VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20421 CVEsRSS

CVE-2026-79637High· 7.7
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.25%via CVEORG
CVE-2026-78494High· 7.4
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.24%via CVEORG
CVE-2026-73787High· 7.2
4w ago

Authenticated Arbitrary File Write allows Remote Code Execution via CPPM Web Interface

A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlyin…

▾ TwilightHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 0.84%via CVEORG
CVE-2026-73769High· 7.2
4w ago

Authenticated Remote Code Execution in CPPM Web Interface

A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands…

▾ TwilightHewlett Packard Enterprise (HPE) · ClearPass Policy Manager (CPPM)EPSS 1.1%via CVEORG
CVE-2026-23855High· 7.2
4w ago

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection…

Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions prior to 7.30.10.50, and Dell iDRAC10, 17G versions prior to 1.30.30.50, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection…

▾ TwilightDell · iDRAC9EPSS 0.93%via CVEORG
CVE-2026-21087High· 8.6
4w ago

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

Out-of-bounds write in libmdnie.so prior to SMR Sep-2026 Release 1 allows local attackers to execute arbitrary code with system server privilege.

▾ TwilightSamsung Mobile · Samsung Mobile DevicesEPSS 0.12%via CVEORG
CVE-2026-80925None
4w ago

In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLAN offload Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX) on a lower dev…

In the Linux kernel, the following vulnerability has been resolved: vlan: fix skb_under_panic and races when toggling HW VLAN offload Toggling hardware VLAN TX offload (NETIF_F_HW_VLAN_CTAG_TX or NETIF_F_HW_VLAN_STAG_TX) on a lower dev…

▾ SunlitLinux · LinuxEPSS 0.16%via NVD
CVE-2026-79741Medium· 5.3
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthentica…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 3.5%via CVEORG
CVE-2026-79689Medium· 5.3
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unaut…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 4.7%via CVEORG
CVE-2026-78492High· 7.4
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ TwilightDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.24%via CVEORG
CVE-2026-21101High· 8.4
4w ago

Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

Improper input validation in DualDAR driver prior to SMR Sep-2026 Release 1 allows local privileged attackers to potentially execute arbitrary code with root privilege.

▾ TwilightSamsung Mobile · Samsung Mobile DevicesEPSS 0.12%via CVEORG
CVE-2026-8044High· 8.6
4w ago

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as back…

CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as back…

▾ TwilightSchneider Electric · EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert)EPSS 0.67%via CVEORG
CVE-2026-78484Medium· 5.5
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 2.5%via CVEORG
CVE-2026-87794High· 8.4
4w ago

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend

bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnerability in the nativeZip function that allows attackers to inject arbitrary arguments to the Info-ZIP backend. Attackers can supply a malicious destination path combine…

▾ Twilightnfriedly · bestzipEPSS 0.28%via NVD
CVE-2026-54048Medium· 5.3
4w ago

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but th…

Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but th…

▾ Sunlitapache · impalaEPSS 0.54%via NVD
CVE-2026-87994Medium· 4.3PoC
4w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the channel branch of chat_completion in backend/open_webui/main.py checked channel write access and channel membership for a …

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-87876Low· 3.0PoC
4w ago

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

▾ TwilightRed Hat · cups-mainEPSS 0.33%via NVD
CVE-2026-87998High· 7.1
4w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/knowledge/{id}/delete in backend/open_webui/routers/knowledge.py authorized deletion against the knowledge bas…

▾ Twilightopenwebui · open_webuiEPSS 0.49%via NVD
CVE-2026-87012Medium· 4.3
4w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the share…

▾ Sunlitopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-87014Medium· 6.5PoC
4w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…

▾ Twilightopenwebui · open_webuiEPSS 0.51%via NVD
CVE-2026-74761High· 7.5
4w ago

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affec…

Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affec…

▾ Twilightapache · activemqEPSS 0.62%via NVD
CVE-2026-73334High· 8.1
4w ago

Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data …

▾ TwilightApache Software Foundation · org.apache.parquet.crypto.keytools:parquet-hadoopEPSS 0.36%via CVEORG
CVE-2026-41871Critical· 9.8
4w ago

Apache Nutch: Unauthenticated reflection-based job execution in Nutch Server (Nutch REST API)

Missing Authorization, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server (Nutch REST API). This issue affects Apache Nutch: from 1.10 through 1.22. Users are re…

▾ MidnightApache Software Foundation · Apache NutchEPSS 0.74%via CVEORG
CVE-2026-56207Critical· 9.8
4w ago

Apache Impala: SAML authentication bypass via forged bearer token

Signature of Bearer token is not verified in last step of SAML2 authentication for Impala's hs2-http interface, allowing altering user name and acting as another user. This issue affects Apache Impala: >=4.0.0. Users are recommende…

▾ MidnightApache Software Foundation · Apache ImpalaEPSS 0.46%via CVEORG
CVE-2026-50165High· 7.1
4w ago

alf.io has Improper Access Control for Organization Owners that Exposes System Secrets

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. An Improper Access Control issue in versions prior to 2.0-M5-2605 allows an organization owner to read system-level configuration se…

▾ Twilightalfio-event · alf.ioEPSS 0.35%via CVEORG
CVE-2026-79944Low· 3.4
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Least Privilege Violation vulnerability. A high privileged attacker with local access could potentially exploit thi…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.13%via NVD
CVE-2026-21100Medium· 6.9
4w ago

Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.

Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.

▾ SunlitSamsung Mobile · Samsung Mobile DevicesEPSS 0.09%via CVEORG
CVE-2026-15460Medium· 5.4
4w ago

Missing channel-state validation in Zephyr Bluetooth Classic L2CAP receive path

The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destination channel ID, without checking that the target channel had reach…

▾ Sunlitzephyrproject · zephyrEPSS 0.16%via CVEORG
CVE-2026-41870High· 8.8
4w ago

Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in…

▾ TwilightApache Software Foundation · Apache NutchEPSS 0.66%via CVEORG
CVE-2026-71613High· 7.8PoC
4w ago

Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function

Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function. Fixed in 9a253a07fd3f6b48022bba74302bf39388dda859.

▾ MidnightEPSS 0.20%via CVEORG
CVEs tagged “cve.org” — page 448 · VulnSea