VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15636 CVEsRSS

CVE-2026-18066High· 7.9
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information and trigger unauthorized actions due to server-side request forgery.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.10%via NVD
CVE-2026-18124Medium· 6.5
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to obtain sensitive information due to insufficiently protected credentials.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.10%via NVD
CVE-2026-18123High· 7.6
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.19%via NVD
CVE-2026-18074High· 8.2
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper authentication and missing authorization.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.41%via NVD
CVE-2026-19202Critical· 9.1
6d ago

A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences

A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cached and reused across different audiences. If an application uses the SDK to authenticate to two or more different audi…

▾ MidnightGoogle · mcp-toolbox-sdk-pythonEPSS 0.25%via NVD
CVE-2026-18132Medium· 6.5
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to perform unauthorized payment mutation actions due to missing authorization.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.21%via NVD
CVE-2026-18131High· 8.2
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary JavaScript in an authenticated user's browser due to improper neutralization of HTML input.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.25%via NVD
CVE-2026-18133Medium· 5.4
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to modify server files due to path traversal.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.30%via NVD
CVE-2026-94450High· 7.5
6d ago

Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram

Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only s…

▾ TwilightAWS · s2n-quicEPSS 1.9%via NVD
CVE-2026-95814High· 8.1
6d ago

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization …

Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization …

▾ Twilightdani-garcia · vaultwardenEPSS 0.43%via NVD
CVE-2026-95813Medium· 6.1
6d ago

e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation controls to attacker-controlled o…

e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and controller navigation links, allowing attackers to redirect pagination and navigation controls to attacker-controlled o…

▾ Sunlite621ng · e621ngEPSS 0.34%via NVD
CVE-2026-95812Medium· 6.1PoC
6d ago

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters

ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper function that fails to sanitize cat, sort, and time query parameters. Attackers can craft malicious requests with injected …

▾ TwilightMacWarrior · clipbucket-v5EPSS 0.35%via NVD
CVE-2026-95815Medium· 6.3
6d ago

OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data

OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them in forged de…

▾ SunlitOpenClaw · OpenClaw iOSEPSS 0.16%via NVD
CVE-2026-91018High· 8.8
6d ago

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or allow code execution on the victim system.

▾ TwilightlwIP · lwIP APIEPSS 0.24%via NVD
CVE-2026-77987Critical· 9.3
6d ago

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server

A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. The notebook viewer validated the scheme and host of a user-supplied URL but did not validate the port, allowing reques…

▾ MidnightGitHub · Enterprise ServerEPSS 0.89%via NVD
CVE-2026-75101Medium· 6.0
6d ago

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization

An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of the instance to read the raw diff or patch of pull requests in private repositories without authorization. Access tok…

▾ SunlitGitHub · Enterprise ServerEPSS 0.45%via NVD
CVE-2026-67615High· 8.8PoC
6d ago

openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/…

openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/…

▾ MidnightApereo Foundation · openEQUELLAEPSS 0.54%via NVD
CVE-2026-96260Medium· 6.5
6d ago

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory…

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust server memory…

▾ SunlitMattermost · MattermostEPSS 0.41%via NVD
CVE-2026-96259Medium· 5.5
6d ago

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests …

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server issue requests …

▾ SunlitMattermost · MattermostEPSS 0.26%via NVD
CVE-2026-88020Medium· 6.1
6d ago

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

▾ SunlitAutonomy Logic · OpenPLC RuntimeEPSS 0.27%via NVD
CVE-2026-77912High· 7.4
6d ago

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…

▾ TwilightGitHub · Enterprise ServerEPSS 0.45%via NVD
CVE-2026-96269High· 7.5
6d ago

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user s…

▾ TwilightGNU · EmacsEPSS 0.15%via NVD
CVE-2026-62364Low· 2.3
6d ago

wlc is a Weblate command-line client using Weblate's REST API

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_…

▾ SunlitWeblateOrg · wlcEPSS 0.08%via NVD
CVE-2026-76910Medium· 5.3PoC
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the s…

▾ TwilightUnleash · unleashEPSS 0.30%via NVD
CVE-2026-76909Low· 2.1
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTit…

▾ SunlitUnleash · unleashEPSS 0.27%via NVD
CVE-2026-77426High· 7.1
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting …

▾ TwilightUnleash · unleashEPSS 0.48%via NVD
CVE-2026-77425Medium· 4.3PoC
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUp…

▾ TwilightUnleash · unleashEPSS 0.23%via NVD
CVE-2026-63627Medium· 6.9
6d ago

mppx is a TypeScript interface for machine payments protocol

mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject trailing bytes. A client could …

▾ Sunlitwevm · mppxEPSS 0.38%via NVD
CVE-2026-76710High· 7.5
6d ago

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially c…

▾ TwilightHewlett Packard Enterprise (HPE) · ALEEPSS 0.54%via NVD
CVE-2026-76708Critical· 9.8
6d ago

A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts

A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacke…

▾ Midnightarubanetworks · analytics_and_location_engineEPSS 0.59%via NVD
CVEs tagged “cve.org” — page 77 · VulnSea