VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15684 CVEsRSS

CVE-2026-93712High· 7.5
6d ago

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and che…

Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from outside public_dir via relative path segments in the File route handler. The handler joins the request path onto public_dir without collapsing relative segments, and che…

▾ TwilightEPSS 0.55%via NVD
CVE-2026-94490Medium· 4.7
6d ago

A security flaw has been discovered in OctoPrint 1.0.0

A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command API. Performing a manipulation of the argument co…

▾ SunlitEPSS 2.1%via NVD
CVE-2026-94489Medium· 4.3PoC
6d ago

A vulnerability was identified in OctoPrint 1.0.0

A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. Such manipulation of the argument filename lead…

▾ TwilightEPSS 0.52%via NVD
CVE-2026-63374Critical· 9.3
6d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, connect_tcp() and TLSStream.wrap() can validate internationalized host names after the standard library…

▾ Midnightagronholm · anyioEPSS 0.29%via NVD
CVE-2026-94425High· 8.8
1w ago

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150

A vulnerability was found in Moore Threads MTT S80 Driver Package 340.150. The affected element is the function sub_140006F0C in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation results in improper privilege ma…

▾ TwilightMoore Threads · MTT S80 Driver PackageEPSS 0.16%via NVD
CVE-2026-94426Low· 3.5PoC
1w ago

A vulnerability was determined in xuxueli xxl-job up to 3.5.0

A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /jobgroup/insert. This manipulation of the argument Name causes cross site scripting. The attack can be initiated remo…

▾ Twilightxuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-94627High· 7.5
1w ago

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments

vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV cache block ownership when concurrent child requests share a single transfer ID in prefill/decode disaggregated deployments. Attackers can trigger GPU memory exhausti…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94626High· 7.5
1w ago

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory

vLLM through 0.29.0 fails to validate the tp_size parameter in kv_transfer_params on OpenAI-compatible completion endpoints, allowing attackers to allocate unbounded memory. Attackers can supply arbitrary tp_size values in prefill/decode…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94625Medium· 5.3⚖ disputed
1w ago

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed

vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender…

▾ Sunlitvllm-project · vllmEPSS 0.52%via NVD
CVE-2026-94624High· 7.5
1w ago

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier

vLLM through 0.29.0 contains a denial of service vulnerability in P2P KV offloading when OffloadingConnector is configured with TieringOffloadingSpec and a peer-to-peer secondary tier. Attackers can supply arbitrary remote host and port …

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94623High· 7.5
1w ago

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated dep…

vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated dep…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94622High· 7.5
1w ago

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments

vLLM versions through 0.29.0 contain a denial of service vulnerability in the NIXL connector's metadata handling for prefill/decode disaggregated deployments. Attackers can send requests with incomplete kv_transfer_params dictionary entr…

▾ Twilightvllm-project · vllmEPSS 0.63%via NVD
CVE-2026-94540High· 7.7PoC
1w ago

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's l…

DesktopSMS 1.11.0 by MrPear contains an unauthorized access vulnerability that allows local attackers to transmit SMS, retrieve SMS-derived content, and persist an attacker-selected paired identity by interacting with the application's l…

▾ MidnightMrPear · DesktopSMSEPSS 0.16%via NVD
CVE-2026-61652High· 8.7
1w ago

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issue affects all callers who streamed compressed responses relying on the chunk size — explicit (`iter_bytes(chunk_size=…

▾ Twilightkap-sh · zaprosEPSS 0.44%via NVD
CVE-2026-59814High· 7.6PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's GET /shares/:id?resource_id= route serves a resource with the attacker-controlled mime value and om…

▾ Midnightlaurent22 · joplinEPSS 0.35%via NVD
CVE-2026-55210High· 7.4
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's UserModel.ssoLogin() returns an existing account matched by an IdP-asserted email without checking …

▾ Twilightlaurent22 · joplinEPSS 0.48%via NVD
CVE-2026-61541Medium· 6.9
1w ago

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…

Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests content from an untrusted server, or follows a redirect to one, because a malicious response containing an excessive nu…

▾ Sunlitkap-sh · zaprosEPSS 0.43%via NVD
CVE-2026-59815Medium· 4.3PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, Joplin Server's ItemModel.checkIfAllowed() authorizes writes to items with a share ID when any share_users row exis…

▾ Twilightlaurent22 · joplinEPSS 0.23%via NVD
CVE-2026-15890Medium· 5.3
1w ago

The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized functi…

The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead_get_nonce() in subsys/secure_storage/src/its/transform/aead_get.c, stores its nonce counter in unsynchronized functi…

▾ Sunlitzephyrproject · zephyrEPSS 0.06%via NVD
CVE-2026-46650Medium· 4.4
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, isAcceptedUrl() in packages/renderer/htmlUtils.ts uses an unanchored regular expression for internal resource URLs,…

▾ Sunlitlaurent22 · joplinEPSS 0.29%via NVD
CVE-2026-17054Medium· 5.3
1w ago

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task()

The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and …

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2026-94536Medium· 4.3PoC
1w ago

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions

lamp-cloud through 5.10.0 fails to validate the employeeId parameter in the /anyone/visible/resource endpoint, allowing authenticated users to read any employee's roles and permissions. Attackers can supply arbitrary employeeId values to…

▾ Twilightdromara · lamp-cloudEPSS 0.34%via NVD
CVE-2026-79079High· 7.8PoC
1w ago

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c components

▾ MidnightRed HatEPSS 0.19%via NVD
CVE-2026-59830Medium· 5.4
1w ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-controlled display names before interpolating them into an HTML string passed to trustHTML. A user who could choose a cra…

▾ Sunlitdiscourse · discourseEPSS 0.29%via NVD
CVE-2026-93340Medium· 6.8
1w ago

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in…

Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote attackers to obtain valid password reset tokens for any account by exploiting the client-supplied origin parameter in…

▾ SunlitGladys Assistant · Gladys AssistantEPSS 0.53%via NVD
CVE-2026-88738High· 8.8PoC
1w ago

Jazzware RT1000 Edge webUI v

Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload functionality. An attacker with administrative privileges can upload a server-side executable file. The uploaded file i…

▾ MidnightEPSS 0.86%via NVD
CVE-2026-94532Medium· 6.5PoC
1w ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows authenticated users to read any other user's full profile. Attackers can iterate the userId parameter to harvest sensiti…

▾ Twilightdromara · lamp-cloudEPSS 0.44%via NVD
CVE-2026-88756Medium· 5.3
1w ago

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).

Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitted to the public login endpoint (POST /user/authenticate).

▾ SunlitEPSS 0.22%via NVD
CVE-2026-78806Medium· 5.5
1w ago

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component

An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker to obtain sensitive information via the PerformCommissioningStep function in the ChipDeviceController.cpp component

▾ SunlitEPSS 0.11%via NVD
CVE-2026-94535High· 7.1PoC
1w ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows authenticated users to delete other users' notifications. Attackers can call the DELETE /anyone/extendNotice/deleteMyNoti…

▾ Midnightdromara · lamp-cloudEPSS 0.47%via NVD
CVEs tagged “cve.org” — page 92 · VulnSea