VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20334 CVEsRSS

CVE-2026-84821High· 7.5
3w ago

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions.

▾ TwilightEpsiloncool · fulltext-searchEPSS 0.39%via NVD
CVE-2026-75584High· 7.5
3w ago

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload

ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bps…

▾ Twilightnasa-jpl · ION-DTNEPSS 0.61%via NVD
CVE-2026-64838High· 8.3PoC
3w ago

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root

ICEcoder versions through 8.1 fail to properly validate the oldFileName parameter in file move and rename operations, allowing authenticated users to relocate files from outside the document root. Attackers can use path traversal sequenc…

▾ MidnightICEcoder · icecoder/icecoderEPSS 0.52%via NVD
CVE-2026-64837High· 8.8
3w ago

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names

ICEcoder through 8.1 passes an unescaped filesystem path into a shell command in lib/properties.php, allowing authenticated users to inject OS commands through directory names. Attackers can create directories with shell metacharacters i…

▾ TwilightICEcoder · icecoder/icecoderEPSS 0.81%via NVD
CVE-2026-64836High· 8.8
3w ago

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check

ICEcoder versions through 8.1 contain a path traversal vulnerability in the file-control endpoint due to a logic error in the document-root confinement check. The File::check() validation function compares realpath() to boolean true, whi…

▾ TwilightICEcoder · icecoder/icecoderEPSS 0.61%via NVD
CVE-2026-88889High· 7.8
3w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties

Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attacke…

▾ Twilightrenovatebot · renovateEPSS 1.0%via NVD
CVE-2026-88883High· 7.7⚖ disputed
3w ago

Renovate is an automated dependency update tool

Renovate is an automated dependency update tool. In versions before 44.14.4 (and Mend Renovate CE/EE images before 15.4.0 and the mend-renovate-enterprise-edition Helm chart before 10.4.0), log sanitisation for TLS private keys used for …

▾ Twilightrenovatebot · renovateEPSS 0.39%via NVD
CVE-2026-88881High· 8.6
3w ago

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

Renovate, a dependency update tool, follows pagination links supplied by the GitHub server in the HTTP `Link` header when interacting with GitHub.com, GitHub Enterprise Cloud, or GitHub Enterprise Server, and sends the credentials config…

▾ Twilightrenovatebot · renovateEPSS 0.41%via NVD
CVE-2026-88879High· 8.2⚖ disputed
3w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three disti…

▾ Twilighttraefik · traefikEPSS 0.29%via NVD
CVE-2026-88878Medium· 5.3⚖ disputed
3w ago

Traefik is an HTTP reverse proxy and load balancer

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by defau…

▾ Sunlittraefik · traefikEPSS 0.42%via NVD
CVE-2026-88876High· 7.5PoC
3w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling get…

▾ MidnightWWBN · AVideoEPSS 0.44%via NVD
CVE-2026-88875Medium· 4.3
3w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and A…

▾ SunlitWWBN · AVideoEPSS 0.31%via NVD
CVE-2026-88873High· 7.1
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests …

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests …

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-88870High· 7.1
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages wit…

▾ TwilightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-88869Critical· 9.3PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated at…

▾ AbyssalWWBN · AVideoEPSS 0.53%via NVD
CVE-2026-88868High· 8.7
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permiss…

▾ TwilightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-88867High· 8.7PoC
3w ago

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability

WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Cate…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-88866High· 8.7PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers …

▾ MidnightWWBN · AVideoEPSS 0.45%via NVD
CVE-2026-88864Critical· 9.1PoC
3w ago

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST

Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassin…

▾ AbyssalCap-go · capgo.appEPSS 0.37%via NVD
CVE-2026-88863High· 8.1
3w ago

capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts

capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /priv…

▾ TwilightCap-go · capgo.appEPSS 0.39%via NVD
CVE-2026-88862High· 8.8PoC
3w ago

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header

Capgo (capgo.app) backend through 12.242.4 does not validate parent-child delegation when processing the x-limited-key-id header. checkKeyByIdPg() in supabase/functions/_backend/utils/hono_middleware.ts resolves the attacker-supplied num…

▾ MidnightCap-go · capgo.appEPSS 0.44%via NVD
CVE-2026-88861High· 8.3PoC
3w ago

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication)

Capgo (Cap-go/capgo.app) contains an authentication bypass affecting all versions (no patched version available at time of publication). The Edge authorization path allows a password-only Supabase aal1 session to exercise privileged RBAC…

▾ MidnightCap-go · capgo.appEPSS 0.52%via NVD
CVE-2026-88860Medium· 6.3
3w ago

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active

Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving stale overrides active. Attackers can retain channel-specific permissions after their base RBAC access has been revoked…

▾ SunlitCap-go · capgo.appEPSS 0.27%via NVD
CVE-2026-88896Medium· 5.3
3w ago

EspoCRM before 10.0.4 is vulnerable to server-side request forgery

EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates outbound URLs to block requests to internal/private IP addresses, strips ::ffff: (IPv4-mapped IPv6) prefixes but doe…

▾ Sunlitespocrm · espocrmEPSS 0.37%via NVD
CVE-2026-38626Critical· 9.8
3w ago

Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

▾ MidnightEPSS 0.47%via NVD
CVE-2026-9166High· 7.5
3w ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.…

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GIS Informatics GisLab Laboratory Management System allows Path Traversal. This issue affects GisLab Laboratory Management System: from 1.4.…

▾ TwilightGIS Informatics · GisLab Laboratory Management SystemEPSS 0.50%via NVD
CVE-2026-9163Critical· 9.8
3w ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from…

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from…

▾ MidnightGIS Informatics · GisLab Laboratory Management SystemEPSS 0.47%via NVD
CVE-2026-9161Medium· 5.3
3w ago

Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not resp…

Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not resp…

▾ SunlitDernekPlus · Website TemplateEPSS 0.33%via NVD
CVE-2026-88038Medium· 4.8
3w ago

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies

cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2 the library validates the cookie name and value against character sets that reject the semicolon separator, but the …

▾ Sunlitcookies · cookiesEPSS 0.25%via NVD
CVE-2026-85545High· 7.1
3w ago

There is an Vulnerability in some HikCentral Access Control versions

There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.

▾ TwilightHikvision · HikCentral Access ControlEPSS 0.29%via NVD
CVEs tagged “cve.org” — page 439 · VulnSea