VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15684 CVEsRSS

CVE-2026-88746High· 7.1
1w ago

idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.

idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-73553High· 7.5PoC
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix befo…

▾ Midnightenvoyproxy · envoyEPSS 0.52%via NVD
CVE-2026-73551Medium· 5.3
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon para…

▾ Sunlitenvoyproxy · envoyEPSS 0.55%via NVD
CVE-2026-77519Medium· 5.4PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and active status, without enforcing the is_permanent and expire_ti…

▾ Twilight1Panel-dev · MaxKBEPSS 0.24%via NVD
CVE-2026-73511Medium· 5.3
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolo…

▾ Sunlitenvoyproxy · envoyEPSS 0.55%via NVD
CVE-2026-88467None
1w ago

CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

▾ SunlitEPSS 0.20%via NVD
CVE-2026-79316High· 7.6
1w ago

An improper access control vulnerability exists in x-ui 0.3.2

An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, …

▾ TwilightEPSS 0.32%via NVD
CVE-2026-77520Medium· 5.4
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from the homepage application question-ranking endpoint when the published victi…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.23%via NVD
CVE-2026-58272Medium· 5.3PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accou…

▾ TwilightSync-in · serverEPSS 0.34%via NVD
CVE-2026-58270Medium· 6.5PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic…

▾ TwilightSync-in · serverEPSS 0.35%via NVD
CVE-2026-88745Medium· 6.1
1w ago

EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.

EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-79916Critical· 9.1
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /r…

▾ Midnight1Panel-dev · MaxKBEPSS 0.45%via NVD
CVE-2026-88405Critical· 9.8PoC
1w ago

A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

▾ AbyssalEPSS 0.75%via NVD
CVE-2026-77518Medium· 5.0PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because …

▾ Twilight1Panel-dev · MaxKBEPSS 0.27%via NVD
CVE-2026-88403Medium· 6.5PoC
1w ago

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-77525Medium· 4.2PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id and chat_record_id values without confirming that the c…

▾ Twilight1Panel-dev · MaxKBEPSS 0.19%via NVD
CVE-2026-77523High· 7.4
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads and saves a Model by id alone without including wo…

▾ Twilight1Panel-dev · MaxKBEPSS 0.26%via NVD
CVE-2026-77516Medium· 5.4
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can still bind its identifier through tool_ids, skill_tool_i…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.28%via NVD
CVE-2026-93433Medium· 5.5
1w ago

A flaw was found in libstoragemgmt

A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specially crafted SCSI (Small Computer System Interface) Vital Product Data (VPD) page 0x80 data. This malformed data, spec…

▾ SunlitRed Hat · libstoragemgmtEPSS 0.15%via NVD
CVE-2026-79917Medium· 6.5
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.27%via NVD
CVE-2026-94424High· 8.8
1w ago

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150

A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_140001000 in the library mtdispkm64.sys of the component IOCTL Handler. The manipulation leads to heap-based buffer overfl…

▾ TwilightMoore Threads · MTT S80 Driver PackageEPSS 0.20%via NVD
CVE-2026-77522Medium· 4.3PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get wit…

▾ Twilight1Panel-dev · MaxKBEPSS 0.30%via NVD
CVE-2026-77521Critical· 10.0PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits exe…

▾ Abyssal1Panel-dev · MaxKBEPSS 1.0%via NVD
CVE-2026-77517Medium· 5.4PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, then query the target Document by document_id or Paragraph…

▾ Twilight1Panel-dev · MaxKBEPSS 0.23%via NVD
CVE-2026-94588Medium· 4.4
1w ago

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality

In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is caused by improper handling of user-supplied input passed to the underlying apt-get command when fetching package ch…

▾ SunlitProxmox · pmg-apiEPSS 0.25%via NVD
CVE-2026-79319Medium· 5.3
1w ago

Stencil core 4.43.5 is vulnerable to Incorrect Access Control.

Stencil core 4.43.5 is vulnerable to Incorrect Access Control.

▾ SunlitEPSS 0.21%via NVD
CVE-2026-79318Medium· 6.5
1w ago

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file()/write_file() (applications/admin/controllers/webservices.py).

▾ SunlitEPSS 0.56%via NVD
CVE-2026-73546High· 7.4PoC
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's /stats?format=html admin endpoint uses StatsHtmlRender, which sanitizes string statistic values …

▾ Midnightenvoyproxy · envoyEPSS 0.60%via NVD
CVE-2026-73512High· 7.5PoC
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's HttpDatagramHandler caches the current RequestDecoder when Capsule Protocol is enabled. Stream r…

▾ Midnightenvoyproxy · envoyEPSS 0.83%via NVD
CVE-2026-58269High· 8.1PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, `POST /api/auth/token` authenticates with username and password only, then calls `getTokens()`, which returns full a…

▾ MidnightSync-in · serverEPSS 0.22%via NVD
CVEs tagged “cve.org” — page 94 · VulnSea