VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20185 CVEsRSS

CVE-2026-77159Medium· 5.5PoC
3w ago

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can…

▾ TwilightRed Hat · libvirtEPSS 0.16%via NVD
CVE-2026-88914Medium· 4.4
3w ago

A flaw was found in GStreamer's gst-plugins-good isomp4 plugin

A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in th…

▾ SunlitRed Hat · gstreamer1-plugins-goodEPSS 0.12%via NVD
CVE-2026-87985Critical· 10.0
3w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute…

▾ Midnightmistralai · mistral-vibeEPSS 0.56%via NVD
CVE-2026-89298Medium· 4.9
3w ago

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retriev…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.41%via NVD
CVE-2026-71416High· 8.8PoC
3w ago

Headroom compresses data before the data reaches a large language model

Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to …

▾ Midnightheadroomlabs-ai · headroomEPSS 0.22%via NVD
CVE-2026-89169Medium· 4.1
3w ago

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

▾ SunlitDebian · live-bootEPSS 0.15%via NVD
CVE-2026-47839Critical· 9.2
3w ago

A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration

A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an …

▾ MidnightCloud Foundry Foundation · UAAEPSS 0.31%via NVD
CVE-2026-38056High· 8.8
3w ago

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0

A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the pri…

▾ TwilightST Engineering iDirect · Evolution iQ‑Series terminalsEPSS 0.15%via NVD
CVE-2026-57843Medium· 5.5
3w ago

NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, whi…

NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, whi…

▾ SunlitThe NetBSD Foundation · NetBSDEPSS 0.14%via NVD
CVE-2026-57842High· 7.0
3w ago

NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path

NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to exe…

▾ TwilightThe NetBSD Foundation · NetBSDEPSS 0.14%via NVD
CVE-2026-84960Medium· 6.1
3w ago

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping

The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes…

▾ Sunlitcbutlerjr · WP-Members Membership PluginEPSS 0.37%via NVD
CVE-2026-77150Medium· 6.1
3w ago

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping.…

The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping.…

▾ Sunlitunitecms · Unlimited Elements For ElementorEPSS 0.45%via NVD
CVE-2026-89147High· 7.5PoC
3w ago

Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections

Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can conn…

▾ Midnightnet-snmp · Net-SNMPEPSS 0.49%via NVD
CVE-2026-87123Medium· 5.9
3w ago

hbs is an Express view engine wrapper for Handlebars

hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during output escaping when an async helper, registered with registerAsyncHelper, resolves to an object whose toHTML property is truthy but…

▾ Sunlithbs · hbsEPSS 0.41%via NVD
CVE-2026-86815Medium· 5.5
3w ago

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.…

The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-86782Medium· 5.5
3w ago

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do n…

The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do n…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-86780Medium· 6.8
3w ago

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting …

The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting …

▾ SunlitEPSS 0.43%via NVD
CVE-2026-86779Low· 2.7
3w ago

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above…

The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-85678Medium· 6.8
3w ago

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary Java…

The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary Java…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-85677High· 8.8
3w ago

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted …

The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-83546Medium· 6.8
3w ago

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when t…

The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when t…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-83545Medium· 6.8
3w ago

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes …

The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes …

▾ SunlitEPSS 0.43%via NVD
CVE-2026-82305Medium· 5.3
3w ago

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

▾ SunlitEPSS 0.30%via NVD
CVE-2026-74925High· 7.2
3w ago

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-14562Medium· 5.3
3w ago

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated atta…

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated atta…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-14560Critical· 10.0
3w ago

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitra…

The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitra…

▾ MidnightEPSS 0.44%via NVD
CVE-2026-87859Medium· 5.3
3w ago

morgan is an HTTP request logger middleware for Node.js

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.41%via NVD
CVE-2026-86813Medium· 4.8
3w ago

The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, su…

The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, su…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-86809Medium· 5.3
3w ago

The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to comple…

The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to comple…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-85116Medium· 6.5
3w ago

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to exe…

The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to exe…

▾ SunlitEPSS 0.31%via NVD
CVEs tagged “cve.org” — page 421 · VulnSea