VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15670 CVEsRSS

CVE-2026-65111High· 7.8
6d ago

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection

NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and…

▾ Twilightnvidia · nemo_speechEPSS 0.25%via NVD
CVE-2026-24267High· 7.8
6d ago

NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution

NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to …

▾ Twilightnvidia · nemo_speechEPSS 0.35%via NVD
CVE-2026-95683Medium· 5.3
6d ago

In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes

In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrichment logic fetched the report using only the event ID as the lookup condition, without applying the report's own dist…

▾ SunlitMISP · MISPEPSS 0.39%via NVD
CVE-2026-65179High· 8.8
6d ago

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation

NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation. A successful exploit of this vulnerability may lead to code execut…

▾ TwilightNVIDIA · NeMo SpeechEPSS 0.67%via NVD
CVE-2026-65178High· 7.8
6d ago

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters

NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted model_config.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denia…

▾ TwilightNVIDIA · NeMo SpeechEPSS 0.38%via NVD
CVE-2026-65128High· 8.8
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information …

▾ TwilightNVIDIA · Infrastructure ControllerEPSS 0.59%via NVD
CVE-2026-65124Medium· 5.9
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.52%via NVD
CVE-2026-65121High· 8.2
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosur…

▾ TwilightNVIDIA · Infrastructure ControllerEPSS 0.32%via NVD
CVE-2026-65127Medium· 4.1
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive system information due to uncleared debug information. A successful exploit of this vulnerability might lead to infor…

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.15%via NVD
CVE-2026-65126Medium· 5.0
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement of a behavioral workflow. A successful exploit of this vulnerability might lead to data tampering, denial of service, …

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.31%via NVD
CVE-2026-65129Medium· 6.7
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denia…

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.13%via NVD
CVE-2026-65125Medium· 6.6
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges,…

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.61%via NVD
CVE-2026-65113Critical· 9.8
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of…

▾ MidnightNVIDIA · Infrastructure ControllerEPSS 0.61%via NVD
CVE-2026-65130High· 8.0
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and infor…

▾ TwilightNVIDIA · Infrastructure ControllerEPSS 2.1%via NVD
CVE-2026-65115Medium· 6.5
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service.

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.53%via NVD
CVE-2026-65114High· 8.3
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service,…

▾ TwilightNVIDIA · Infrastructure ControllerEPSS 0.41%via NVD
CVE-2026-65118High· 7.5
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denia…

▾ TwilightNVIDIA · Infrastructure ControllerEPSS 0.13%via NVD
CVE-2026-65117Medium· 5.0
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information d…

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.23%via NVD
CVE-2026-65112Medium· 6.5
6d ago

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption

NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

▾ SunlitNVIDIA · Infrastructure ControllerEPSS 0.53%via NVD
CVE-2026-95685Medium· 5.3
6d ago

MISP contains an access control flaw in the EventReports functionality

MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allows modification of suggestion content within an event report, was incorrectly mapped to the wildcard permission ('*')…

▾ SunlitMISP · MISPEPSS 0.35%via NVD
CVE-2026-84388Critical· 9.6PoC
6d ago

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticat…

A improper restriction of rendered ui layers or frames vulnerability in Fortinet FortiPAM Chrome Extension 8.0 all versions, FortiPAM Chrome Extension 7.4 all versions may allow attacker to information disclosure via remote unauthenticat…

▾ AbyssalFortinet · FortiPAM Chrome ExtensionEPSS 0.38%via NVD
CVE-2026-95500High· 7.3
6d ago

A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0

A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/con…

▾ TwilightJosephChuks · php-file-manager-with-code-editorEPSS 0.47%via NVD
CVE-2026-94127Critical· 9.8CISA KEV0dayPoC
6d ago

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE)

When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can lead to remote code execution (RCE). This vulnerability is only present when BIG-IP APM is configured as an OAuth Aut…

▾ Hadalf5 · big-ip_access_policy_managerEPSS 2.2%via NVD
CVE-2026-95693Medium· 5.3
6d ago

In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP uplo…

In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), mime_content_type(), and exif_imagetype() on the supplied path before verifying that the value was a genuine PHP uplo…

▾ SunlitMISP · MISPEPSS 0.51%via NVD
CVE-2026-95501Medium· 4.3PoC
6d ago

A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5

A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the function eval of the file cms/weasel.php of the component Template Engine. The manipulation of the argument $_CMS['si…

▾ Twilightmtrano · APENCMSEPSS 0.31%via NVD
CVE-2026-95697Medium· 5.3
6d ago

MISP contains an authorization flaw in the Organisation model's captureOrg method

MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to true, the method unconditionally overwrites organization metadata fields without verifying that the invoking user hold…

▾ SunlitMISP · MISPEPSS 0.38%via NVD
CVE-2026-93344Medium· 6.5
6d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary ve…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_content AJAX action that allows authenticated attackers with subscriber-level access or higher to access arbitrary ve…

▾ SunlitWebWizards · MarketKingEPSS 0.43%via NVD
CVE-2026-95698Medium· 5.3
6d ago

The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file_exists() on the resulting path

The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organization identifier with a fixed image directory and a file extension, then calls file_exists() on the resulting path. The o…

▾ SunlitMISP · MISPEPSS 0.72%via NVD
CVE-2026-79315Medium· 4.7
6d ago

A reflected cross-site scripting vulnerability exists in x-ui 0.3.2

A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request URI into a client-side template binding expression used for sidebar menu highlighting. Server-side HTML entity escapin…

▾ SunlitEPSS 0.27%via NVD
CVE-2026-79314High· 8.8
6d ago

A horizontal privilege escalation vulnerability exists in x-ui 0.3.2

A horizontal privilege escalation vulnerability exists in x-ui 0.3.2. An authenticated user can modify the inbound proxy configurations of other users, including remark, port, protocol, settings, enabled state, expiry time and traffic qu…

▾ TwilightEPSS 0.30%via NVD
CVEs tagged “cve.org” — page 87 · VulnSea