VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20183 CVEsRSS

CVE-2026-81018Medium· 5.5
3w ago

kernel: platform/x86: think-lmi: Free system certificate signatures (CVE-2026-81018)

A flaw was found in the Linux kernel's `think-lmi` driver. When the driver is removed, the system authentication object fails to free stored certificate signatures, leading to a memory leak. This can result in system instability or denial …

▾ SunlitRed Hat · LinuxEPSS 0.16%via CSAF
CVE-2026-80999Medium· 5.5
3w ago

kernel: net: dsa: realtek: use gpiod_set_value_cansleep for reset GPIO (CVE-2026-80999)

A flaw was found in the Linux kernel's Realtek Digital Subscriber Line (DSA) driver. The driver incorrectly uses gpiod_set_value() instead of gpiod_set_value_cansleep() for reset GPIO operations. This can lead to system warnings when the r…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-80996Medium· 5.5
3w ago

kernel: net: l2tp: do not propagate multicast notification errors (CVE-2026-80996)

A flaw was found in the Linux kernel's L2TP (Layer 2 Tunneling Protocol) networking component. Specifically, the netlink handlers responsible for creating and modifying L2TP tunnels and sessions may fail to propagate multicast notification…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.17%via CSAF
CVE-2026-80993Medium· 5.5
3w ago

kernel: net: phylink: correctly validate returned PCS in phylink_inband_caps (CVE-2026-80993)

A flaw was found in the Linux kernel's `net: phylink` component. The `phylink_inband_caps()` function does not correctly validate the return value from `mac_select_pcs`, which can return an error pointer instead of a valid Physical Coding …

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-80974Medium· 5.5
3w ago

kernel: mfd: sm501: Fix potential memory leaks during remove (CVE-2026-80974)

A flaw was found in the `mfd: sm501` component of the Linux kernel. This vulnerability arises from a failure to properly free allocated memory for `struct sm501_devdata` during the device removal process. A local attacker could potentially…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-62133Medium· 5.4
3w ago

WordPress RTMKit plugin <= 2.1.5 - Cross Site Request Forgery (CSRF) vulnerability

Subscriber Cross Site Request Forgery (CSRF) in RTMKit <= 2.1.5 versions.

▾ Sunlitrometheme · rometheme-for-elementorEPSS 0.14%via CVEORG
CVE-2026-89484Medium· 5.5
3w ago

kernel: lockd: fix NULL dereference on lockowner allocation failure (CVE-2026-89484)

A flaw was found in the Linux kernel's `lockd` component. This vulnerability occurs when the Network Lock Manager (NLM) client attempts to initialize file lock operations without successfully allocating a lockowner. This can lead to a NULL…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89468Medium· 5.5
3w ago

kernel: power: supply: lp8788-charger: fix use-after-free on remove (CVE-2026-89468)

A flaw was found in the Linux kernel's lp8788-charger component. During the removal of the lp8788-charger, a race condition can occur where work can be queued and executed after the associated memory has been freed. This use-after-free vul…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-89467Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: fix use-after-free qcom_battmgr_pdr_notify() queues enable_work when the PMIC GLINK service comes up, and the worker recovers battmgr thro…

In the Linux kernel, the following vulnerability has been resolved: power: supply: qcom_battmgr: fix use-after-free qcom_battmgr_pdr_notify() queues enable_work when the PMIC GLINK service comes up, and the worker recovers battmgr thro…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89462Medium· 5.5
3w ago

kernel: power: supply: max17040: propagate register read errors (CVE-2026-89462)

A flaw was found in the Linux kernel's power supply subsystem, specifically within the max17040 driver. This vulnerability occurs when the `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly handle errors returned by…

▾ SunlitRed Hat · LinuxEPSS 0.17%via CSAF
CVE-2026-81825High· 7.2
3w ago

Simple Ajax Chat <= 20260811 - Unauthenticated Stored Cross-Site Scripting

The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output esc…

▾ Twilightspecialk · Simple Ajax Chat – Add a Fast, Secure Chat BoxEPSS 0.49%via CVEORG
CVE-2026-89252Medium· 6.5PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's…

▾ TwilightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-89256High· 8.7PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-72709Critical· 9.8PoC
3w ago

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any serve…

▾ AbyssalSPIP · SPIPEPSS 0.66%via NVD
CVE-2026-89090Medium· 5.9
3w ago

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response …

▾ SunlitAWS · AWS SDK for Go v2EPSS 0.30%via NVD
CVE-2026-89010Critical· 9.8PoC
3w ago

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to …

▾ AbyssalWAVLINK Technology · WN535M1EPSS 3.2%via NVD
CVE-2026-86781Medium· 5.3
3w ago

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowin…

The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowin…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-89257Medium· 5.4PoC
3w ago

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the …

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-11765Low· 3.3
3w ago

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Argument Injection. This issue affects Pardus Pen: before 4.2.1.

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Argument Injection. This issue affects Pardus Pen: before 4.2.1.

▾ SunlitTUBITAK BILGEM Software Technologies Research Institute · Pardus PenEPSS 0.12%via NVD
CVE-2026-13326Medium· 6.9
3w ago

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

▾ Sunlitqt · qtEPSS 0.15%via NVD
CVE-2026-17176High· 7.7
3w ago

An OS command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation …

An OS command injection vulnerability in the TDDP module of Deco BE11000 and Deco M9 Plus allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation …

▾ TwilightTP-Link Systems Inc. · Deco BE11000 V2EPSS 5.0%via NVD
CVE-2026-84390Critical· 9.8
3w ago

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via <insert attack vector here>

▾ MidnightFortinet · FortiMonitorOnSightEPSS 0.52%via NVD
CVE-2026-14566Medium· 4.3
3w ago

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a sub…

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a sub…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-89250High· 7.5PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can reque…

▾ MidnightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-18121Medium· 6.3
3w ago

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calend…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.29%via NVD
CVE-2026-89240Medium· 6.1PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not…

▾ TwilightWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-81905Medium· 6.3
3w ago

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alo…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.36%via NVD
CVE-2026-84941Medium· 6.9
3w ago

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of …

An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of …

▾ SunlitTP-Link Systems Inc. · Omada Software Controller (Windows)EPSS 0.47%via NVD
CVE-2026-78129Medium· 5.9
3w ago

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

▾ Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-78135Medium· 5.6
3w ago

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

▾ Sunlitstrongswan · strongswanEPSS 0.36%via NVD
CVEs tagged “cve.org” — page 420 · VulnSea