VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15510 CVEsRSS

CVE-2026-93544Medium· 6.5
4d ago

An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.

An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X server to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.24%via NVD
CVE-2026-94611High· 8.1
4d ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik API serializers return stored credentials when an account has view permission on an affected configuration, even when that account is not…

▾ Twilightgoauthentik · authentikEPSS 0.33%via NVD
CVE-2026-94606High· 8.9
4d ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, authentik email authenticator enrollment during an authentication or enrollment flow accepts a recipient address supplied in the setup request inst…

▾ Twilightgoauthentik · authentikEPSS 0.49%via NVD
CVE-2026-94609High· 8.8PoC
4d ago

authentik is an open-source identity provider

authentik is an open-source identity provider. Prior to 2026.2.7, 2026.5.7, and 2026.8.2, an account with delegated permission to manage a group, group membership, or a user can grant superuser status to an account or assign an existing …

▾ Midnightgoauthentik · authentikEPSS 0.51%via NVD
CVE-2026-93545Medium· 6.5
4d ago

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88385High· 7.5
4d ago

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control t…

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-88378None
4d ago

QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().

QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().

▾ SunlitEPSS 0.17%via NVD
CVE-2026-94281Medium· 6.5
4d ago

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88384Medium· 5.5PoC
4d ago

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.19%via NVD
CVE-2026-91160High· 8.2
4d ago

OpenWA is a free, open source, self-hosted WhatsApp API gateway

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form,…

▾ Twilightrmyndharis · OpenWAEPSS 0.25%via NVD
CVE-2026-56738High· 8.5
4d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value directly into the query string withou…

▾ Twilightthorsten · phpMyFAQEPSS 0.26%via NVD
CVE-2026-88373High· 7.5PoC
4d ago

libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path

libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequentl…

▾ MidnightEPSS 0.34%via NVD
CVE-2026-63498High· 8.7
4d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments…

▾ Twilightgrokability · snipe-itEPSS 0.24%via NVD
CVE-2026-88377None
4d ago

Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers

Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Cr…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-88376High· 7.5PoC
4d ago

Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create()

Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can caus…

▾ MidnightEPSS 0.39%via NVD
CVE-2026-88390High· 7.7PoC
4d ago

An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASS…

An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASS…

▾ MidnightEPSS 0.17%via NVD
CVE-2026-88383Medium· 6.5
4d ago

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind()

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an inco…

▾ SunlitRed Hat · Red Hat Enterprise Linux 7EPSS 0.17%via NVD
CVE-2026-88382High· 7.5PoC
4d ago

hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.

hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.

▾ MidnightEPSS 0.39%via NVD
CVE-2026-97231High· 7.3
4d ago

A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0

A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to la…

▾ Twilightvolotat · AnagnorisisEPSS 0.38%via NVD
CVE-2026-62368High· 8.1PoC
4d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-ta…

▾ Midnightsnipe · snipe/snipe-itEPSS 0.30%via NVD
CVE-2026-97226Medium· 6.3
4d ago

A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1

A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument fi…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-63493High· 8.6
4d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challe…

▾ Twilightsnipe · snipe/snipe-itEPSS 0.27%via NVD
CVE-2026-96750High· 7.1
4d ago

MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view

MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Co…

▾ TwilightMongoDB · CompassEPSS 0.19%via NVD
CVE-2026-96746Medium· 6.5
4d ago

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

▾ SunlitMongoDB · C DriverEPSS 0.37%via NVD
CVE-2026-96745Medium· 5.6
4d ago

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers…

▾ SunlitMongoDB · PHP DriverEPSS 0.30%via NVD
CVE-2026-96744High· 7.1
4d ago

Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than…

Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than…

▾ TwilightMongoDB · Laravel MongoDB (PHP)EPSS 0.29%via NVD
CVE-2026-93541Medium· 6.5
4d ago

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

▾ SunlitX.org · libXiEPSS 0.24%via NVD
CVE-2026-93425Critical· 9.9PoC
4d ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in…

▾ AbyssalDokploy · dokployEPSS 0.62%via NVD
CVE-2026-93283None
4d ago

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to drop the reference taken by…

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to drop the reference taken by…

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-93282High· 8.1
4d ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider …

▾ TwilightLinux · LinuxEPSS 0.31%via NVD
CVEs tagged “cve.org” — page 47 · VulnSea