VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15658 CVEsRSS

CVE-2026-77399Medium· 6.5
6d ago

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expan…

▾ Sunlitcollective · icalendarEPSS 0.31%via NVD
CVE-2026-63386Medium· 5.3PoC
6d ago

js-toml is a TOML parser for JavaScript

js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recursive parser at src/load/parser.ts or the interpreter at src/load/interpreter.ts, so deeply nested arrays, deeply neste…

▾ Twilightsunnyadn · js-tomlEPSS 0.36%via NVD
CVE-2026-57149Critical· 9.9
6d ago

plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone

plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic por…

▾ Midnightplone · plone.app.portletsEPSS 0.64%via NVD
CVE-2026-77257High· 8.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to local file operations without restric…

▾ Twilightsooperset · mcp-atlassianEPSS 0.40%via NVD
CVE-2026-77254Critical· 9.1PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use global…

▾ Abyssalmcp-atlassian · mcp_atlassianEPSS 0.61%via NVD
CVE-2026-77262High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does not apply the path restriction added for…

▾ Midnightsooperset · mcp-atlassianEPSS 0.54%via NVD
CVE-2026-95831High· 7.8
6d ago

Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file

Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts t…

▾ TwilightEPSS 0.12%via NVD
CVE-2026-77255High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementa…

▾ Midnightsooperset · mcp-atlassianEPSS 0.40%via NVD
CVE-2026-77269Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not constrain source paths used by attachmen…

▾ Twilightsooperset · mcp-atlassianEPSS 0.38%via NVD
CVE-2026-77266Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment accepts absolute paths and traversal sequences without constraining the resolved path to the server w…

▾ Twilightmcp-atlassian · mcp_atlassianEPSS 0.47%via NVD
CVE-2026-76192Medium· 5.5
6d ago

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service conditi…

▾ SunlitAdobe · InDesign DesktopEPSS 0.18%via NVD
CVE-2026-84396Medium· 5.5
6d ago

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service

InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service conditi…

▾ SunlitAdobe · InDesign DesktopEPSS 0.14%via NVD
CVE-2026-77544High· 7.5
6d ago

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-77272Medium· 5.4
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth error query parameter is passed to CallbackHandler._send_response in oauth_setup.py and interpolated into an …

▾ Sunlitmcp-atlassian · mcp_atlassianEPSS 0.24%via NVD
CVE-2026-77558High· 7.5
6d ago

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-77556High· 7.5
6d ago

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Out-of-bounds Read vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-77247High· 8.3PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence upload tools interpret caller-controlled path arguments on the MCP server and open those files befo…

▾ Midnightsooperset · mcp-atlassianEPSS 0.45%via NVD
CVE-2026-77555High· 7.5
6d ago

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-37604Critical· 9.8
6d ago

pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trus…

pH7Software pH7Builder (pH7 Social Dating CMS) through 18.2.0 resolves the client IP address in _protected/framework/Ip/Ip.class.php from the HTTP_CLIENT_IP and HTTP_X_FORWARDED_FOR headers without verifying the request comes from a trus…

▾ MidnightEPSS 0.66%via NVD
CVE-2026-77268Medium· 5.5
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the OAuth fallback token directory and JSON file are created without explicit owner-only modes. Local users or processe…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.11%via NVD
CVE-2026-77259High· 7.7PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment opens a caller-selected server-local file without checking that the resolved path remains …

▾ Midnightsooperset · mcp-atlassianEPSS 0.39%via NVD
CVE-2026-37603Medium· 6.5PoC
6d ago

Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0

Improper Restriction of Excessive Authentication Attempts in the administration login of pH7Software pH7Builder (pH7 Social Dating CMS) through 19.2.0. The CAPTCHA escalation flag is stored in the PHP session as captcha_admin_enabled and…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-95861High· 7.5
6d ago

A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-77249Medium· 5.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, JiraUserMixin._lookup_user_by_permissions uses the module-level requests.get function instead of the fetcher's protecte…

▾ Sunlitmcp-atlassian · mcp-atlassianEPSS 0.33%via NVD
CVE-2026-95862High· 7.5
6d ago

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi gateway devices to execute a Denial of Service (DoS) attack on the device.

▾ TwilightUbiquiti Inc · Dream MachinesEPSS 0.46%via NVD
CVE-2026-77256Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the plaintext OAuth fallback file containing refresh and access tokens is written with permissions inherited from the p…

▾ Twilightmcp-atlassian · mcp_atlassianEPSS 0.41%via NVD
CVE-2026-77253High· 7.1PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira and Confluence attachment upload tools accept arbitrary local filesystem paths and send the selected bytes to Atla…

▾ Midnightmcp-atlassian · mcp_atlassianEPSS 0.40%via NVD
CVE-2026-89277Medium· 5.5
6d ago

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-s…

▾ SunlitAdobe · Content Credentials Rust SDKEPSS 0.25%via NVD
CVE-2026-77248High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the streamable HTTP transport accepts requests without a user identity and falls back to operator credentials, while up…

▾ Midnightmcp-atlassian · mcp_atlassianEPSS 0.42%via NVD
CVE-2026-19480High· 7.5
6d ago

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write acces…

▾ TwilightAdobe · Content Credentials Rust SDKEPSS 0.65%via NVD
CVEs tagged “cve.org” — page 80 · VulnSea