VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15531 CVEsRSS

CVE-2026-95519High· 7.8
4d ago

A flaw was found in rpm

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest …

▾ TwilightRed Hat · rpmEPSS 0.14%via NVD
CVE-2026-97360Critical· 10.0PoC
4d ago

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …

▾ Abyssalrejetto · hfs2EPSS 0.32%via NVD
CVE-2026-94416Medium· 6.8
4d ago

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not…

▾ SunlitRed Hat · ansible-automation-platform-25/gateway-rhel8EPSS 0.45%via NVD
CVE-2026-88916Medium· 6.8
4d ago

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPDF: through 09092026.

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPDF: through 09092026.

▾ SunlitTÜBİTAK ULAKBİM · UlakPDFEPSS 0.21%via NVD
CVE-2026-88907High· 7.4
4d ago

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakPDF: through 09092026.

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakPDF: through 09092026.

▾ TwilightTÜBİTAK ULAKBİM · UlakPDFEPSS 0.32%via NVD
CVE-2026-19072Critical· 9.9
4d ago

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the fiel…

▾ MidnightRapid7 · VelociraptorEPSS 0.40%via NVD
CVE-2026-96515High· 8.6PoC
4d ago

This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality

This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uplo…

▾ MidnightNetlink ICT Pvt Ltd · Netlink ICT HG323RW RouterEPSS 0.31%via NVD
CVE-2026-97182High· 7.3PoC
4d ago

A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1

A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component…

▾ Midnighthalo-dev · HaloEPSS 0.37%via NVD
CVE-2026-19532Medium· 5.3
4d ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124.

▾ SunlitHAVELSAN Inc. · Liman MYSEPSS 0.26%via NVD
CVE-2026-7169High· 7.5
4d ago

a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’…

a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’…

▾ TwilightEvope Collector · Evope CollectorEPSS 0.14%via NVD
CVE-2026-97311Medium· 4.3
4d ago

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-4806Medium· 6.5
4d ago

The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2

The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due to a missing capability check on the save_option() function in all versions up to, and including, 1.1.2. This makes …

▾ Sunlitalexvtn · Custom Thank You Page for WooCommerceEPSS 0.17%via NVD
CVE-2026-3253Medium· 4.3
4d ago

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1…

The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the forms() method of the AdminController class in all versions up to, and including, 1…

▾ Sunlitmailerlite · MailerLite – Signup forms (official)EPSS 0.16%via NVD
CVE-2026-97179Medium· 4.3
4d ago

A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2

A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of the file o2server/x_base_core_project/src/main/java/com/x/base/core/project/connection/CipherConnectionAction.java of …

▾ SunlitEPSS 0.33%via NVD
CVE-2026-79680Medium· 4.5⚖ disputed
4d ago

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module

Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker using a specially modified VNC client that violates the RFB protocol can bypass Qt VNC Server's password authentication…

▾ Sunlitqt · qtEPSS 0.34%via NVD
CVE-2026-16302Medium· 4.3
4d ago

The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option t…

The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.20.0 via the editor_assets function, which exposes the uag_insta_linked_accounts option t…

▾ Sunlitbrainstormforce · Spectra Legacy – Gutenberg BlocksEPSS 0.19%via NVD
CVE-2026-4638High· 7.1
4d ago

PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe

PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters using cscript.exe. If a non-numeric value is passed instead, cscript.exe raises a 'Type mismatch' runtime error that …

▾ TwilightPaessler GmbH · PRTG Network MonitorEPSS 0.27%via NVD
CVE-2026-4637Medium· 5.1PoC
4d ago

Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability

Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnerability. When a request is made for a non-existent resource ending in \".htm\", the web interface returns an HTTP 403 …

▾ TwilightPaessler GmbH · PRTG Network MonitorEPSS 0.55%via NVD
CVE-2026-15731Medium· 6.4
4d ago

The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output …

The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post content in all versions up to, and including, 2.4.31 due to insufficient input sanitization and output …

▾ Sunlitmagazine3 · WP Multilang – Translation and Multilingual PluginEPSS 0.25%via NVD
CVE-2026-92905Medium· 5.3
4d ago

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.

ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowed attackers to crash the log collector using malformed syslog packets.

▾ SunlitZohocorp · ManageEngine EventLog AnalyzerEPSS 0.97%via NVD
CVE-2026-57590High· 8.1
4d ago

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler

A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not properly verify whether the authenticated user has permission to access the project associated with the target Task …

▾ TwilightApache Software Foundation · org.apache.dolphinscheduler:dolphinscheduler-apiEPSS 0.23%via NVD
CVE-2026-18335Medium· 5.4
4d ago

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 6.2.0 via the 'kirki_data' Parameter. This makes it possible fo…

▾ Sunlitthemeum · Kirki – Freeform Page Builder, Website Builder & CustomizerEPSS 0.26%via NVD
CVE-2026-12227Critical· 9.8PoC
4d ago

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter

The Visual Composer Website Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 45.16.0 via the `vcv-template` parameter. This makes it possible for unauthenticated attackers to includ…

▾ Abyssalvisualcomposer · Visual Composer Website BuilderEPSS 0.77%via NVD
CVE-2026-97185High· 7.8
4d ago

A flaw was found in GIMP

A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly validate vector indices before writing into fixed-size arrays. This can lead to an out-of-bounds write, corrupting me…

▾ TwilightRed Hat · gimpEPSS 0.13%via NVD
CVE-2026-85682High· 8.8
4d ago

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10

The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10. This is due to the plugin transmitting a wp_rest nonce to window.opener via postMessage() with a wildcard targetOrig…

▾ Twilightyourownprogrammer · YOP PollEPSS 0.14%via NVD
CVE-2026-78313Medium· 6.5
4d ago

Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Improper Access Control in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ SunlitDeltaww · DIAEnergieEPSS 0.46%via NVD
CVE-2026-78312Critical· 9.1
4d ago

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ MidnightDeltaww · DIAEnergieEPSS 0.34%via NVD
CVE-2026-78311High· 8.8
4d ago

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ TwilightDeltaww · DIAEnergieEPSS 0.24%via NVD
CVE-2026-78310Medium· 4.3
4d ago

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ SunlitDeltaww · DIAEnergieEPSS 0.21%via NVD
CVE-2026-78309High· 8.8
4d ago

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ TwilightDeltaww · DIAEnergieEPSS 0.24%via NVD
CVEs tagged “cve.org” — page 54 · VulnSea