VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25423 CVEsRSS

CVE-2026-86473Critical· 9.1
1w ago

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie

Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token cookie. When a client logs out presenting its credential as an Authorization bearer header instead, the endpoint returns its normal logout …

▾ Midnightapache · airflowEPSS 0.75%via NVD
CVE-2026-94387Medium· 5.4
1w ago

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping

Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can i…

▾ Sunlitaureuserp · aureuserpvia NVD
CVE-2026-93884None
1w ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

▾ Sunlitvia NVD
CVE-2026-88807High· 8.9
1w ago

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

▾ TwilightX.org · libXrenderEPSS 0.26%via NVD
CVE-2026-88806High· 7.5
1w ago

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

▾ Twilightx.org · libX11EPSS 0.20%via NVD
CVE-2025-71421High· 7.2
1w ago

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator

UVdesk core-framework before 1.1.7 contains an improper privilege management vulnerability in the editAgent endpoint that allows agents with agent-management privilege to escalate their own role to administrator. Attackers can submit the…

▾ Twilightuvdesk · core-frameworkEPSS 0.44%via NVD
CVE-2025-71420Medium· 4.3PoC
1w ago

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups

UVdesk core-framework before 1.1.7 contains an authorization bypass vulnerability in the saved reply endpoint that allows authenticated agents to access replies restricted to other support groups. Attackers with ROLE_AGENT can enumerate …

▾ Twilightuvdesk · core-frameworkEPSS 0.30%via NVD
CVE-2025-71419Medium· 5.4
1w ago

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action

UVdesk core-framework before 1.1.7 contains a stored cross-site scripting vulnerability in the SwiftMailer configuration identifier parameter of the createMailerConfiguration action. Attackers with ROLE_AGENT can inject malicious script …

▾ Sunlituvdesk · core-frameworkEPSS 0.18%via NVD
CVE-2026-94382Medium· 4.2PoC
1w ago

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access

Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-alerts handlers that allows any authenticated user to create or delete alerts on systems they cannot access. Attacker…

▾ Twilighthenrygd · beszelEPSS 0.30%via NVD
CVE-2026-85220Low· 3.7
1w ago

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. …

A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Denial-of-Service attack against the honeypot. The vulnerability is accessible when the Redis service is enabled only. …

▾ SunlitThinkst Applied Research · CanaryEPSS 0.41%via NVD
CVE-2026-94393Medium· 6.4
1w ago

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on o…

When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without properly checking whether that report actually belongs to the same event. As a result, a user who has editing rights on o…

▾ SunlitMISP · MISPEPSS 0.37%via NVD
CVE-2026-94394Medium· 6.3
1w ago

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of…

When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall event, but it does not always check whether the individual pieces of data are also allowed for that user. Because of…

▾ SunlitMISP · MISPEPSS 0.35%via NVD
CVE-2026-94383High· 8.6
1w ago

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension

The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file extension. The only sanitization applied was basename() to strip path components and a check for empty or dot values. A …

▾ TwilightMISP · MISPEPSS 0.51%via NVD
CVE-2026-94381High· 8.7
1w ago

MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information

MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API key should only let someone view information. However, after logging in with such a key, a specific MISP function co…

▾ TwilightMISP · MISPEPSS 0.37%via NVD
CVE-2026-94379Medium· 6.9
1w ago

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths

The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-critical code paths. The original code used an allowlist approach, checking only for specific HTTP methods (POST and PU…

▾ SunlitMISP · MISPEPSS 0.58%via NVD
CVE-2026-94374High· 8.3
1w ago

MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model

MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event model. When processing module results, the code iterates over EventReport entries supplied in the resolved data and saves…

▾ TwilightMISP · MISPEPSS 0.37%via NVD
CVE-2026-94216Medium· 4.3PoC
1w ago

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This vulnerability affects the function authorize of the file /usr/sbin/webserver of the component HTTP Header Handler. E…

▾ TwilightST Engineering iDirect · EvolutionEPSS 0.46%via NVD
CVE-2026-94372Medium· 6.3
1w ago

MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page

MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP instance detects unknown custom or default galaxy clusters during synchronization, it renders sample tag names in an …

▾ SunlitMISP · MISPEPSS 0.39%via NVD
CVE-2026-94211Low· 2.4PoC
1w ago

A vulnerability has been found in Hyve5 Leantime up to 3.9.8

A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of the file /app/Domain/Dashboard/Templates/show.blade.php of the component Project Dashboard. Such manipulation leads to …

▾ TwilightHyve5 · LeantimeEPSS 0.35%via NVD
CVE-2026-84285High· 8.8
1w ago

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

▾ TwilightDassault Systèmes · Tuleap Enterprise EditionEPSS 1.8%via NVD
CVE-2026-94373Medium· 6.3
1w ago

MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component

MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The ContextualMenu class populates HTML <option> elements by assigning user-controllable values to the innerHTML property. Be…

▾ SunlitMISP · MISPEPSS 0.39%via NVD
CVE-2026-94214Medium· 4.3PoC
1w ago

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717

A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the file /login.html of the component Management Service. Performing a manipulation of the arg…

▾ TwilightST Engineering iDirect · EvolutionEPSS 0.46%via NVD
CVE-2026-94368High· 7.1
1w ago

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway

A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object Gateway. The issue occurs when the service processes S3 presigned URLs using Signature Version 4 (SigV4). Due to impr…

▾ TwilightRed Hat · odf4/mcg-core-rhel9EPSS 0.23%via NVD
CVE-2026-89139High· 8.7
1w ago

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…

Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a compute provider named subprocess whose function is to launch a worker by running a command on the machine hosting the Work…

▾ TwilightTemporal Technologies, Inc. · go.temporal.io/serverEPSS 0.58%via NVD
CVE-2026-87858High· 7.2
1w ago

Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header

Temporal Server decided whether a Workflow completion callback was internal by reading a caller-supplied HTTP header. An authenticated caller holding only write permission in a single namespace could attach a completion callback whose UR…

▾ TwilightTemporal Technologies, Inc. · go.temporal.io/serverEPSS 0.78%via NVD
CVE-2026-65654High· 8.7
1w ago

github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes

github.com/temporalio/ringpop-go enforces configured LabelOptions limits when an application changes the local node's labels, but affected versions do not apply those limits to label maps received in SWIM membership changes. A network pe…

▾ TwilightTemporal Technologies, Inc. · github.com/temporalio/ringpop-goEPSS 0.58%via NVD
CVE-2026-65653High· 8.7
1w ago

github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks

github.com/temporalio/tchannel-go did not reject TChannel call fragments containing checksum metadata but no length-prefixed argument chunks. The fragment reader left its chunk slice empty and then unconditionally selected the first elem…

▾ TwilightTemporal Technologies, Inc. · github.com/temporalio/tchannel-goEPSS 0.71%via NVD
CVE-2026-65652High· 8.7
1w ago

github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames

github.com/temporalio/tchannel-go did not validate the one-byte checksum-type field in inbound TChannel call frames. A network peer that can reach a listener can complete the standard initialization handshake and send a call request with…

▾ TwilightTemporal Technologies, Inc. · github.com/temporalio/tchannel-goEPSS 0.71%via NVD
CVE-2026-65651High· 8.7
1w ago

temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit

temporalio/sqlparser accepts SQL containing deeply nested unary expressions and can return a correspondingly deep abstract syntax tree without enforcing an applicable nesting limit. The library's String and Walk operations recursively tr…

▾ TwilightTemporal Technologies, Inc. · github.com/temporalio/sqlparserEPSS 0.67%via NVD
CVE-2026-16651High· 8.7
1w ago

temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits

temporalio/sqlparser can panic when Parse, ParseStrictDDL, or ParseNext processes a MySQL version comment whose contents are empty or consist only of one to five decimal digits. ExtractMysqlComment does not check the -1 result returned b…

▾ TwilightTemporal Technologies, Inc. · github.com/temporalio/sqlparserEPSS 0.39%via NVD
CVEs tagged “nvd” — page 102 · VulnSea