VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15670 CVEsRSS

CVE-2026-93088Critical· 9.8PoC
6d ago

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …

SGLang's multimodal generation runtime is vulnerable to unauthenticated arbitrary code execution because the disaggregated-diffusion orchestrator's DiffusionServer binds an unauthenticated ZeroMQ ROUTER socket to a network interface and …

▾ AbyssalSGLang · SGLangEPSS 0.73%via NVD
CVE-2026-95701Medium· 5.1
6d ago

In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image

In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path component when checking for the existence of an organization logo image. The original code called file_exists() with a …

▾ SunlitMISP · MISPEPSS 0.76%via NVD
CVE-2026-79313Critical· 9.8⚖ disputed
6d ago

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration

webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relies on periodic cleanup to expire sessions instead of checking the last-access time when a session is loaded. As a result, an exp…

▾ MidnightRed HatEPSS 0.38%via NVD
CVE-2026-95703Medium· 5.1
6d ago

In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP fi…

In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem probes (file_exists, MIME type detection, EXIF reading) before verifying that the value corresponded to a genuine PHP fi…

▾ SunlitMISP · MISPEPSS 0.51%via NVD
CVE-2026-89407High· 7.5PoC
6d ago

NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT…

NumberInput.looksLikeValidNumber() in FasterXML jackson-core pre-validates "stringified numbers" with two regular expressions: PATTERN_FLOAT ([+-]?[0-9]*[\.]?[0-9]+([eE][+-]?[0-9]+)?), present since 2.17.0, and PATTERN_FLOAT_TRAILING_DOT…

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-coreEPSS 0.63%via NVD
CVE-2026-95754Medium· 6.9
6d ago

In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list

In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentication) verification branch did not include the User.disabled column in its SELECT fields list. The query selected only…

▾ SunlitMISP · MISPEPSS 0.54%via NVD
CVE-2026-94570Medium· 5.9
6d ago

SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socke…

SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decode worker, which enables an unauthenticated remote attacker with network reachability to the Decode control PULL socke…

▾ SunlitSGLang · SGLangEPSS 0.47%via NVD
CVE-2026-19915High· 7.3
6d ago

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0

A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

▾ TwilightHP Inc · HP Support AssistantEPSS 0.11%via NVD
CVE-2026-95396Medium· 4.3PoC
6d ago

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file HospitalController.java of the component Public Search Handlers. The manipulation of the ar…

▾ Twilightsfturing · hosp_orderEPSS 0.47%via NVD
CVE-2026-95665Medium· 5.1
6d ago

MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form

MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. The view template app/View/Events/ajax/eventRestSearchExportConfirmationForm.ctp renders a URL-supplied event ID list i…

▾ SunlitMISP · MISPEPSS 0.54%via NVD
CVE-2026-95667Medium· 6.9
6d ago

The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output

The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_install.log and a named pipe (FIFO) at /var/log/misp_install.log.pipe to capture all installer output. The log captures …

▾ SunlitMISP · MISPEPSS 0.18%via NVD
CVE-2026-95671Medium· 5.3
6d ago

In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST

In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element capture only when the HTTP request method was POST. However, the underlying CRUDComponent::add() method persists data on…

▾ SunlitMISP · MISPEPSS 0.37%via NVD
CVE-2026-95674Medium· 5.3
6d ago

In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list of enabled modules to find a match

In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list of enabled modules to find a match. If the specified module was not present in the enabled modules list, the code sil…

▾ SunlitMISP · MISPEPSS 0.41%via NVD
CVE-2026-95675Critical· 9.8PoC
6d ago

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…

D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web manageme…

▾ AbyssalD-LINK · DAP-1360EPSS 2.1%via NVD
CVE-2026-95499High· 7.3
6d ago

A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0

A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upl…

▾ TwilightJosephChuks · php-file-manager-with-code-editorEPSS 0.47%via NVD
CVE-2026-93341Medium· 4.3
6d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher to create refund requests a…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refund AJAX action that allows authenticated attackers with subscriber-level access or higher to create refund requests a…

▾ SunlitWebWizards · MarketKingEPSS 0.33%via NVD
CVE-2026-95679Medium· 6.9
6d ago

MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests

MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build() library contains a logic error in its readFile guard condition (readFile && http || https), where PHP operator pre…

▾ SunlitMISP · MISPEPSS 0.60%via NVD
CVE-2026-93342Medium· 5.4
6d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher to duplicate any vend…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate_product AJAX action that allows authenticated attackers with subscriber-level access or higher to duplicate any vend…

▾ SunlitWebWizards · MarketKingEPSS 0.32%via NVD
CVE-2026-12718Critical· 9.8
6d ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The…

▾ MidnightKarel Electronic Industry and Trade Inc. · KarelIPSEPSS 0.32%via NVD
CVE-2026-95682Medium· 4.8
6d ago

MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen

MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org…

▾ SunlitMISP · MISPEPSS 0.42%via NVD
CVE-2026-95666Medium· 4.3
6d ago

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive dat…

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive dat…

▾ SunlitMattermost · MattermostEPSS 0.36%via NVD
CVE-2026-93343Medium· 6.5
6d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the comp…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the comp…

▾ SunlitWebWizards · MarketKingEPSS 0.40%via NVD
CVE-2026-95271High· 7.3PoC
6d ago

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation lead…

▾ Midnightdgtlmoon · changedetection.ioEPSS 0.65%via NVD
CVE-2026-95272Low· 3.7PoC
6d ago

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument fil…

▾ Twilightdgtlmoon · changedetection.ioEPSS 0.67%via NVD
CVE-2026-95658Medium· 6.9
6d ago

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation fo…

▾ SunlitMISP · MISPEPSS 0.27%via NVD
CVE-2026-95273Medium· 4.3PoC
6d ago

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argume…

▾ Twilightdgtlmoon · changedetection.ioEPSS 0.52%via NVD
CVE-2026-95659Medium· 4.8
6d ago

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-theme…

▾ SunlitMISP · MISPEPSS 0.39%via NVD
CVE-2026-75791High· 8.6
6d ago

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

▾ TwilightZohocorp · ManageEngine ADSelfService PlusEPSS 1.7%via NVD
CVE-2026-95661Medium· 5.1
6d ago

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal insid…

▾ SunlitMISP · MISPEPSS 0.44%via NVD
CVE-2026-95619High· 7.7
6d ago

A flaw was found in libstdc++

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corrup…

▾ TwilightRed Hat · gcc-mainEPSS 0.36%via NVD
CVEs tagged “cve.org” — page 88 · VulnSea