VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15595 CVEsRSS

CVE-2026-96548Medium· 5.6PoC
5d ago

A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is poss…

▾ Twilightsfturing · hosp_orderEPSS 0.26%via NVD
CVE-2026-96546Low· 2.5PoC
5d ago

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. …

▾ TwilightRed Hat · gimpEPSS 0.11%via NVD
CVE-2026-96545Medium· 4.4PoC
5d ago

An out-of-bounds heap read flaw was found in GIMP's TIM image loader

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the l…

▾ TwilightRed Hat · gimpEPSS 0.18%via NVD
CVE-2026-94181High· 7.4
5d ago

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.

▾ TwilightThe Browser Company of New York · ArcEPSS 0.26%via NVD
CVE-2026-93421Medium· 5.3
5d ago

Mesop is a Python-based UI framework that allows users to build web applications

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report…

▾ Sunlitmesop-dev · mesopEPSS 0.40%via NVD
CVE-2026-90905High· 7.2
5d ago

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated c…

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated c…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.26%via NVD
CVE-2026-90904High· 8.6
5d ago

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-l…

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-l…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.31%via NVD
CVE-2026-90903High· 7.2
5d ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. Al…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.17%via NVD
CVE-2026-90902High· 8.6
5d ago

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdat…

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdat…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.28%via NVD
CVE-2026-90901High· 8.6
5d ago

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) …

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) …

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.28%via NVD
CVE-2026-90900Medium· 5.3
5d ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addRevi…

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addRevi…

▾ Sunlitjoomshaper.com · Easy Store extension for JoomlaEPSS 0.17%via NVD
CVE-2026-90899High· 8.2
5d ago

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.33%via NVD
CVE-2026-84502Critical· 9.9
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the modul…

▾ MidnightRed Hat · automation-controllerEPSS 0.62%via NVD
CVE-2026-84499High· 7.7
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template no…

▾ TwilightRed Hat · automation-controllerEPSS 0.38%via NVD
CVE-2026-84486High· 8.2
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) a…

▾ TwilightRed Hat · automation-controllerEPSS 0.52%via NVD
CVE-2026-84474Critical· 9.9
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template …

▾ MidnightRed Hat · automation-controllerEPSS 0.80%via NVD
CVE-2026-82368High· 8.7
5d ago

Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services

Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed a…

▾ TwilightBrocade · SANnavEPSS 0.25%via NVD
CVE-2026-82356High· 7.5
5d ago

Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate

Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.

▾ TwilightImprivata · Imprivata Enterprise Access ManagementEPSS 0.11%via NVD
CVE-2026-77602Critical· 9.9
5d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later…

▾ Midnightopenc3 · openc3EPSS 0.57%via NVD
CVE-2026-77601High· 8.8PoC
5d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-ap…

▾ MidnightOpenC3 · cosmosEPSS 0.58%via NVD
CVE-2026-77423High· 7.5PoC
5d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in builtins/src/ma…

▾ Midnightjline · jline3EPSS 0.39%via NVD
CVE-2026-77394High· 7.6PoC
5d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /ope…

▾ MidnightOpenC3 · cosmosEPSS 0.39%via NVD
CVE-2026-76648High· 8.5
5d ago

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'r…

▾ TwilightRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.24%via NVD
CVE-2026-76089High· 7.7
5d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-s…

▾ Twilightverbb · formieEPSS 0.24%via NVD
CVE-2026-76087High· 8.2
5d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete subm…

▾ Twilightverbb · formieEPSS 0.31%via NVD
CVE-2026-76086High· 8.5
5d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration…

▾ Twilightverbb · verbb/formieEPSS 0.29%via NVD
CVE-2026-71465Low· 3.1
5d ago

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob. A limit beginning with - is parsed as an ansible CLI op…

▾ SunlitRed Hat · automation-controllerEPSS 0.21%via NVD
CVE-2026-71464Low· 3.1
5d ago

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers. Schedule and WFJT Node accept --upload-pack=/bin/id…

▾ SunlitRed Hat · automation-controllerEPSS 0.21%via NVD
CVE-2026-71463Low· 2.7
5d ago

Notification template Jinja AST whitelist only inspects static Getattr nodes

Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the…

▾ SunlitRed Hat · automation-controllerEPSS 0.27%via NVD
CVE-2026-71462Medium· 4.1
5d ago

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenan…

▾ SunlitRed Hat · automation-controllerEPSS 0.26%via NVD
CVEs tagged “cve.org” — page 62 · VulnSea