VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15599 CVEsRSS

CVE-2026-95604High· 7.5
5d ago

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions.

▾ TwilightTangible · tangible-loops-and-logicEPSS 0.33%via NVD
CVE-2026-95603High· 7.2
5d ago

Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.

Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions.

▾ TwilightVictor Rodriguez · reycob-product-import-exportEPSS 0.40%via NVD
CVE-2026-95602Medium· 6.5
5d ago

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n…

Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects YITH WooCommerce Request A Quote: from n…

▾ SunlitYITH · YITH WooCommerce Request A QuoteEPSS 0.28%via NVD
CVE-2026-93618Medium· 6.5
5d ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetTricks allows Stored XSS. This issue affects JetTricks: from n/a through 2.0.1.

▾ SunlitCrocoblock. Jetimpex Inc. · JetTricksEPSS 0.16%via NVD
CVE-2026-77420Medium· 5.5
5d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(String patterns, String line) in reader/src/main/java/org/jline/reader/impl/history/DefaultHistory.java converts the HIS…

▾ Sunlitjline · jline3EPSS 0.12%via NVD
CVE-2026-77422High· 7.5PoC
5d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in builtins/src/main/java/org/jline/builtins/PosixCommands.java accepts a user-controlled regular expression in grep(…

▾ Midnightjline · jline3EPSS 0.50%via NVD
CVE-2026-77421Medium· 6.5
5d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's regex search mode passes a user-controlled search term from doSearch(String text) in builtins/src/main/java/org/jlin…

▾ Sunlitjline · jline3EPSS 0.43%via NVD
CVE-2026-92692Medium· 6.9
5d ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/Quer…

▾ Sunlitsulu · suluEPSS 0.33%via NVD
CVE-2026-88840Medium· 5.3
5d ago

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

▾ SunlitRed Hat · busyboxEPSS 0.21%via NVD
CVE-2026-88839Medium· 6.7
5d ago

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

▾ SunlitRed Hat · busybox-mainEPSS 0.12%via NVD
CVE-2026-88837Medium· 6.5
5d ago

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authentication check.

▾ SunlitRed Hat · busybox-mainEPSS 0.27%via NVD
CVE-2026-88835Medium· 6.1
5d ago

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.

▾ SunlitRed Hat · busybox-mainEPSS 0.12%via NVD
CVE-2026-88831Medium· 5.3
5d ago

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.

▾ SunlitRed Hat · busybox-mainEPSS 0.24%via NVD
CVE-2026-86867Medium· 6.5
5d ago

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls

Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in `libs/ktem/ktem/pag…

▾ SunlitCinnamon AI · KotaemonEPSS 0.18%via NVD
CVE-2026-91775High· 7.4PoC
5d ago

LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import warnings, resulting in XSS in the administrative interface.

▾ MidnightLimeSurvey · LimeSurveyEPSS 0.38%via NVD
CVE-2026-86930Critical· 9.1
5d ago

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect

An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulne…

▾ MidnightClaris · FileMaker ServerEPSS 0.29%via NVD
CVE-2026-86926High· 7.8
5d ago

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution

A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulne…

▾ TwilightClaris · FileMaker ServerEPSS 0.13%via NVD
CVE-2026-96808High· 7.4
5d ago

In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .

In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivileged callers, validated file paths by rejecting literal .. components but did not prevent symlink traversal. A malic…

▾ TwilightFlatpak · FlatpakEPSS 0.12%via NVD
CVE-2026-86938High· 7.3
5d ago

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory

A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability…

▾ TwilightClaris · FileMaker ProEPSS 0.10%via NVD
CVE-2026-86934Critical· 9.1
5d ago

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing …

An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing …

▾ MidnightClaris · FileMaker ServerEPSS 0.33%via NVD
CVE-2026-96807Medium· 4.0
5d ago

In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location

In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regenerate_ld_cache to write files at an arbitrary location. The filenames and content are not attacker controlled, making t…

▾ SunlitFlatpak · FlatpakEPSS 0.12%via NVD
CVE-2026-96804High· 8.8
5d ago

MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control entirely in _load_model(), which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

▾ TwilightMLflow · MLflowEPSS 0.42%via NVD
CVE-2026-96775High· 8.8
5d ago

MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when the model_path ends in .pkl, which allows a remote attacker to execute arbitrary code via a crafted MLmodel artifact.

▾ TwilightMLflow · MLflowEPSS 0.39%via NVD
CVE-2026-96759Critical· 9.8
5d ago

orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects

orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI spe…

▾ Midnightorval-labs · orvalEPSS 0.43%via NVD
CVE-2026-96758Critical· 9.8PoC
5d ago

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema…

▾ Abyssalorval-labs · orvalEPSS 0.54%via NVD
CVE-2026-96757Critical· 9.8PoC
5d ago

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications t…

▾ Abyssalorval-labs · orvalEPSS 0.57%via NVD
CVE-2026-96756High· 8.1
5d ago

orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls

orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in Open…

▾ Twilightorval-labs · orvalEPSS 0.48%via NVD
CVE-2026-96755Critical· 9.8
5d ago

orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals

orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema def…

▾ Midnightorval-labs · orvalEPSS 0.42%via NVD
CVE-2026-96754Critical· 9.8
5d ago

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a st…

▾ Midnightorval-labs · orvalEPSS 0.43%via NVD
CVE-2026-96514High· 7.3PoC
5d ago

A weakness has been identified in Neethuharii CafeManagement

A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogin.php of the component Login Handler. This manipulation of the argument uname causes sql injection. It is possible to…

▾ MidnightNeethuharii · CafeManagementEPSS 0.25%via NVD
CVEs tagged “cve.org” — page 65 · VulnSea