VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15636 CVEsRSS

CVE-2026-95927High· 7.3PoC
5d ago

A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0

A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads …

▾ MidnightSourceCodester · Online Reviewer Management SystemEPSS 0.27%via NVD
CVE-2026-95925High· 7.3PoC
5d ago

A vulnerability was found in SourceCodester Online Reviewer Management System 1.0

A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the a…

▾ MidnightSourceCodester · Online Reviewer Management SystemEPSS 0.27%via NVD
CVE-2026-96272High· 7.5PoC
5d ago

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-bas…

▾ MidnightMacWarrior · clipbucket-v5EPSS 0.32%via NVD
CVE-2026-96271High· 7.1
5d ago

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users

Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to …

▾ Twilightphotoview · photoviewEPSS 0.23%via NVD
CVE-2026-95897Medium· 5.5PoC
5d ago

A security vulnerability has been detected in Dask up to 2026.8.0

A security vulnerability has been detected in Dask up to 2026.8.0. This affects the function from_npy_stack of the file dask/array/core.py of the component Loader. Such manipulation leads to deserialization. The attack can be launched re…

▾ TwilightRed Hat · DaskEPSS 0.19%via NVD
CVE-2026-96273Medium· 5.5
5d ago

Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked

Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB.createUnregisteredOption(), causing an ArrayIndexOutOfBoundsException that leaves domain objects permanently locked. Attackers can craft a malicious program database f…

▾ SunlitNationalSecurityAgency · ghidraEPSS 0.12%via NVD
CVE-2026-95924High· 7.3PoC
5d ago

A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0

A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument di…

▾ MidnightSourceCodester · Online Reviewer Management SystemEPSS 0.26%via NVD
CVE-2026-95829Medium· 6.3
5d ago

A vulnerability was identified in TDuckCloud tduck-platform up to 5.3

A vulnerability was identified in TDuckCloud tduck-platform up to 5.3. This vulnerability affects the function PaginationInnerInterceptor.concatOrderBy of the file tduck-api/src/main/java/com/tduck/cloud/api/config/MybatisPlusConfig.java…

▾ SunlitTDuckCloud · tduck-platformEPSS 0.19%via NVD
CVE-2026-92930Medium· 6.2
5d ago

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 uses an administrator password-reset unlock-code design that lacks a per-device secret or other server-side cryptographic material. An attacker with physical-console access and…

▾ SunlitOpenEye · Apex Network Video Recorder (NVR)EPSS 0.16%via NVD
CVE-2026-92929Medium· 5.3
5d ago

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 trusts an X-Forwarded-For header supplied by an arbitrary client when determining the request source address. An unauthenticated remote attacker can spoof a loopback address to…

▾ SunlitOpenEye · Apex Network Video Recorder (NVR)EPSS 0.36%via NVD
CVE-2026-95830Medium· 6.3PoC
5d ago

A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0

A security flaw has been discovered in theRealSain Pixtream up to 866afd4f0cea812b918780fb74b67dccf8c4d6a0. This issue affects some unknown processing of the file /post_upload.php. The manipulation of the argument media results in unrest…

▾ TwilighttheRealSain · PixtreamEPSS 0.20%via NVD
CVE-2026-94367High· 7.2
5d ago

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command…

▾ TwilightOpenEye · Apex Network Video Recorder (NVR)EPSS 1.0%via NVD
CVE-2026-92928Medium· 6.5
5d ago

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the accoun…

▾ SunlitOpenEye · Apex Network Video Recorder (NVR)EPSS 0.21%via NVD
CVE-2026-95868Medium· 6.3PoC
5d ago

A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the component Search …

▾ TwilightAdithyaYelloju · Restaurant-Management-SystemEPSS 0.24%via NVD
CVE-2026-95833Medium· 6.3PoC
5d ago

A weakness has been identified in itsourcecode Leave Management System 1.0

A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated r…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.20%via NVD
CVE-2026-77285Low· 2.4⚖ disputed
5d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runn…

▾ Sunlitopenbao · openbaoEPSS 0.13%via NVD
CVE-2026-63132Critical· 9.2
5d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthentic…

▾ Midnightopenbao · openbaoEPSS 0.50%via NVD
CVE-2026-63131Medium· 6.0
5d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] f…

▾ Sunlitopenbao · openbaoEPSS 0.35%via NVD
CVE-2026-61685High· 7.5
6d ago

ReactPress is a publishing system for React developers

ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `articl…

▾ Twilightfecommunity · reactpressEPSS 0.53%via NVD
CVE-2026-57576Medium· 6.5
6d ago

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, …

▾ Sunlitplone · plone.app.dexterityEPSS 0.76%via NVD
CVE-2026-18163Critical· 9.8
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

▾ MidnightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.51%via NVD
CVE-2026-18170Medium· 6.5
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.19%via NVD
CVE-2026-18162Critical· 9.8
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

▾ MidnightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.48%via NVD
CVE-2026-18176High· 7.4
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.13%via NVD
CVE-2026-18172High· 7.4
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.20%via NVD
CVE-2026-18173Low· 3.7
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.24%via NVD
CVE-2026-18169Critical· 9.9
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

▾ MidnightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.53%via NVD
CVE-2026-95820Medium· 6.3PoC
6d ago

A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6

A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a man…

▾ Twilightanirbandutta9 · College-Notes-GalleryEPSS 0.35%via NVD
CVE-2026-95828Medium· 4.3PoC
6d ago

A vulnerability was determined in Mstfakts College-Management-System

A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead to session fixiation. It is…

▾ TwilightMstfakts · College-Management-SystemEPSS 0.49%via NVD
CVE-2026-95819High· 7.3PoC
6d ago

A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6

A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument use…

▾ Midnightanirbandutta9 · College-Notes-GalleryEPSS 0.41%via NVD
CVEs tagged “cve.org” — page 75 · VulnSea