VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15572 CVEsRSS

CVE-2026-93577Critical· 9.9
4d ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on…

▾ MidnightGitLab · GitLabEPSS 0.43%via NVD
CVE-2026-92874Medium· 5.4
4d ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to …

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with an MCP-scoped token to …

▾ SunlitGitLab · GitLabEPSS 0.14%via NVD
CVE-2026-92628Low· 3.1
4d ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search r…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under a race condition, the MCP search tool's shared state handling could have caused search r…

▾ SunlitGitLab · GitLabEPSS 0.13%via NVD
CVE-2026-92529Medium· 4.3
4d ago

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions…

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user with developer-role permissions…

▾ SunlitGitLab · GitLabEPSS 0.18%via NVD
CVE-2026-92470High· 7.7
4d ago

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD varia…

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD varia…

▾ TwilightGitLab · GitLabEPSS 0.21%via NVD
CVE-2026-89078Critical· 9.9
4d ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on…

▾ MidnightGitLab · GitLabEPSS 0.36%via NVD
CVE-2026-96739Medium· 4.3PoC
4d ago

A flaw has been found in SEMCMS up to 4.2

A flaw has been found in SEMCMS up to 4.2. Affected by this issue is some unknown functionality of the file /Edit/php/upload_json.php of the component KindEditor Upload Interface. This manipulation of the argument imgFile causes cross si…

▾ TwilightEPSS 0.26%via NVD
CVE-2026-92530Medium· 4.3
4d ago

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request autho…

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request autho…

▾ SunlitGitLab · GitLabEPSS 0.11%via NVD
CVE-2026-47132Medium· 5.4PoC
4d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injection vulnerability in phpMyFAQ’s chat user search allows any logged-in user to bypass the intended display-name search …

▾ Twilightthorsten · thorsten/phpmyfaqEPSS 0.25%via NVD
CVE-2026-96680Medium· 4.3PoC
5d ago

A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2

A vulnerability was detected in ByteDance Coze Scraper Extension up to 2.0.2. Affected by this vulnerability is the function chrome.runtime.onMessageExternal.addListener of the file static/background/index.js of the component External Me…

▾ TwilightByteDance · Coze Scraper ExtensionEPSS 0.26%via NVD
CVE-2026-96678Medium· 6.3
5d ago

A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f

A security vulnerability has been detected in weiqingwen spring-boot-forum up to 538eecc3c6b85fdf0768ab4e8354b48c0c17d94f. Affected is the function validate of the file src/main/java/com/qingwenwei/util/NewUserFormValidator.java of the c…

▾ Sunlitweiqingwen · spring-boot-forumEPSS 0.34%via NVD
CVE-2026-96676Medium· 6.3PoC
5d ago

A vulnerability was identified in Fast FAC1900R 20190827_2.0.2

A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote.…

▾ TwilightFast · FAC1900REPSS 0.24%via NVD
CVE-2026-70125High· 8.8
5d ago

Microsoft Office Outlook Remote Code Execution Vulnerability

Microsoft Office Outlook Remote Code Execution Vulnerability

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.44%via NVD
CVE-2026-59980Medium· 6.3
5d ago

hpack is an HTTP/2 Header Encoding for Python

hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, unbounded variable integer decoding can cause run-away computation on malformed input leading to O(n^2) runtime, effectively blocking further processing with large en…

▾ Sunlitpython-hyper · hpackEPSS 0.30%via NVD
CVE-2026-96606Medium· 5.3
5d ago

A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13

A security flaw has been discovered in LB-Link BL-CPE600EU 5.8.13. This vulnerability affects unknown code of the file Mifi_config.bin of the component Configuration Backup Handler. The manipulation results in information disclosure. The…

▾ SunlitLB-Link · BL-CPE600EUEPSS 0.29%via NVD
CVE-2026-96604High· 7.3PoC
5d ago

A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0

A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql i…

▾ MidnightSoftNews Media Group · DataLife EngineEPSS 0.25%via NVD
CVE-2026-96603High· 7.3PoC
5d ago

A vulnerability has been found in Abdurrab5 online-makeup-store

A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing…

▾ MidnightAbdurrab5 · online-makeup-storeEPSS 0.28%via NVD
CVE-2026-93352Critical· 9.8
5d ago

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php

Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address CVE-2026-49972 …

▾ Midnightplank · laravel-mediableEPSS 0.62%via NVD
CVE-2026-81537High· 8.8
5d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to OS command injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.98%via NVD
CVE-2026-81536High· 7.7
5d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity (XXE) injection.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.28%via NVD
CVE-2026-81208High· 7.7
5d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to improper handling of encrypted credentials. An attacker could exploit this vulnerability to obtain credentials intended …

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.23%via NVD
CVE-2026-80423High· 8.8
5d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to the exposure of namespace-wide secrets via accessible file mounts.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.33%via NVD
CVE-2026-96601High· 7.3PoC
5d ago

A vulnerability was detected in Abdurrab5 online-makeup-store

A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack…

▾ MidnightAbdurrab5 · online-makeup-storeEPSS 0.25%via NVD
CVE-2026-96602High· 7.3
5d ago

A flaw has been found in Abdurrab5 online-makeup-store

A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. Th…

▾ TwilightAbdurrab5 · online-makeup-storeEPSS 0.25%via NVD
CVE-2026-75887High· 7.5
5d ago

A flaw was found in the OpenShift console

A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to r…

▾ TwilightRed Hat · openshift4/ose-consoleEPSS 0.36%via NVD
CVE-2026-86583High· 8.8
5d ago

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow

The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.4.17 via the plugin's own export and re-import workflow. The vulnerability exists because the ex…

▾ Twilightcarazo · Import and export users and customersEPSS 0.33%via NVD
CVE-2026-19125High· 8.1PoC
5d ago

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the s…

▾ Midnightlynn999 · EthPress – Web3 LoginEPSS 0.64%via NVD
CVE-2026-82369High· 8.6
5d ago

Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches

Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authenticated users to break out of restricted execution contexts on managed switches. An attacker with command execution permi…

▾ TwilightBrocade · SANnavEPSS 0.51%via NVD
CVE-2026-80425High· 8.8
5d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.94%via NVD
CVE-2026-80412High· 8.8
5d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper escaping of connector property values during OSH script generation.

▾ TwilightIBM · DataStage on Cloud Pak for DataEPSS 0.54%via NVD
CVEs tagged “cve.org” — page 58 · VulnSea