VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15527 CVEsRSS

CVE-2026-56736High· 8.2PoC
4d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4.2.0-alpha allows any unauthenticated user (or low-privileged registered user) to inject arbitrary JavaScript that ex…

▾ Midnightthorsten · phpMyFAQEPSS 0.24%via NVD
CVE-2026-52001None
4d ago

An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts

An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE transport eventSourceInit fetch wrapper " src/lib/utils.ts

▾ SunlitEPSS 0.25%via NVD
CVE-2026-51997High· 8.8
4d ago

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functions

▾ TwilightEPSS 0.53%via NVD
CVE-2026-51996None
4d ago

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function

An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/utils.ts and the getServerUrlHash function

▾ SunlitEPSS 0.29%via NVD
CVE-2026-51995High· 7.5
4d ago

An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components

An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src/lib/authorization-server-metadata.ts, src/lib/utils.ts components

▾ TwilightEPSS 0.47%via NVD
CVE-2026-51994Critical· 9.1
4d ago

mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header

mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata URL extracted from a remote MCP server's WWW-Authenticate header

▾ MidnightEPSS 0.35%via NVD
CVE-2026-19492Low· 3.2
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in a hypervisor call interface. An attacker with root access to a guest partition can read a …

▾ SunlitIBM · PowerVM HypervisorEPSS 0.11%via NVD
CVE-2026-18870Medium· 4.3
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

▾ SunlitIBM · PowerVM HypervisorEPSS 0.18%via NVD
CVE-2026-13467High· 8.1
4d ago

Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

▾ TwilightAltera · Trusted FirmwareEPSS 0.11%via NVD
CVE-2026-13466High· 8.1
4d ago

Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issue affects Trusted Firmware: through socfpga_v2.14.0.

▾ TwilightAltera · Trusted FirmwareEPSS 0.11%via NVD
CVE-2026-13465High· 8.1
4d ago

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Implemented Memory Protections. This issue affects Trusted Firmware: through socfpga_v2.14.0.

▾ TwilightAltera · Trusted FirmwareEPSS 0.11%via NVD
CVE-2026-12559High· 7.3
4d ago

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized scri…

▾ TwilightOpenText · Vendor Invoice Management for SAP SolutionsEPSS 0.39%via NVD
CVE-2026-97062Medium· 5.4PoC
4d ago

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with scrip…

▾ TwilightWebkul · Aureus ERPEPSS 0.22%via NVD
CVE-2026-97061Medium· 4.3
4d ago

Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instance

Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instance. Attackers can query the SearchController or Search::Playlists…

▾ Sunlitblackcandy-org · Black CandyEPSS 0.22%via NVD
CVE-2026-97059High· 8.2
4d ago

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM inst…

▾ TwilightOFFIS · DCMTKEPSS 0.35%via NVD
CVE-2026-97058Medium· 5.3PoC
4d ago

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision value…

▾ Twilightalexei · sprintf-jsEPSS 0.37%via NVD
CVE-2026-97057High· 7.5
4d ago

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis e…

▾ TwilightNodeRedis · redis-parserEPSS 0.39%via NVD
CVE-2026-88360Medium· 5.5
4d ago

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly…

▾ SunlitRed HatEPSS 0.14%via NVD
CVE-2026-88359Medium· 6.5PoC
4d ago

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format()

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer…

▾ TwilightRed HatEPSS 0.25%via NVD
CVE-2026-77798Medium· 6.5
4d ago

Velociraptor contains a deadlock condition that may be triggered by authenticated users

Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.

▾ SunlitRapid7 · VelociraptorEPSS 0.20%via NVD
CVE-2026-77797Low· 3.6
4d ago

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

▾ SunlitRapid7 · VelociraptorEPSS 0.10%via NVD
CVE-2026-18857Low· 3.4
4d ago

IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface

IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service …

▾ SunlitIBM · OPENBMCEPSS 0.11%via NVD
CVE-2026-18104Low· 3.3
4d ago

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

▾ SunlitIBM · Db2 Mirror for iEPSS 0.06%via NVD
CVE-2026-17511Low· 3.4
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authent…

▾ SunlitIBM · PowerVM HypervisorEPSS 0.13%via NVD
CVE-2026-17504Medium· 5.1
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to…

▾ SunlitIBM · PowerVM HypervisorEPSS 0.10%via NVD
CVE-2026-17503Medium· 5.1
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration. An attacker …

▾ SunlitIBM · PowerVM HypervisorEPSS 0.10%via NVD
CVE-2026-17413Medium· 5.1
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface. An attacker with administrat…

▾ SunlitIBM · PowerVM HypervisorEPSS 0.10%via NVD
CVE-2026-91187Critical· 9.3
4d ago

Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token

Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authent…

▾ Midnightdashbit · nimble_ztaEPSS 0.30%via NVD
CVE-2026-97359Critical· 10.0
4d ago

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attac…

▾ Midnightrejetto · hfs2EPSS 0.78%via NVD
CVE-2026-95521High· 7.8
4d ago

A command injection flaw was found in rpm

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating th…

▾ TwilightRed Hat · rpmEPSS 0.58%via NVD
CVEs tagged “cve.org” — page 53 · VulnSea