VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15670 CVEsRSS

CVE-2026-80154Critical· 9.6
6d ago

All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session…

All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session…

▾ MidnightLANTRONIX · SLC8000EPSS 0.63%via NVD
CVE-2026-95655High· 8.1
6d ago

Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages

Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages f…

▾ Twilightaureuserp · aureuserpEPSS 0.49%via NVD
CVE-2026-79913Medium· 6.5
6d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible…

▾ Sunlitcloudreve · cloudreveEPSS 0.40%via NVD
CVE-2026-77633High· 7.1
6d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditiona…

▾ Twilightcloudreve · cloudreveEPSS 0.37%via NVD
CVE-2026-77637Low· 3.8
6d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied to n…

▾ Sunlitcloudreve · cloudreveEPSS 0.33%via NVD
CVE-2026-75608High· 7.7
6d ago

Frigate is an open source network video recorder

Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker/main/rootfs/usr/local/nginx/conf/nginx.conf requires authentication but does not require an administrator role for G…

▾ Twilightblakeblackshear · frigateEPSS 0.51%via NVD
CVE-2026-81879Medium· 5.5PoC
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's ELF PN_XNUM handling was vulnerable because the ELF parser allocated the program-header array using the resolved PN_XNUM count but s…

▾ Twilightradare · radare2EPSS 0.18%via NVD
CVE-2026-94640High· 7.5
6d ago

A flaw was found in rpcbind

A flaw was found in rpcbind. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a large number of unique requests. The rpcbind service records previously unseen RPC (Remote Procedur…

▾ TwilightRed Hat · rpcbindEPSS 0.61%via NVD
CVE-2026-70410High· 8.8
6d ago

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avatica. Plugin instantiation (via AvaticaUtils#instantiatePlugin and other methods) initializes arbitrary classes via unr…

▾ TwilightApache Software Foundation · org.apache.calcite.avatica:avatica-coreEPSS 0.64%via NVD
CVE-2026-81884Low· 2.5PoC
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_IN_CODE parser was vulnerable because the Mach-O LC_DATA_IN_CODE parser trusted dataoff and datasize and allowed a fi…

▾ Twilightradare · radare2EPSS 0.17%via NVD
CVE-2026-77620High· 8.7
6d ago

Vector is a high-performance observability data pipeline

Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decompressed frame back into its decoder without limiting nested compression depth. An unauthenticated remote peer that ca…

▾ Twilightvectordotdev · vectorEPSS 0.52%via NVD
CVE-2026-80149High· 8.6
6d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

▾ TwilightLANTRONIX · SLC8000EPSS 0.58%via NVD
CVE-2026-80155Critical· 10.0
6d ago

Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web managem…

Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain an authentication bypass vulnerability in the web managem…

▾ MidnightLANTRONIX · SLC8000EPSS 1.0%via NVD
CVE-2026-80144Critical· 9.9
6d ago

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute ar…

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute ar…

▾ MidnightLANTRONIX · SLC8000EPSS 1.5%via NVD
CVE-2026-75511Medium· 5.3
6d ago

Novu provides an API for sending notifications through multiple channels

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URLs from subscriber credentials.webhookUrl, channel endpoint endpoint.url, event payload.webhookUrl, and event override…

▾ Sunlitnovuhq · novuEPSS 0.46%via NVD
CVE-2026-95654High· 7.4
6d ago

Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance

Databasement before 1.7.14 validates invitation tokens only when the acceptance page loads, caching the authorization decision without re-checking token validity during acceptance. Attackers with a leaked or forwarded invitation link can…

▾ TwilightDavid-Crty · DatabasementEPSS 0.51%via NVD
CVE-2026-90462Medium· 5.4PoC
6d ago

A flaw was found in SSSD

A flaw was found in SSSD. When configured with the LDAP access provider and `ldap_access_order` including `ppolicy` or `lockout`, a fail-open condition in the LDAP ppolicy access check can occur if a user lookup returns zero results. Thi…

▾ TwilightRed Hat · sssdEPSS 0.21%via NVD
CVE-2026-75607High· 8.1PoC
6d ago

Frigate is an open source network video recorder

Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards attacker-selected message topics to the dispatcher without checking the authenticated user's role because the nginx …

▾ Midnightblakeblackshear · frigateEPSS 0.64%via NVD
CVE-2026-86698Low· 2.3PoC
6d ago

Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the organization's private packages and their documentation tarballs vi…

Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization membership or session has ended to keep reading the organization's private packages and their documentation tarballs vi…

▾ Twilighthexpm · hex.pmEPSS 0.43%via NVD
CVE-2026-75517Medium· 6.5
6d ago

Novu provides an API for sending notifications through multiple channels

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use cases including remove-integration, update-integration, auto-configure-integration, and set-integration-as-primary l…

▾ Sunlitnovuhq · novuEPSS 0.70%via NVD
CVE-2026-95806High· 7.7
6d ago

MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point.  The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences:    - any fil…

MISP ships with PHP's phar stream wrapper registered in both its web entry point and its console entry point.  The phar stream wrapper causes PHP to treat a phar archive as a directory, which has two security consequences:    - any fil…

▾ TwilightMISP · MISPEPSS 0.39%via NVD
CVE-2026-80152Critical· 9.1
6d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticat…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticat…

▾ MidnightLANTRONIX · SLC8000EPSS 1.7%via NVD
CVE-2026-95805Medium· 5.3
6d ago

A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabl…

A typo in the MISP ACLComponent access control configuration caused the ACL rule for the previewEventAttributes action to reference the permission string 'theming_enabled*' (with a trailing asterisk) instead of the correct 'theming_enabl…

▾ SunlitMISP · MISPEPSS 0.41%via NVD
CVE-2026-86805Medium· 6.3
6d ago

A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges

A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/se…

▾ SunlitThe GNU C Library · glibcEPSS 0.12%via NVD
CVE-2026-92706Low· 3.4
6d ago

Dark Reader is an accessibility browser extension that makes web pages colors dark

Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can cause the browser extension's image inversion pipeline to request an unauthenticated icon-like bitmap from a locally runn…

▾ Sunlitdarkreader · darkreaderEPSS 0.17%via NVD
CVE-2026-75510Medium· 5.1PoC
6d ago

Novu provides an API for sending notifications through multiple channels

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and…

▾ Twilightnovuhq · novuEPSS 0.35%via NVD
CVE-2026-88010Medium· 6.3
6d ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the submitted password and stored secret. Concur…

▾ Sunlittraefik · traefikEPSS 0.69%via NVD
CVE-2026-79312Medium· 6.8
6d ago

webpy web.py 0.76 is vulnerable to Session Fixation

webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the request cookie and loads that session from the store, and _save() writes back under the same session_id; no rotation af…

▾ SunlitRed HatEPSS 0.29%via NVD
CVE-2026-56681High· 7.3PoC
6d ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper trust the client-supplied X-9r-Real-Ip header in src/dashboardGuard.js when i…

▾ Midnight9router · 9routerEPSS 0.97%via NVD
CVE-2026-24239High· 7.8
6d ago

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, information disclosure,…

▾ Twilightnvidia · nemo_speechEPSS 0.35%via NVD
CVEs tagged “cve.org” — page 86 · VulnSea