VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20168 CVEsRSS

CVE-2026-79395Critical· 9.8
3w ago

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass …

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass …

▾ MidnightEPSS 0.77%via NVD
CVE-2026-79035Medium· 6.1
3w ago

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …

▾ SunlitEPSS 0.26%via NVD
CVE-2026-78807High· 7.1
3w ago

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.11%via NVD
CVE-2026-78131Low· 3.7
3w ago

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

▾ Sunlitstrongswan · strongswanEPSS 0.23%via NVD
CVE-2026-78172Medium· 6.1
3w ago

Themify – WooCommerce Product Filter <= 1.5.5 - Reflected Cross-Site Scripting

The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping…

▾ Sunlitthemifyme · Themify – WooCommerce Product FilterEPSS 0.37%via CVEORG
CVE-2026-72708High· 7.5PoC
3w ago

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

▾ MidnightSPIP · SPIPEPSS 0.52%via NVD
CVE-2026-7298Medium· 6.1
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0.

▾ SunlitIdeaSoft Software Industry and Trade Inc. · Smart E-CommerceEPSS 0.25%via NVD
CVE-2026-89245Medium· 6.5PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can cra…

▾ TwilightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-68497High· 7.5PoC
3w ago

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-databindEPSS 0.58%via NVD
CVE-2026-62139Medium· 4.3
3w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

▾ SunlitGoogle · google-site-kitEPSS 0.10%via NVD
CVE-2026-14565Medium· 5.4
3w ago

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated …

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated …

▾ SunlitEPSS 0.13%via NVD
CVE-2026-80942Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…

▾ SunlitLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89454Medium· 4.4
3w ago

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89453Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-54047Critical· 9.2
3w ago

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud

Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies …

▾ MidnightLaciSynchroni · serverEPSS 0.30%via NVD
CVE-2026-81009Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value …

In the Linux kernel, the following vulnerability has been resolved: io_uring/query: cap user size passed to copy_struct_to_user io_handle_query_entry() clamps hdr.size for the inbound copy_from_user() but keeps the original user value …

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89158Medium· 6.5
3w ago

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

▾ Sunlitpcre · pcre2EPSS 0.25%via NVD
CVE-2026-6641Medium· 6.4
3w ago

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the…

▾ Sunlitdglingren · Media Library AssistantEPSS 0.36%via NVD
CVE-2026-89243High· 8.1PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permi…

▾ MidnightWWBN · AVideoEPSS 0.38%via NVD
CVE-2026-68528Medium· 6.0
3w ago

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting

Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the …

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.38%via NVD
CVE-2026-78134High· 7.1
3w ago

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

▾ Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-89092Medium· 4.2
3w ago

glibc: nscd stack overflow leads to degraded DNS resolution (CVE-2026-89092)

A flaw was found in glibc, specifically within the nscd service. A remote attacker, operating a malicious Domain Name System (DNS) server, could send an overly large DNS response. This could trigger a stack overflow in the nscd service, ca…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.27%via CSAF
CVE-2026-88260High· 8.7
3w ago

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OA…

Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OA…

▾ TwilightBrainzcompany · Zenius EMS 8.0EPSS 0.32%via NVD
CVE-2026-85979High· 8.6
3w ago

Affected versions of Puppet Enterprise contain a command injection vulnerability

Affected versions of Puppet Enterprise contain a command injection vulnerability. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this parameter, …

▾ TwilightPerforce Software · Puppet EnterpriseEPSS 1.3%via NVD
CVE-2026-78133High· 7.5
3w ago

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

▾ Twilightstrongswan · strongswanEPSS 0.43%via NVD
CVE-2026-78127Low· 3.7
3w ago

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

▾ Sunlitstrongswan · strongswanEPSS 0.35%via NVD
CVE-2026-89262High· 7.5PoC
3w ago

MoguBlog through 6.2 Arbitrary Comment Deletion via Request-Body Ownership Check

MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary commen…

▾ Midnightmoxi624 · MoguBlogEPSS 0.54%via CVEORG
CVE-2026-89251Medium· 6.5PoC
3w ago

AVideo Missing Authorization via AD_Server log.php Wallet Credit

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign vid…

▾ TwilightWWBN · AVideoEPSS 0.18%via CVEORG
CVE-2026-89246Medium· 5.4PoC
3w ago

WWBN AVideo CSV Formula Injection via myComments.download.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated…

▾ TwilightWWBN · AVideoEPSS 0.24%via CVEORG
CVE-2026-89099High· 7.5
3w ago

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption

A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-…

▾ Twilightmongodb · mongodbEPSS 0.32%via NVD
CVEs tagged “cve.org” — page 417 · VulnSea