VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15659 CVEsRSS

CVE-2026-77251High· 8.3PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence se…

▾ Midnightsooperset · mcp-atlassianEPSS 0.25%via NVD
CVE-2026-77250Medium· 6.1PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian direc…

▾ Twilightsooperset · mcp-atlassianEPSS 0.12%via NVD
CVE-2026-43643High· 7.5
6d ago

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafte…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafte…

▾ TwilightSoftaculous · VirtualizorEPSS 0.62%via NVD
CVE-2026-83603High· 8.4PoC
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata…

▾ Midnightnetdata · netdataEPSS 0.35%via NVD
CVE-2026-83601Medium· 6.5PoC
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot in src/plugins.d/pluginsd_internals.h witho…

▾ Twilightnetdata · netdataEPSS 0.37%via NVD
CVE-2026-83600Medium· 6.5PoC
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. Th…

▾ Twilightnetdata · netdataEPSS 0.55%via NVD
CVE-2026-83598High· 7.8
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell…

▾ Twilightnetdata · netdataEPSS 0.16%via NVD
CVE-2026-86059Critical· 9.6PoC
6d ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucke…

▾ AbyssalDokploy · dokployEPSS 0.49%via NVD
CVE-2026-85709Medium· 5.3PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and l…

▾ TwilightHKUDS · LightRAGEPSS 0.39%via NVD
CVE-2026-94456Critical· 9.1
6d ago

Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source

Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE ver…

▾ MidnightGitroomHQ · postiz-appEPSS 0.52%via NVD
CVE-2026-94455High· 7.1
6d ago

An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session

An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on th…

▾ TwilightGitroomHQ · postiz-appEPSS 0.26%via NVD
CVE-2026-85725Medium· 5.9PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after th…

▾ TwilightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-85740High· 7.1
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying…

▾ TwilightHKUDS · LightRAGEPSS 0.22%via NVD
CVE-2026-85734Critical· 9.1
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication atte…

▾ MidnightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-86062Medium· 6.1PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an H…

▾ TwilightHKUDS · LightRAGEPSS 0.25%via NVD
CVE-2026-83803High· 7.7
6d ago

Sentry is an error tracking and performance monitoring tool

Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field while importing a user-supplied relocation archive.…

▾ Twilightgetsentry · sentryEPSS 0.60%via NVD
CVE-2026-76805Medium· 5.3
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that all…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.41%via NVD
CVE-2026-76804Medium· 5.5
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. …

▾ Sunlitprojectdiscovery · nucleiEPSS 0.17%via NVD
CVE-2026-76803Medium· 5.3
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN opti…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.40%via NVD
CVE-2026-95818Low· 3.6⚖ disputed
6d ago

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_R…

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_R…

▾ SunlitThe GNU C Library · glibcEPSS 0.13%via NVD
CVE-2026-76802Medium· 4.7⚖ disputed
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzz…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.18%via NVD
CVE-2026-87902High· 8.1CISA KEVPoC
6d ago

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are…

▾ Abyssalwordpress · wordpressEPSS 18%via NVD
CVE-2026-84301Medium· 6.3PoC
6d ago

FastGPT is an open-source LLM platform for building AI applications on a knowledge base

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates a hostname with isInternalAddress() before a l…

▾ Twilightlabring · FastGPTEPSS 0.29%via NVD
CVE-2026-83602Medium· 6.5
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled b…

▾ Sunlitnetdata · netdataEPSS 0.51%via NVD
CVE-2026-83599High· 7.5
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompre…

▾ Twilightnetdata · netdataEPSS 0.74%via NVD
CVE-2026-13087High· 8.8PoC
6d ago

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write lis…

▾ MidnightRed Hat · kernelEPSS 0.47%via NVD
CVE-2026-56682Medium· 5.3PoC
6d ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, …

▾ Twilightdecolua · 9routerEPSS 0.47%via NVD
CVE-2026-81881Low· 3.3
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata sect…

▾ Sunlitradare · radare2EPSS 0.13%via NVD
CVE-2026-81878Medium· 5.5PoC
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without reje…

▾ Twilightradare · radare2EPSS 0.20%via NVD
CVE-2026-81886Medium· 5.5
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run …

▾ Sunlitradare · radare2EPSS 0.12%via NVD
CVEs tagged “cve.org” — page 84 · VulnSea