VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

15700 CVEsRSS

CVE-2026-52741High· 7.5
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(…

▾ Twilightgocd · gocdEPSS 0.54%via NVD
CVE-2026-52740Medium· 5.3
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with no…

▾ Sunlitgocd · gocdEPSS 0.58%via NVD
CVE-2026-80110High· 8.1
1w ago

A flaw was found in pki-core

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to ove…

▾ TwilightRed Hat · pki-coreEPSS 0.24%via NVD
CVE-2026-75939High· 7.4
1w ago

A flaw was found in openshift/oc-mirror

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature v…

▾ TwilightRed Hat · openshift4/oc-mirror-plugin-rhel8EPSS 0.31%via NVD
CVE-2026-54584Medium· 5.3
1w ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport …

▾ SunlitMidnightBSD · mportEPSS 0.47%via NVD
CVE-2026-93339Medium· 5.4
1w ago

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…

▾ SunlitMetaphor Creations · DittyEPSS 0.31%via NVD
CVE-2026-61629High· 7.5PoC
1w ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptL…

▾ Midnightlucasdillmann · nginx-ignitionEPSS 0.42%via NVD
CVE-2026-94184High· 8.1
1w ago

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixe…

▾ TwilightRed Hat · fetchmailEPSS 0.78%via NVD
CVE-2026-61630Medium· 4.2
1w ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the is…

▾ Sunlitlucasdillmann · github.com/lucasdillmann/nginx-ignitionEPSS 0.38%via NVD
CVE-2026-55567High· 7.8PoC
1w ago

BleachBit cleans files to free disk space and to maintain privacy

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory w…

▾ Midnightbleachbit · bleachbitEPSS 0.14%via NVD
CVE-2026-52743Medium· 4.3
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…

▾ Sunlitgocd · gocdEPSS 0.40%via NVD
CVE-2026-82355Medium· 4.2
1w ago

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

▾ Sunlitapache · airflowEPSS 0.73%via NVD
CVE-2026-75158Medium· 4.3
1w ago

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore e…

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-94404High· 7.1
1w ago

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protec…

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protec…

▾ TwilightMISP · MISPEPSS 0.21%via NVD
CVE-2026-94401High· 8.3
1w ago

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

▾ TwilightMISP · MISPEPSS 0.38%via NVD
CVE-2026-86473Critical· 9.1
1w ago

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout …

▾ Midnightapache · airflowEPSS 0.75%via NVD
CVE-2026-94387Medium· 5.4
1w ago

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can i…

▾ Sunlitaureuserp · aureuserpvia NVD
CVE-2026-88807High· 8.9
1w ago

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

▾ TwilightX.org · libXrenderEPSS 0.26%via NVD
CVE-2026-88806High· 7.5
1w ago

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

▾ Twilightx.org · libX11EPSS 0.20%via NVD
CVE-2025-71421High· 7.2
1w ago

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit the…

▾ Twilightuvdesk · core-frameworkEPSS 0.44%via NVD
CVE-2025-71420Medium· 4.3PoC
1w ago

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate …

▾ Twilightuvdesk · core-frameworkEPSS 0.30%via NVD
CVE-2025-71419Medium· 5.4
1w ago

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script …

▾ Sunlituvdesk · core-frameworkEPSS 0.18%via NVD
CVE-2026-94382Medium· 4.2PoC
1w ago

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attacker…

▾ Twilighthenrygd · beszelEPSS 0.30%via NVD
CVE-2026-85220Low· 3.7
1w ago

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. …

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. …

▾ SunlitThinkst Applied Research · CanaryEPSS 0.41%via NVD
CVE-2026-94393Medium· 6.4
1w ago

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on o…

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on o…

▾ SunlitMISP · MISPEPSS 0.37%via NVD
CVE-2026-94394Medium· 6.3
1w ago

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of…

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of…

▾ SunlitMISP · MISPEPSS 0.35%via NVD
CVE-2026-94383High· 8.6
1w ago

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A …

▾ TwilightMISP · MISPEPSS 0.51%via NVD
CVE-2026-94381High· 8.7
1w ago

MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information

MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function co…

▾ TwilightMISP · MISPEPSS 0.37%via NVD
CVE-2026-94379Medium· 6.9
1w ago

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PU…

▾ SunlitMISP · MISPEPSS 0.58%via NVD
CVE-2026-94374High· 8.3
1w ago

MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model

MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves…

▾ TwilightMISP · MISPEPSS 0.37%via NVD
CVEs tagged “cve.org” — page 99 · VulnSea