VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

21060 CVEsRSS

CVE-2026-94449High· 7.5
today

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, …

TwilightRed Hat · exploit-intelligence/agent-client-rhel9via NVD
CVE-2026-77561Medium· 5.3
today

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a globa…

Sunlittinyauthapp · tinyauthvia NVD
CVE-2026-63116High· 8.8
today

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When…

TwilightdeepstreamIO · deepstream.iovia NVD
CVE-2026-62866Medium· 6.2
today

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the s…

SunlitTomWright · daselvia NVD
CVE-2026-62371High· 8.8
today

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actio…

Twilightkubeedge · kubeedgevia NVD
CVE-2026-62370Medium· 6.5
today

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHea…

Sunlitkubeedge · kubeedgevia NVD
CVE-2026-59168Medium· 6.2
today

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go parseElement, …

SunlitTomWright · daselvia NVD
CVE-2026-83621High· 8.1
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.…

Twilightntop · ntopngvia NVD
CVE-2026-84990High· 8.8
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any a…

Twilightntop · ntopngvia NVD
CVE-2026-62987Medium· 5.8
today

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…

Sunlitfabiolb · fabiovia NVD
CVE-2026-61674Critical· 9.2
today

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the …

Midnightfluent · fluent-bitvia NVD
CVE-2026-58504Medium· 6.1
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the draw.io origin when selected cells are processed …

Sunlitjgraph · drawiovia NVD
CVE-2026-63416Low· 3.7
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL …

Sunlitjgraph · drawiovia NVD
CVE-2026-63334Medium· 6.8
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java perfor…

Sunlitjgraph · drawiovia NVD
CVE-2026-63373Medium· 4.2
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is f…

Sunlitjgraph · drawiovia NVD
CVE-2026-76898High· 7.7
today

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and…

Twilightjgraph · drawiovia NVD
CVE-2026-79920Critical· 9.9
today

Ajenti is a Linux & BSD modular server admin panel

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-mana…

Midnightajenti · ajentivia NVD
CVE-2026-17051Medium· 6.0
today

The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose()

The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose(). It read the peer-written doorbell register, extracted the payload length with IPC_HEADER_GET_LENGT…

Sunlitzephyrproject · zephyrvia NVD
CVE-2026-17050Medium· 5.7
today

The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c)

The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicated usb_device_heap in usbh_device_set_configuration() (subsys/usb/host/usbh_device.c). On three failure paths — a fai…

Sunlitzephyrproject · zephyrvia NVD
CVE-2026-77582Medium· 6.9
today

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing difference between authentication attempts for existing and nonexistent local usernames. internal/controller/user_contr…

Sunlittinyauthapp · tinyauthvia NVD
CVE-2026-77560High· 8.1
today

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.2, Tinyauth compares forwarded hostnames case-sensitively while reverse proxies route equivalent hostnames case-insensitively, allowing an authenticated low-privilege u…

Twilighttinyauthapp · tinyauthvia NVD
CVE-2026-82412High· 8.8
today

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, the vulnerability-scan endpoints scripts/lua/rest/v2/add/host/to_scan.lua and scripts/lua/rest/v2/exec/host/schedule_vulnerability_scan.lua accept the sca…

Twilightntop · ntopngvia NVD
CVE-2026-36468Medium· 6.1
today

Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…

Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitrarily named URL parameter key, with part of its name containing any URL-encoded common XSS payload (such as "><script>…

Sunlitvia NVD
CVE-2026-36470None
today

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied into the response HTML unmodified/unescaped during POST messages to index.php.

Sunlitvia NVD
CVE-2026-36469None
today

CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).

CuteNews v.2.1.2 is vulnerable to Server-Side Request Forgery (SSRF) in core/modules/media.php -- upload_from_inet (Media Manager's "Upload by URL" functionality).

Sunlitvia NVD
CVE-2026-36471None
today

Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded s…

Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote attacker to inject arbitrary values into internal request variables (including __referer) via a crafted base64-encoded s…

Sunlitvia NVD
CVE-2026-77166Low· 2.4
today

The emoji field in the page emoji update endpoint does not properly validate user input

The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line breaks, the sidebar layout becomes broken and can hide other items.

SunlitNextcloud · Collectivesvia NVD
CVE-2026-77165Medium· 6.5
today

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recovery path outside of the database.

SunlitNextcloud · Servervia NVD
CVE-2026-53940High· 8.8
today

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms

Conda is a system-level binary package and environment manager that runs on major operating systems and platforms. Prior to 26.5.2, parse_entry_point_def in conda/common/path/python.py accepted an unvalidated entry-point command from a n…

Twilightconda · condavia NVD
CVE-2026-85751Critical· 9.8
today

Mailu is a mail server distributed as a set of Docker images

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-F…

MidnightMailu · Mailuvia NVD
CVEs tagged “nvd” · VulnSea