VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15598 CVEsRSS

CVE-2026-96611Medium· 6.9
5d ago

FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c

FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds checking, allowing values exceeding INT_…

▾ SunlitFFmpeg · FFmpegEPSS 0.11%via NVD
CVE-2026-73586Medium· 6.4
5d ago

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerabilit…

▾ Sunlitdell · policy_manager_for_secure_connect_gatewayEPSS 0.11%via NVD
CVE-2026-73587Medium· 6.8
5d ago

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability

Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerabil…

▾ Sunlitdell · policy_manager_for_secure_connect_gatewayEPSS 0.08%via NVD
CVE-2026-63001Medium· 4.8
5d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_manager/lib/media_manager.php inserts a Media Manager type name into raw backend warning HTML without escaping it whe…

▾ Sunlitredaxo · coreEPSS 0.18%via NVD
CVE-2026-88974Medium· 5.4PoC
5d ago

WPGraphQL provides a GraphQL API for WordPress sites

WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjectUpdate.php checks only the collection-level edit_posts capability and the post author, but does not enforce the obje…

▾ Twilightwp-graphql · wp-graphqlEPSS 0.27%via NVD
CVE-2026-63002Medium· 4.8PoC
5d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker wh…

▾ Twilightredaxo · coreEPSS 0.18%via NVD
CVE-2026-63000Medium· 6.4
5d ago

REDAXO is a PHP-based content management system

REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/install/lib/api/api_package_update.php inherits the false default from rex_api_function::requiresCsrfProtection() inste…

▾ Sunlitredaxo · coreEPSS 0.13%via NVD
CVE-2026-96560Critical· 9.8
5d ago

LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data

LightLLM through 1.2.0 contains a remote code execution vulnerability in the KV-transfer worker when started with --pd_trans_mode nccl, which exposes an unauthenticated RPyC control channel that deserializes attacker-supplied data. Attac…

▾ MidnightModelTC · LightLLMEPSS 0.65%via NVD
CVE-2026-96512High· 7.8PoC
5d ago

A flaw was found in sudo

A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER time-based access restrictions with timestamps that omit the trailing 'Z' timezone indicator, the time evaluation relies on the TZ environment variable inherited from…

▾ MidnightRed Hat · sudoEPSS 0.13%via NVD
CVE-2026-86708Critical· 10.0
5d ago

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impers…

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impers…

▾ MidnightZohocorp · ManageEngine Applications ManagerEPSS 1.2%via NVD
CVE-2026-86683High· 8.1
5d ago

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to change the proxy settings.

▾ TwilightZohocorp · ManageEngine Applications ManagerEPSS 0.68%via NVD
CVE-2026-86681High· 7.6
5d ago

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned…

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to a permissions validation issue that allowed low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned…

▾ TwilightZohocorp · ManageEngine Applications ManagerEPSS 0.46%via NVD
CVE-2026-86679High· 7.1
5d ago

ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.

ZohoCorp ManageEngine Applications Manager versions 182000 and below were vulnerable to a permissions validation issue that allowed a low-privileged user to delete service monitors outside their assigned scope.

▾ TwilightZohocorp · ManageEngine Applications ManagerEPSS 0.78%via NVD
CVE-2026-86678High· 8.8
5d ago

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to obtain an administrator’s API key and use it to perform administrator-level actions.

▾ TwilightZohocorp · ManageEngine Applications ManagerEPSS 0.68%via NVD
CVE-2026-86677High· 8.8
5d ago

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.

ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unauthorized SQL commands, potentially gaining administrator access and remote code execution.

▾ TwilightZohocorp · ManageEngine Applications ManagerEPSS 2.0%via NVD
CVE-2026-59167Critical· 10.0PoC
5d ago

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler…

▾ Abyssalsuneditor · suneditorEPSS 0.39%via NVD
CVE-2026-18179Medium· 6.5
5d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions due to improper authorization.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.24%via NVD
CVE-2026-18177High· 7.1
5d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute unauthorized payment actions due to missing authorization checks.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.18%via NVD
CVE-2026-12974High· 7.9
5d ago

A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.

A Security Policy Bypass vulnerability exists in Forcepoint Security Engine (NGFW). This issue affects Forcepoint Security Engine (NGFW): from 7.1.0 through 7.1.13, from 7.3.0 through 7.3.1, 7.3.3, from 7.4.0 through 7.4.1, and 7.5.0.

▾ TwilightForcepoint · Forcepoint Security Engine (NGFW)EPSS 0.29%via NVD
CVE-2026-95676High· 7.4
5d ago

A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions

A missing/improper authentication vulnerability in the WatchGuard AuthPoint Gateway's LDAP Sync first-factor authentication allows a remote attacker to bypass single-factor password verification under non-default operating conditions. Ad…

▾ TwilightWatchGuard · AuthPoint Authentication GatewayEPSS 0.50%via NVD
CVE-2026-86247High· 7.4
5d ago

Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, f…

Race condition within a thread vulnerability in Apache Tomcat Native allowed client certificate verification requirements to be down-graded for some configurations. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, f…

▾ TwilightApache Software Foundation · Apache Tomcat NativeEPSS 0.18%via NVD
CVE-2026-86246Critical· 9.1
5d ago

Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX.…

Initialization of a resource with an insecure default vulnerability in Apache Tomcat Native enabled insecure options by default including ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX.…

▾ MidnightApache Software Foundation · Apache Tomcat NativeEPSS 0.28%via NVD
CVE-2026-86243High· 7.5
5d ago

Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8

Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. E…

▾ TwilightApache Software Foundation · Apache Tomcat NativeEPSS 0.40%via NVD
CVE-2026-76979High· 7.7
5d ago

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to an XML Injection vulnerability in the Rule Tracking Compare Policies feature.

▾ TwilightZohocorp · ManageEngine OpManagerEPSS 1.1%via NVD
CVE-2026-76978High· 8.8
5d ago

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Command Injection vulnerability in the Diagnose Settings feature.

▾ TwilightZohocorp · ManageEngine OpManagerEPSS 3.7%via NVD
CVE-2026-75825High· 8.8
5d ago

ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.

ZohoCorp ManageEngine OpManager versions 12.8.710 and below with the Application Manager Plugin enabled were vulnerable to an Authentication Bypass vulnerability.

▾ TwilightZohocorp · ManageEngine OpManagerEPSS 1.1%via NVD
CVE-2026-19599Critical· 9.9
5d ago

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

▾ MidnightZohocorp · ManageEngine OpManagerEPSS 2.9%via NVD
CVE-2026-77112Medium· 6.5
5d ago

Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc

Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server Side Request Forgery. This issue affects Weoll: before 3.2.45.44.

▾ SunlitGlobal IT Informatics Technology Services Inc. · WeollEPSS 0.21%via NVD
CVE-2026-76980High· 7.4
5d ago

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.

ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.709 and below were vulnerable to a Data Exposure vulnerability in the Firewall Analyzer syslog collector.

▾ TwilightZohocorp · ManageEngine OpManagerEPSS 0.39%via NVD
CVE-2026-84091Medium· 5.3PoC
5d ago

The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to ma…

The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a payment notification is genuine before marking the corresponding order as paid, allowing unauthenticated users to ma…

▾ TwilightEPSS 0.18%via NVD
CVEs tagged “cve.org” — page 68 · VulnSea