VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15700 CVEsRSS

CVE-2026-79920Critical· 9.9
1w ago

Ajenti is a Linux & BSD modular server admin panel

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-mana…

▾ Midnightajenti · ajentiEPSS 0.62%via NVD
CVE-2026-17051Medium· 6.0
1w ago

The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose()

The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose(). It read the peer-written doorbell register, extracted the payload length with IPC_HEADER_GET_LENGT…

▾ Sunlitzephyrproject · zephyrEPSS 0.11%via NVD
CVE-2026-17050Medium· 5.7
1w ago

The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c)

The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a fai…

▾ Sunlitzephyrproject · zephyrEPSS 0.16%via NVD
CVE-2026-77582Medium· 6.9PoC
1w ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…

▾ Twilighttinyauthapp · tinyauthEPSS 0.48%via NVD
CVE-2026-77560High· 8.1
1w ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…

▾ Twilighttinyauthapp · tinyauthEPSS 0.61%via NVD
CVE-2026-82412High· 8.8
1w ago

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the sca…

▾ Twilightntop · ntopngEPSS 0.65%via NVD
CVE-2026-36468Medium· 6.1
1w ago

Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…

Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-36470Medium· 5.8
1w ago

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.

▾ SunlitEPSS 0.22%via NVD
CVE-2026-36469Critical· 9.1
1w ago

CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).

CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).

▾ MidnightEPSS 0.27%via NVD
CVE-2026-36471Medium· 5.8
1w ago

Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded s…

Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded s…

▾ SunlitEPSS 0.21%via NVD
CVE-2026-77166Low· 2.4PoC
1w ago

The emoji field in the page emoji update endpoint does not properly validate user input

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

▾ TwilightNextcloud · CollectivesEPSS 0.28%via NVD
CVE-2026-77165Medium· 6.5PoC
1w ago

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

▾ TwilightNextcloud · ServerEPSS 0.41%via NVD
CVE-2026-53940High· 8.8PoC
1w ago

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…

▾ Midnightconda · condaEPSS 0.55%via NVD
CVE-2026-85751Critical· 9.8
1w ago

Mailu is a mail server distributed as a set of Docker images

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-F…

▾ MidnightMailu · MailuEPSS 0.56%via NVD
CVE-2026-61681Medium· 4.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, the SNS UnsubscribeConfirmation handler in internal/integrations/ingestors/sns/sns.go calls http.Get() on payload.Unsub…

▾ Sunlithatchet-dev · hatchetEPSS 0.31%via NVD
CVE-2026-36472Medium· 5.2
1w ago

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS)

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascrip…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-63342Medium· 6.3
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-ta…

▾ Sunlithatchet-dev · hatchetEPSS 0.31%via NVD
CVE-2026-84298Low· 3.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map …

▾ Sunlithatchet-dev · hatchetEPSS 0.24%via NVD
CVE-2026-55563High· 8.9PoC
1w ago

Feast is the open source feature store for AI and machine learning

Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across…

▾ Midnightfeast-dev · feastEPSS 0.50%via NVD
CVE-2026-88978Medium· 4.3
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and …

▾ Sunlithatchet-dev · hatchetEPSS 0.28%via NVD
CVE-2026-36467High· 7.2
1w ago

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leadi…

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leadi…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-61687High· 7.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

▾ Twilighthatchet-dev · hatchetEPSS 0.17%via NVD
CVE-2026-94301Critical· 9.8
1w ago

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

▾ MidnightApache Software Foundation · Apache MINAEPSS 0.39%via NVD
CVE-2026-71543High· 7.2
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated…

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.42%via NVD
CVE-2026-68919High· 7.0
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage …

▾ Twilightgocd · gocdEPSS 0.48%via NVD
CVE-2026-61628High· 8.1PoC
1w ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the …

▾ Midnightlucasdillmann · nginx-ignitionEPSS 0.43%via NVD
CVE-2026-55870Low· 2.3
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticat…

▾ Sunlitgocd · gocdEPSS 0.58%via NVD
CVE-2026-55625Medium· 4.9
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and…

▾ Sunlitgocd · gocdEPSS 0.59%via NVD
CVE-2026-55060Low· 3.7
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source c…

▾ Sunlitgocd · gocdEPSS 0.41%via NVD
CVE-2026-52742Medium· 5.1
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for gro…

▾ Sunlitgocd · gocdEPSS 0.71%via NVD
CVEs tagged “cve.org” — page 98 · VulnSea