE-2026-90448Medium· 6.5
3w ago

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwr…

▾ SunlitCISA · MalcolmEPSS 0.18%via NVD
CVE-2026-90447Medium· 6.5
3w ago

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user i…

▾ SunlitCISA · MalcolmEPSS 0.22%via NVD
CVE-2026-90446Medium· 4.3
3w ago

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows …

▾ SunlitCISA · MalcolmEPSS 0.17%via NVD
CVEs tagged “cve.org” — page 416 · VulnSea