VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20334 CVEsRSS

CVE-2026-81550High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-81540High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.55%via NVD
CVE-2026-81265High· 7.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5.

IBM Langflow OSS 1.0.0 through 1.11.5.

▾ Twilightlangflow · langflowEPSS 0.39%via NVD
CVE-2026-81207High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body …

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.29%via NVD
CVE-2026-71647High· 7.5
3w ago

An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp

An issue in EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via the checkCollisionCallback, execFSMCallback, planFromGlobalTraj in ego_replan_fsm.cpp

▾ TwilightEPSS 0.61%via NVD
CVE-2026-9225Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging to other users due to improper access control in the File/Read File component. When executing flows through the /api…

▾ Sunlitlangflow · langflowEPSS 0.35%via NVD
CVE-2026-3096Medium· 4.7
3w ago

The product's web portals allow external links to be opened in a new browser tab

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navig…

▾ SunlitWSO2 · WSO2 API Control PlaneEPSS 0.29%via NVD
CVE-2026-81789High· 8.6
3w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Studio Wombat Advanced Product Fields Extended for WooCommerce allows Path Traversal. This issue affects Advanced Product Fields Extended fo…

▾ TwilightStudio Wombat · Advanced Product Fields Extended for WooCommerceEPSS 0.53%via NVD
CVE-2026-49364Critical· 9.1
3w ago

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache Act…

▾ Midnightapache · artemisEPSS 0.57%via NVD
CVE-2026-80351Critical· 9.8
3w ago

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled rep…

▾ Midnightapache · camelEPSS 1.0%via NVD
CVE-2026-57822Medium· 6.5
3w ago

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deseriali…

▾ Sunlitapache · artemisEPSS 0.70%via NVD
CVE-2026-88014Medium· 6.3
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.N…

▾ Sunlitrclone · rcloneEPSS 0.15%via NVD
CVE-2026-45747High· 7.5PoC
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lu…

▾ Midnightoisf · suricataEPSS 0.42%via NVD
CVE-2026-88008Critical· 9.1PoC⚖ disputed
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backen…

▾ Abyssaltraefik · traefikEPSS 0.49%via NVD
CVE-2026-87912Medium· 5.9
3w ago

Missing S3 bucket ownership verification in the AWS Security Agent plugin for aws-agents-for-devsecops

A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials a…

▾ SunlitAWS · AWS Security Agent pluginEPSS 0.44%via CVEORG
CVE-2026-73699High· 7.2PoC
3w ago

FileRun < 2026.3.0 PHP Object Injection via Perms::getPerms()

FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a position…

▾ MidnightFileRun · FileRunEPSS 0.78%via CVEORG
CVE-2026-73698High· 7.2PoC
3w ago

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php…

▾ MidnightFileRun · FileRunEPSS 0.62%via NVD
CVE-2026-6285High· 7.5
3w ago

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc

Weak Password Recovery Mechanism for Forgotten Password vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Password Recovery Exploitation. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9.26.2319.

▾ TwilightAnkaref Innovation and Technology Inc. · LIBRID/LIBREFEPSS 0.39%via NVD
CVE-2026-88277High· 8.8
3w ago

GV-LPCLPC2011/2211 - ONVIF Subscribe Address Command Injection

GeoVision GV-LPC2211 V1.13 allows an authenticated ONVIF user to inject shell commands through ConsumerReference.Address and execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPCLPC2011/2211EPSS 0.65%via CVEORG
CVE-2026-68006Critical· 9.1
3w ago

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

▾ MidnightEPSS 0.53%via NVD
CVE-2026-89045Medium· 4.0PoC
3w ago

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops

zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method…

▾ Twilightluben · zstd-jniEPSS 0.18%via NVD
CVE-2026-88270Medium· 6.5
3w ago

GV-LPC2011/LPC2211 - SSVR Guest Firmware-Mode Pre-Validation Service Teardown Denial of Service

GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any firmware image is validated.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.37%via CVEORG
CVE-2026-84063Medium· 6.5
3w ago

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type

BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allo…

▾ SunlitD-ZERO CO.,LTD. · BurgerEditorEPSS 0.43%via NVD
CVE-2026-84042High· 7.8
3w ago

A flaw was found in crun

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The iss…

▾ TwilightRed Hat · crunEPSS 0.10%via NVD
CVE-2026-73693High· 8.8
3w ago

FileRun < 2026.3.0 OS Command Injection via PhotoProofSheet Handler

FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in th…

▾ TwilightFileRun · FileRunEPSS 2.7%via CVEORG
CVE-2026-84819High· 7.1
3w ago

WordPress WPAdverts plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability

Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.

▾ TwilightGreg Winiarski · wpadvertsEPSS 0.25%via CVEORG
CVE-2026-84062Medium· 4.3
3w ago

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key

BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product.

▾ SunlitD-ZERO CO.,LTD. · BurgerEditorEPSS 0.30%via NVD
CVE-2026-81801High· 8.1
3w ago

WordPress WP-Stateless plugin <= 4.4.1 - Settings Change vulnerability

Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.

▾ TwilightUDX Usability Dynamics · wp-statelessEPSS 0.38%via CVEORG
CVE-2026-81794High· 7.5
3w ago

WordPress Shirt Product Designer for WooCommerce plugin 1.0.4 - Broken Access Control vulnerability

Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.

▾ Twilightmlfactory · woo-shirt-product-designerEPSS 0.35%via CVEORG
CVE-2026-81787Medium· 6.5
3w ago

WordPress IMPress for IDX Broker plugin <= 3.3.0 - Broken Authentication vulnerability

Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions.

▾ SunlitIDX Broker · idx-broker-platinumEPSS 0.42%via CVEORG
CVEs tagged “cve.org” — page 437 · VulnSea