VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15599 CVEsRSS

CVE-2026-96513High· 7.3PoC
5d ago

A security flaw has been discovered in Neethuharii CafeManagement

A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the file AddProductCode.php. The manipulation of the argument image results in unrestricted upload. The attack may be perfor…

▾ MidnightNeethuharii · CafeManagementEPSS 0.28%via NVD
CVE-2026-95848Critical· 9.3PoC
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class cannot be loaded, Server.initializeAuthenticator and Server.initializeAuthorizatorPolicy treat the failure as though no cu…

▾ Abyssalmoquette-io · moquetteEPSS 0.51%via NVD
CVE-2026-95847High· 8.8PoC
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as queue_ plus the client ID and its metadata-map name as queue_ plus the client ID plus _meta. A durable session whose c…

▾ Midnightmoquette-io · moquetteEPSS 0.41%via NVD
CVE-2026-95846High· 7.5PoC
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will message without applying the canWrite authorization and reserved-topic checks used for a normal PUBLISH. A client can conf…

▾ Midnightmoquette · moquetteEPSS 0.27%via NVD
CVE-2026-95845High· 7.5
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending per-session message queues. When a fast publisher sends messages to a slow subscriber whose in-flight window is full, q…

▾ Twilightmoquette · moquetteEPSS 0.36%via NVD
CVE-2026-95844High· 8.7
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic filters before processing them through recursive CTrie insertion and matching operations. A remote client can publish…

▾ Twilightmoquette-io · moquetteEPSS 0.29%via NVD
CVE-2026-95843High· 7.5PoC
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter through SharedSubscriptionUtils.extractShareName before validating the complete $share/{shareName}/{topicFilter} struct…

▾ Midnightmoquette · moquetteEPSS 0.43%via NVD
CVE-2026-95842High· 7.5PoC
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and SessionEventLoopGroup does not restart a terminated loop. An MQTT command that raises an uncaught exception can term…

▾ Midnightmoquette · moquetteEPSS 0.43%via NVD
CVE-2026-93349High· 8.8PoC
5d ago

Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the use…

Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows an attacker who supplies a crafted Data Package descriptor to execute arbitrary operating system commands as the use…

▾ Midnightfrictionlessdata · frictionless-pyEPSS 2.0%via NVD
CVE-2026-88832High· 7.3
5d ago

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.

▾ TwilightRed Hat · busybox-mainEPSS 0.13%via NVD
CVE-2026-88830High· 7.5
5d ago

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow when processing a crafted ClientKeyExchange message.

▾ TwilightRed Hat · busyboxEPSS 0.35%via NVD
CVE-2026-96651Medium· 6.5
5d ago

Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'

Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any fi…

▾ SunlitPlex · Media ServerEPSS 0.41%via NVD
CVE-2026-6668High· 7.5
5d ago

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service

Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growt…

▾ TwilightRed Hat · PgBouncerEPSS 0.40%via NVD
CVE-2026-19888High· 7.5
5d ago

Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process

Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to crash the process. A malformed message can make the parser report success while…

▾ TwilightRed Hat · PgBouncerEPSS 0.39%via NVD
CVE-2026-96656High· 7.2
5d ago

Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load

Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so f…

▾ TwilightPlex · Media ServerEPSS 0.34%via NVD
CVE-2026-96654Medium· 6.5
5d ago

Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.

Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters.

▾ SunlitPlex · Media ServerEPSS 0.22%via NVD
CVE-2026-6669Medium· 5.9
5d ago

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in …

Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in PgBouncer through 1.25.2 allows a malicious or compromised PostgreSQL backend to cause uncontrolled CPU consumption in …

▾ SunlitRed Hat · PgBouncerEPSS 0.31%via NVD
CVE-2026-96652Medium· 4.3
5d ago

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.

▾ SunlitPlex · Media ServerEPSS 0.20%via NVD
CVE-2026-96655Medium· 4.3
5d ago

Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.

Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter.

▾ SunlitPlex · Media ServerEPSS 0.20%via NVD
CVE-2025-63564Critical· 9.8
5d ago

SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

▾ MidnightEPSS 0.51%via NVD
CVE-2026-96675Low· 3.3⚖ disputed
5d ago

alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access

alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings…

▾ SunlitALSA Project · alsa-libEPSS 0.11%via NVD
CVE-2026-85724Critical· 9.6PoC
5d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, AuthorizationsCollector.canDoOperation substitutes client ID and username values directly into rules containing %c or %u and then t…

▾ Abyssalmoquette · moquetteEPSS 0.27%via NVD
CVE-2026-96674Medium· 4.4
5d ago

alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks

alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculation…

▾ SunlitALSA Project · alsa-libEPSS 0.11%via NVD
CVE-2026-96673High· 7.5PoC
5d ago

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in th…

▾ MidnightPhotoview · PhotoviewEPSS 0.42%via NVD
CVE-2026-96672Medium· 6.4
5d ago

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call()

Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values reference whitelisted methods before passing them to frappe.call(). Accounts Managers can supply arbitrary dotted Python pa…

▾ SunlitFrappe · ERPNextEPSS 0.22%via NVD
CVE-2026-93769High· 7.2
5d ago

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a …

HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegated, non-system-administrator Manage Users permission (admin_manage_users) to inject persistent HTML/JavaScript into a …

▾ TwilightHumhub · HumhubEPSS 0.28%via NVD
CVE-2026-79310High· 8.5
5d ago

webpy web.py 0.76 is vulnerable to server-side template injection (SSTI)

webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlled template code that built-in security checks are designed to reject. When an application preco…

▾ TwilightRed HatEPSS 0.72%via NVD
CVE-2026-79306Medium· 6.5
5d ago

CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint

CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply absolute or otherw…

▾ SunlitEPSS 0.48%via NVD
CVE-2026-79304Medium· 6.5
5d ago

CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint

CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller endpoint. An authenticated remote attacker with ownership of any configured domain can supply an arbitrary absolute or…

▾ SunlitEPSS 0.54%via NVD
CVE-2026-6327Medium· 4.3
5d ago

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

▾ SunlitIBM · ConcertEPSS 0.17%via NVD
CVEs tagged “cve.org” — page 66 · VulnSea