VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20321 CVEsRSS

CVE-2026-79590Medium· 6.5PoC
3w ago

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0

A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functio…

▾ TwilightEPSS 0.37%via NVD
CVE-2026-71645High· 7.5
3w ago

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause a denial of service via the exploration state machine

▾ TwilightEPSS 0.61%via NVD
CVE-2026-71643High· 7.5
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM component

▾ TwilightEPSS 0.61%via NVD
CVE-2026-71642Medium· 4.0
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the EGOReplanFSM::checkCollisionCallback()

▾ SunlitEPSS 0.18%via NVD
CVE-2026-71640Critical· 9.1PoC
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

▾ AbyssalEPSS 0.63%via NVD
CVE-2026-82079High· 7.0
3w ago

Potential Leakage of Nintendo Switch System Information Through a Proximity-Based Remote Attack

A stack-based buffer overflow vulnerability in the Nintendo Switch local wireless networking functionality may allow an attacker within wireless range to execute arbitrary code using return-oriented programming (ROP) through crafted netw…

▾ TwilightNintendo · Nintendo SwitchEPSS 0.25%via CVEORG
CVE-2026-19583Critical· 9.9
3w ago

Velociraptor Required Permissions bypass by using client monitoring queries

Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. Howe…

▾ MidnightRapid7 · VelociraptorEPSS 0.60%via CVEORG
CVE-2026-85217High· 8.6
3w ago

Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated…

▾ TwilightAutodesk · FusionEPSS 0.19%via CVEORG
CVE-2026-81049Medium· 4.4
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

▾ Sunlitdell · thinosEPSS 0.12%via NVD
CVE-2026-78374Medium· 6.9
3w ago

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0

Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The front-end JSON editor endpoint exposes an action called contact that requires no authentication, no CSRF token, no cap…

▾ Sunlitjoomlart.com · T4 Page Builder extension for JoomlaEPSS 0.54%via CVEORG
CVE-2026-78302High· 8.6
3w ago

Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rend…

▾ Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.44%via CVEORG
CVE-2026-78085Medium· 6.9
3w ago

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.50%via CVEORG
CVE-2026-78084Medium· 6.9
3w ago

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file remo…

▾ Sunlitjoomshaper.com · SP Property extension for JoomlaEPSS 0.33%via CVEORG
CVE-2026-78083High· 7.1
3w ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) end…

▾ Twilightjoomshaper.com · SP Property extension for JoomlaEPSS 0.21%via CVEORG
CVE-2026-78082Critical· 9.3
3w ago

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4

Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting…

▾ Midnightjoomshaper.com · SP Property extension for JoomlaEPSS 0.51%via CVEORG
CVE-2026-88940Medium· 5.3PoC
3w ago

knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint

knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to loc…

▾ Twilightknowns-dev · knownsEPSS 0.56%via CVEORG
CVE-2026-88939High· 8.3PoC
3w ago

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions

knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project direct…

▾ Midnightknowns-dev · knownsEPSS 0.48%via NVD
CVE-2026-88937High· 8.8PoC
3w ago

knowns through 0.33.0 Path Traversal via Template Engine

knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates t…

▾ Midnightknowns-dev · knownsEPSS 0.65%via CVEORG
CVE-2026-87958High· 8.1
3w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

▾ Twilightibm · db2EPSS 0.38%via NVD
CVE-2026-81550High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-81540High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.55%via NVD
CVE-2026-81265High· 7.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5.

IBM Langflow OSS 1.0.0 through 1.11.5.

▾ Twilightlangflow · langflowEPSS 0.39%via NVD
CVE-2026-81207High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.29%via NVD
CVE-2026-71647High· 7.5
3w ago

An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp

An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp

▾ TwilightEPSS 0.61%via NVD
CVE-2026-9225Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api…

▾ Sunlitlangflow · langflowEPSS 0.35%via NVD
CVE-2026-3096Medium· 4.7
3w ago

The product's web portals allow external links to be opened in a new browser tab

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navig…

▾ SunlitWSO2 · WSO2 API Control PlaneEPSS 0.29%via NVD
CVE-2026-81789High· 8.6
3w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

▾ TwilightStudio Wombat · Advanced Product Fields Extended for WooCommerceEPSS 0.53%via NVD
CVE-2026-49364Critical· 9.1
3w ago

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

▾ Midnightapache · artemisEPSS 0.57%via NVD
CVE-2026-80351Critical· 9.8
3w ago

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

▾ Midnightapache · camelEPSS 1.0%via NVD
CVE-2026-57822Medium· 6.5
3w ago

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

▾ Sunlitapache · artemisEPSS 0.70%via NVD
CVEs tagged “cve.org” — page 436 · VulnSea