VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15684 CVEsRSS

CVE-2026-94534High· 7.1PoC
1w ago

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles

lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allowing authenticated attackers to modify arbitrary user profiles. Attackers can supply target user IDs in request bodie…

▾ Midnightdromara · lamp-cloudEPSS 0.49%via NVD
CVE-2026-94533Medium· 6.5PoC
1w ago

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments

lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticated users to download arbitrary attachments. Attackers can retrieve other users' stored files by supplying valid attac…

▾ Twilightdromara · lamp-cloudEPSS 0.44%via NVD
CVE-2026-78847Critical· 9.8PoC
1w ago

An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.

An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to parse front matter when language is js/javascript.This allows arbitrary code execution.

▾ AbyssalEPSS 0.60%via NVD
CVE-2026-61851Medium· 6.5
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js atte…

▾ Sunlitchartbrew · chartbrewEPSS 0.47%via NVD
CVE-2026-61743Medium· 6.3PoC
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's server/modules/safeRequest.js calls validateOutboundUrl() to resolve and validate …

▾ Twilightchartbrew · chartbrewEPSS 0.40%via NVD
CVE-2026-65980High· 7.9
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.3, Chartbrew's ClickHouse protocol in server/sources/plugins/clickhouse/clickhouse.protocol.js ca…

▾ Twilightchartbrew · chartbrewEPSS 0.66%via NVD
CVE-2026-61852Medium· 5.8PoC
1w ago

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. Prior to 5.2.2, Chartbrew's runQuery() implementation in server/modules/ai/orchestrator/tools/runQuery.js inte…

▾ Twilightchartbrew · chartbrewEPSS 0.36%via NVD
CVE-2026-88412Medium· 5.3
1w ago

An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ SunlitEPSS 0.40%via NVD
CVE-2026-88411High· 7.5
1w ago

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 leads to a Denial of Service (DoS) within the application.

▾ TwilightEPSS 0.49%via NVD
CVE-2026-88410High· 7.1
1w ago

The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

▾ TwilightEPSS 0.32%via NVD
CVE-2026-88409High· 8.8
1w ago

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix function (/v19/decode_matrix.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ TwilightEPSS 0.48%via NVD
CVE-2026-88408Medium· 6.5
1w ago

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/op_aggregate.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ SunlitEPSS 0.41%via NVD
CVE-2026-88407High· 7.5
1w ago

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20.4 allows attackers to cause a Denial of Service (DoS) via a crafted input.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-88406High· 7.5
1w ago

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c)

FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses function (/ast/ast_validations.c). This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted i…

▾ TwilightEPSS 0.46%via NVD
CVE-2026-88404Critical· 9.8PoC
1w ago

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execution.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

▾ AbyssalEPSS 0.86%via NVD
CVE-2026-88402Critical· 9.8PoC
1w ago

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.

▾ AbyssalEPSS 0.47%via NVD
CVE-2026-79919Medium· 6.3
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack he…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.39%via NVD
CVE-2026-79918Medium· 6.3
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.36%via NVD
CVE-2026-67827Critical· 9.8PoC
1w ago

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffm…

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffm…

▾ AbyssalEPSS 0.75%via NVD
CVE-2026-61647High· 7.1
1w ago

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-t…

▾ Twilightroomi-fields · notebooklm-mcpEPSS 0.32%via NVD
CVE-2026-59816Medium· 4.3PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts o…

▾ Twilightlaurent22 · joplinEPSS 0.36%via NVD
CVE-2026-55179Medium· 6.5PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from a…

▾ Twilightlaurent22 · joplinEPSS 0.26%via NVD
CVE-2026-55105High· 7.7PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated by the vendored fountain.js renderer …

▾ Midnightlaurent22 · joplinEPSS 0.50%via NVD
CVE-2026-49453High· 7.0PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or pa…

▾ Midnightlaurent22 · joplinEPSS 0.41%via NVD
CVE-2026-49450High· 7.1PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.…

▾ Midnightlaurent22 · joplinEPSS 0.18%via NVD
CVE-2026-49449Low· 2.5
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note au…

▾ Sunlitlaurent22 · joplinEPSS 0.17%via NVD
CVE-2026-46649Critical· 9.1
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minut…

▾ Midnightlaurent22 · joplinEPSS 0.56%via NVD
CVE-2026-94572Critical· 9.4PoC
1w ago

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and t…

▾ AbyssalOpenStack · OctaviaEPSS 0.53%via NVD
CVE-2026-94571Critical· 9.4
1w ago

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, …

▾ MidnightOpenStack · OctaviaEPSS 0.53%via NVD
CVE-2026-79317Medium· 4.8
1w ago

A session invalidation flaw exists in x-ui 0.3.2

A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the databas…

▾ SunlitEPSS 0.29%via NVD
CVEs tagged “cve.org” — page 93 · VulnSea