VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25423 CVEsRSS

CVE-2026-36472Medium· 5.2
1w ago

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS)

CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allows a remote attacker to execute arbitrary JavaScript in the context of an authenticated user's session via a javascrip…

▾ SunlitEPSS 0.23%via NVD
CVE-2026-63342Medium· 6.3
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, api-contracts/openapi/paths/v1/workflow-runs/workflow_run.yaml defines the GET /api/v1/stable/durable-tasks/{durable-ta…

▾ Sunlithatchet-dev · hatchetEPSS 0.31%via NVD
CVE-2026-84298Low· 3.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, the V1 DurableTask stream handler stores worker-supplied task_external_id values in the durableInvocations routing map …

▾ Sunlithatchet-dev · hatchetEPSS 0.24%via NVD
CVE-2026-55563High· 8.9PoC
1w ago

Feast is the open source feature store for AI and machine learning

Feast is the open source feature store for AI and machine learning. Prior to 0.65.0, .github/workflows/pr_integration_tests.yml uses pull_request_target with the synchronize event and preserves ok-to-test, approved, or lgtm labels across…

▾ Midnightfeast-dev · feastEPSS 0.50%via NVD
CVE-2026-88978Medium· 4.3
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, the WorkerStatus gRPC polling path in pkg/repository/durable_events.go passes caller-supplied durable task, node, and …

▾ Sunlithatchet-dev · hatchetEPSS 0.28%via NVD
CVE-2026-36467High· 7.2
1w ago

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leadi…

Unrestricted Upload of File with Dangerous Type in core/modules/media.php in CuteNews v.2.1.2 allows remote authenticated users with access to the Media Manager panel to execute arbitrary code in the context of the web application, leadi…

▾ TwilightEPSS 0.53%via NVD
CVE-2026-61687High· 7.1
1w ago

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

▾ Twilighthatchet-dev · hatchetEPSS 0.17%via NVD
CVE-2026-94301Critical· 9.8
1w ago

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committ…

▾ MidnightApache Software Foundation · Apache MINAEPSS 0.39%via NVD
CVE-2026-71543High· 7.2
1w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies could substitute attacker-controlled identity data without rejecting syntax-significant characters. In ACL templated…

▾ Twilightopenbao · github.com/openbao/openbaoEPSS 0.42%via NVD
CVE-2026-68919High· 7.0
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.3.0 until 26.1.0, GoCD does not correctly encode and escape malicious material modification comments that mimic the special trackback format used by package materials when rendering the Stage …

▾ Twilightgocd · gocdEPSS 0.48%via NVD
CVE-2026-61628High· 8.1PoC
1w ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. Prior to version 2.41.1, `POST /api/users/onboarding/finish` is registered as anonymous (unauthenticated) and creates a user with full ReadWrite admin permissions. Because the …

▾ Midnightlucasdillmann · nginx-ignitionEPSS 0.43%via NVD
CVE-2026-55870Low· 2.3
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in the userinfo portion of source control material URLs through several read-only APIs available to regular authenticat…

▾ Sunlitgocd · gocdEPSS 0.58%via NVD
CVE-2026-55625Medium· 4.9
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/admin/internal/material_test and /go/api/internal/config_repos/*/material_test accept an arbitrary existing pipeline and…

▾ Sunlitgocd · gocdEPSS 0.59%via NVD
CVE-2026-55060Low· 3.7
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 13.1.0 until 26.1.0, the /go/api/support/process_list endpoint does not enforce its intended administrator-only authorization. An authenticated internal user can query the endpoint while source c…

▾ Sunlitgocd · gocdEPSS 0.41%via NVD
CVE-2026-52742Medium· 5.1
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical full server configuration to pipeline group administrators instead of restricting responses to configuration for gro…

▾ Sunlitgocd · gocdEPSS 0.71%via NVD
CVE-2026-52741High· 7.5
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.3.0 until 26.1.0, GoCD can generate unescaped tracking-tool links from commit comments when a project uses a lenient Tracking Tool regular expression with an ID capturing group, such as JIRA-(…

▾ Twilightgocd · gocdEPSS 0.54%via NVD
CVE-2026-52740Medium· 5.3
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names case-sensitively when selecting authorization filters. A lower-privileged authenticated user can send a request with no…

▾ Sunlitgocd · gocdEPSS 0.58%via NVD
CVE-2026-80110High· 8.1
1w ago

A flaw was found in pki-core

A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to ove…

▾ TwilightRed Hat · pki-coreEPSS 0.24%via NVD
CVE-2026-75939High· 7.4
1w ago

A flaw was found in openshift/oc-mirror

A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature v…

▾ TwilightRed Hat · openshift4/oc-mirror-plugin-rhel8EPSS 0.31%via NVD
CVE-2026-54584Medium· 5.3
1w ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport …

▾ SunlitMidnightBSD · mportEPSS 0.47%via NVD
CVE-2026-93339Medium· 5.4
1w ago

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…

Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that allows authenticated users with Author-level privileges or higher to inject arbitrary HTML elements by supplying malicio…

▾ SunlitMetaphor Creations · DittyEPSS 0.31%via NVD
CVE-2026-61629High· 7.5PoC
1w ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptL…

▾ Midnightlucasdillmann · nginx-ignitionEPSS 0.42%via NVD
CVE-2026-94184High· 8.1
1w ago

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support

A stack-based buffer overflow flaw was found in fetchmail when built with NTLM support. A malicious or compromised mail server advertising NTLM authentication can send a crafted Type 2 challenge that causes fetchmail to write past a fixe…

▾ TwilightRed Hat · fetchmailEPSS 0.78%via NVD
CVE-2026-61630Medium· 4.2
1w ago

nginx ignition is a user interface for the nginx web server

nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enabled the OTP 2FA can have their TOTP reused during the standard 30 second validity window. Version 2.35.1 patches the is…

▾ Sunlitlucasdillmann · github.com/lucasdillmann/nginx-ignitionEPSS 0.38%via NVD
CVE-2026-55567High· 7.8PoC
1w ago

BleachBit cleans files to free disk space and to maintain privacy

BleachBit cleans files to free disk space and to maintain privacy. Prior to 6.0.1, privileged Windows cleaning does not lock and validate a target's parent directory before deletion. A local unprivileged user can replace that directory w…

▾ Midnightbleachbit · bleachbitEPSS 0.14%via NVD
CVE-2026-52743Medium· 4.3
1w ago

GoCD is a continuous deliver server

GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a requested server-assigned job ID belongs to the pipeline and stage named in the request. An authenticated user can gu…

▾ Sunlitgocd · gocdEPSS 0.40%via NVD
CVE-2026-82355Medium· 4.2
1w ago

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airflow resolves the caller from the cookie and ignores the bearer token, inverting the intended precedence of bearer ove…

▾ Sunlitapache · airflowEPSS 0.73%via NVD
CVE-2026-75158Medium· 4.3
1w ago

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read

Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting them to the Dags the caller is authorized to read. Any authenticated user holding asset-read access could therefore e…

▾ Sunlitapache · airflowEPSS 0.64%via NVD
CVE-2026-94404High· 7.1
1w ago

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protec…

MISP has a security issue that could let an attacker change threat-intelligence data through a logged-in user’s browser without that user knowingly approving the change. The affected function did not properly enforce MISP’s usual protec…

▾ TwilightMISP · MISPEPSS 0.21%via NVD
CVE-2026-94401High· 8.3
1w ago

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

MISP has a file-handling vulnerability that could let certain authenticated users make the server read files or access internal network services. When importing an XML file, MISP did not properly verify that the uploaded content was act…

▾ TwilightMISP · MISPEPSS 0.38%via NVD
CVEs tagged “nvd” — page 101 · VulnSea