VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20321 CVEsRSS

CVE-2026-68487Critical· 9.9
3w ago

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

▾ MidnightWebPros · PleskEPSS 0.65%via CVEORG
CVE-2026-89046High· 8.2PoC
3w ago

zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)

A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.65%via CSAF
CVE-2026-88055Medium· 5.5PoC
3w ago

AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-…

▾ TwilightMintplex-Labs · anything-llmEPSS 0.28%via CVEORG
CVE-2026-88023High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · php_libraryEPSS 0.48%via NVD
CVE-2026-88022High· 7.7
3w ago

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value

Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This…

▾ Twilightmongodb · laravel_mongodbEPSS 0.43%via NVD
CVE-2026-85228High· 7.4
3w ago

ai.djl/api: Integer overflow in tensor buffer validation in Deep Java Library (CVE-2026-85228)

A flaw was found in Deep Java Library. Due to an integer overflow during tensor buffer validation, a remote, unauthenticated attacker can send a crafted tensor payload to trigger out-of-bounds memory access. Successful exploitation can all…

▾ TwilightRed Hat · Red Hat build of Debezium 3EPSS 0.54%via CSAF
CVE-2026-52098Critical· 9.8
3w ago

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

▾ Midnightflowiseai · flowiseEPSS 1.1%via NVD
CVE-2026-15418Low· 2.4
3w ago

CP210x Memory Leakage

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Window…

▾ SunlitSilicon Labs · silabser.sys driverEPSS 0.15%via CVEORG
CVE-2026-88026Medium· 6.5
3w ago

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected…

▾ Sunlitmongodb · c#_driverEPSS 0.38%via NVD
CVE-2026-88025High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ident…

▾ Twilightmongodb · c#_driverEPSS 0.48%via NVD
CVE-2026-68527Medium· 5.9
3w ago

Concrete CMS 8.3.0 through 9.5.2 is vulnerable to an authorization bypass through user-controlled key (cross-calendar IDOR) in the Calendar event edit dialog

Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied i…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.47%via CVEORG
CVE-2026-15419High· 7.0
3w ago

CP210x Driver Memory Corruption results in Arbitrary Code Execution

In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

▾ TwilightSilicon Labs · silabser.sys driverEPSS 0.17%via CVEORG
CVE-2026-15417Medium· 6.9
3w ago

CP210x Denial of Service

In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.

▾ SunlitSilicon Labs · silabser.sys driverEPSS 0.13%via CVEORG
CVE-2026-9338Medium· 5.3
3w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially …

▾ Sunlitibm · websphere_application_serverEPSS 0.49%via NVD
CVE-2026-9336Medium· 6.5
3w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server …

▾ Sunlitibm · websphere_application_serverEPSS 0.77%via NVD
CVE-2026-89049Critical· 9.9
3w ago

Server-side request forgery in the Session Manager port forwarding functionality in AWS Systems Manager Agent

A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms …

▾ MidnightAWS · Amazon SSM AgentEPSS 0.66%via CVEORG
CVE-2026-88034High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal iden…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal iden…

▾ Twilightmongodb · c++_driverEPSS 0.46%via NVD
CVE-2026-87090High· 8.3
3w ago

Consul vulnerable to an authorization bypass in the catalog node-write path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker wit…

▾ TwilightHashiCorp · ConsulEPSS 0.37%via CVEORG
CVE-2026-87933High· 8.6PoC
3w ago

cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)

A flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…

▾ MidnightRed Hat · Red Hat Satellite 6EPSS 0.53%via CSAF
CVE-2026-87106Medium· 6.5
3w ago

Consul vulnerable to a denial of service in the native RPC listener

Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal …

▾ SunlitHashiCorp · ConsulEPSS 0.41%via CVEORG
CVE-2026-89054High· 8.2
3w ago

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication

A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the ship…

▾ TwilightThe OpenNMS Group · HorizonEPSS 0.51%via NVD
CVE-2026-88060Medium· 6.1PoC⚖ disputed
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server se…

▾ Twilightangular · angularEPSS 0.36%via NVD
CVE-2026-88021High· 7.5
3w ago

Consul vulnerable to an authorization bypass in the Connect service mesh

Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentio…

▾ TwilightHashiCorp · ConsulEPSS 0.34%via CVEORG
CVE-2026-87107Medium· 5.4
3w ago

Consul vulnerable to an authorization bypass in the catalog deregistration path

Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permiss…

▾ SunlitHashiCorp · ConsulEPSS 0.31%via CVEORG
CVE-2026-81804High· 7.5
3w ago

WordPress ZHBackup – Backup, Restore & Migration plugin <= 2.4.2 - Sensitive Data Exposure vulnerability

Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versions.

▾ TwilightZain Hassan · zhbackupEPSS 0.42%via CVEORG
CVE-2026-79591High· 7.8PoC
3w ago

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

A heap-buffer-overflow and use-after-free vulnerability exists in the xls_getCSS() function of libxls 1.6.3 due to insufficient validation of a file-controlled font index.

▾ MidnightEPSS 0.17%via NVD
CVE-2026-9667Medium· 5.3
3w ago

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a remote, unauthenticated attacker to cause the server to send outbound requests to arbitrary endpoints.

▾ Sunlitibm · websphere_application_serverEPSS 0.43%via NVD
CVE-2026-81784High· 8.1
3w ago

Deserialization of Untrusted Data vulnerability in Marcin Wise Chat wise-chat allows Object Injection.This issue affects Wise Chat: from n/a through 3.4.2.

Deserialization of Untrusted Data vulnerability in Marcin Wise Chat wise-chat allows Object Injection.This issue affects Wise Chat: from n/a through 3.4.2.

▾ TwilightMarcin · wise-chatEPSS 0.44%via NVD
CVE-2026-18386Medium· 4.9
3w ago

WP BackItUp Community Edition <= 2.1.0 - Authenticated (Administrator+) Path Traversal to Arbitrary File Read via 'backup_file' Parameter

The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with a…

▾ Sunlitcssimmon · WP BackItUp Community EditionEPSS 0.73%via CVEORG
CVE-2026-15889Medium· 6.4
3w ago

Aruba HiSpeed Cache <= 3.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content

The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This makes it possibl…

▾ Sunlitarubadev · Aruba HiSpeed CacheEPSS 0.15%via CVEORG
CVEs tagged “cve.org” — page 435 · VulnSea