VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15655 CVEsRSS

CVE-2026-73369Critical· 10.0
6d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-82013Critical· 9.9
6d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal reso…

▾ Midnightadobe · campaignEPSS 0.82%via NVD
CVE-2026-82009Critical· 9.1
6d ago

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attack…

▾ Midnightadobe · campaignEPSS 0.99%via NVD
CVE-2026-82003High· 8.5
6d ago

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execut…

▾ Twilightadobe · campaignEPSS 0.46%via NVD
CVE-2026-84412Critical· 10.0
6d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-83660Critical· 9.9
6d ago

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

▾ Midnightadobe · campaignEPSS 0.34%via NVD
CVE-2026-89276Critical· 9.9
6d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could expl…

▾ Midnightadobe · campaignEPSS 0.53%via NVD
CVE-2026-86056Medium· 5.5PoC
6d ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the NPPM_SAVESESSION handler in PowerEditor/src/NppBigSwitch.cpp converts lParam to a sessionInfo pointer and dereferences its nbFile, files, and sessionFilePathName…

▾ Twilightnotepad-plus-plus · notepad-plus-plusEPSS 0.16%via NVD
CVE-2026-75703Critical· 10.0
6d ago

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user

Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulne…

▾ Midnightadobe · campaignEPSS 1.2%via NVD
CVE-2026-95657Low· 3.5PoC
6d ago

A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8

A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. Executing a m…

▾ Twilightdgtlmoon · Changedetection.ioEPSS 0.42%via NVD
CVE-2026-85995High· 7.3
6d ago

Notepad++ is a free and open-source source code editor

Notepad++ is a free and open-source source code editor. From 8.9.7 until 8.9.8, the Notepad++ updater and signature verification path can accept a modified GUP.exe file whose embedded certificate metadata remains present even though its …

▾ Twilightnotepad-plus-plus · notepad-plus-plusEPSS 0.12%via NVD
CVE-2026-77270Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths.…

▾ Twilightmcp-atlassian · mcp_atlassianEPSS 0.40%via NVD
CVE-2026-77265Medium· 5.9
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again f…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.26%via NVD
CVE-2026-77244Critical· 10.0
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to …

▾ Midnightsooperset · mcp-atlassianEPSS 0.28%via NVD
CVE-2026-7866Critical· 10.0
6d ago

Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers

Stack-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from …

▾ MidnightRTI · connext_professionalEPSS 0.31%via NVD
CVE-2026-18461Critical· 9.2
6d ago

Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection

Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format String Injection. This issue affects Connext Professional: from 7.5.0 before 7.7.0.1, from 7.3.0.10 before 7.3.1.6.

▾ MidnightRTI · connext_professionalEPSS 0.21%via NVD
CVE-2026-8849High· 7.7
6d ago

Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation

Use After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation. This issue affects Connext Professional: from 7.6.0 before 7.7.0.1.

▾ TwilightRTI · connext_professionalEPSS 0.38%via NVD
CVE-2026-11388Medium· 6.9
6d ago

Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation

Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.1.0 before 7.3.1.6.

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-11389Medium· 6.8
6d ago

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Co…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-18458Medium· 6.8
6d ago

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Co…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-18457High· 8.3
6d ago

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6…

▾ TwilightRTI · connext_professionalEPSS 0.26%via NVD
CVE-2026-43641Critical· 9.8PoC
6d ago

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

▾ AbyssalSoftaculous · VirtualizorEPSS 3.0%via NVD
CVE-2026-18460Medium· 6.9
6d ago

Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers

Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.

▾ SunlitRTI · connext_professionalEPSS 0.25%via NVD
CVE-2026-18459High· 8.7
6d ago

Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality

Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*,…

▾ TwilightRTI · connext_professionalEPSS 0.25%via NVD
CVE-2026-83597High· 7.0
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-pr…

▾ Twilightnetdata · netdataEPSS 0.14%via NVD
CVE-2026-18462High· 7.3
6d ago

Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation

Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before…

▾ TwilightRTI · connext_professionalEPSS 0.08%via NVD
CVE-2026-43642High· 8.1
6d ago

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserializat…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserializat…

▾ TwilightSoftaculous · VirtualizorEPSS 0.96%via NVD
CVE-2026-18626Medium· 6.8
6d ago

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 bef…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-77267High· 8.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and us…

▾ Twilightsooperset · mcp-atlassianEPSS 0.34%via NVD
CVE-2026-77252Medium· 6.5
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace administrator-configured allowlists, and caller…

▾ Sunlitmcp-atlassian · mcp_atlassianEPSS 0.30%via NVD
CVEs tagged “cve.org” — page 83 · VulnSea