VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25423 CVEsRSS

CVE-2026-91865High· 7.5
1w ago

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentially during normalization, consuming huge amounts of CPU and memory (denial of service). Users are recommended to upgr…

▾ Twilightapache · neethiEPSS 0.74%via NVD
CVE-2026-16652High· 7.1
1w ago

Temporal Server did not bound the work performed while searching for a Schedule's next action time

Temporal Server did not bound the work performed while searching for a Schedule's next action time. An authenticated caller with namespace write permission could create or update a Schedule that combines a fine-grained cadence with an ex…

▾ TwilightTemporal Technologies, Inc. · go.temporal.io/serverEPSS 0.27%via NVD
CVE-2026-91867Medium· 4.3
1w ago

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). User…

When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server that trickles bytes slowly can keep the fetch alive indefinitely and tie up the calling thread (denial of service). User…

▾ Sunlitapache · neethiEPSS 0.50%via NVD
CVE-2026-91866High· 7.5
1w ago

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes…

▾ Twilightapache · neethiEPSS 0.74%via NVD
CVE-2026-91863High· 7.5
1w ago

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and exhaust the thread stack, crashing the parser (denial of service). Users are recommended to upgrade to version 3.2.4, w…

▾ Twilightapache · neethiEPSS 0.76%via NVD
CVE-2026-91864High· 7.5
1w ago

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into memory without counting it against its size limits, exhausting the heap (denial of service). Users are recommended to u…

▾ Twilightapache · neethiEPSS 0.74%via NVD
CVE-2026-94210Low· 3.5PoC
1w ago

A flaw has been found in Hyve5 Leantime up to 3.9.8

A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the file app/Domain/Tickets/Services/Tickets.php of the component Kanban Board. This manipulation causes cross site scri…

▾ TwilightHyve5 · LeantimeEPSS 0.36%via NVD
CVE-2026-92612Low· 1.0PoC
1w ago

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8

In Eclipse iceoryx2 versions greater than v0.8.0, the StaticString exposes its contents as mutable bytes through safe APIs, while String::as_str() converts those bytes into a Rust string slice without validating UTF-8. An application can…

▾ TwilightEclipse Foundation · Eclipse iceoryx™EPSS 0.15%via NVD
CVE-2026-77021Medium· 5.3
1w ago

Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by se…

Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by se…

▾ SunlitCheckmk GmbH · CheckmkEPSS 0.38%via NVD
CVE-2026-92574High· 8.8
1w ago

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context

A vulnerability in CRI-O checkpoint restore allows a user who can create a pod from a malicious checkpointed container to bypass the destination Kubernetes security context. The restored process may retain credentials, Linux capabilities…

▾ TwilightRed Hat · openshift-sandboxed-containers/osc-monitor-rhel9EPSS 0.65%via NVD
CVE-2026-91921Medium· 5.1
1w ago

Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform

Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the w…

▾ Sunlit1millionbot · AI Chatbot Platform (SaaS) de 1millionbot.EPSS 0.60%via NVD
CVE-2026-94277Medium· 6.3
1w ago

MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding

MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into HTML output via sprintf() without any HTML encoding. An authenticated user holding the perm_galaxy_editor permission …

▾ SunlitMISP · MISPEPSS 0.40%via NVD
CVE-2026-94152Medium· 4.3PoC
1w ago

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorizatio…

▾ TwilightOmega Solution · FBP Fulfillment by PeopleEPSS 0.37%via NVD
CVE-2026-92400Medium· 5.3
1w ago

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account bef…

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment notification was confirmed in the store's configured payment environment or paid to the store's own merchant account bef…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-86802Low· 3.7
1w ago

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary…

The To Do List Member WordPress plugin through 1.6 does not have authorisation or nonce checks in an import routine, and does not validate the location it fetches the imported data from, allowing unauthenticated users to create arbitrary…

▾ SunlitEPSS 0.25%via NVD
CVE-2026-85113Medium· 6.5
1w ago

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated …

The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before rendering them on public pages, and the shortcode stripping it applies can be defeated by nesting, allowing unauthenticated …

▾ SunlitEPSS 0.31%via NVD
CVE-2026-85010Medium· 5.3
1w ago

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place ord…

The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side when items are added to or updated in the cart, allowing unauthenticated users to set an arbitrary price and place ord…

▾ SunlitEPSS 0.32%via NVD
CVE-2025-12999Critical· 9.1PoC
1w ago

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-Forwarded-Proto and X-Forwarded-Prefix request headers, with no check on whether the sender was a truste…

▾ AbyssalEclipse Foundation · Eclipse Open VSXEPSS 0.34%via NVD
CVE-2026-94151Medium· 5.3PoC
1w ago

A weakness has been identified in Omega Solution HRM OS up to 20260717

A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /role-permission/permission of the component Role Permission API. Executing a manipulation of the argument roleId can le…

▾ TwilightOmega Solution · HRM OSEPSS 0.68%via NVD
CVE-2026-94150Low· 2.4PoC
1w ago

A security flaw has been discovered in Omega Solution HRM OS up to 20260717

A security flaw has been discovered in Omega Solution HRM OS up to 20260717. The impacted element is an unknown function of the file /media/view/ of the component SVG File Upload. Performing a manipulation results in cross site scripting…

▾ TwilightOmega Solution · HRM OSEPSS 0.35%via NVD
CVE-2026-94149Medium· 4.3PoC
1w ago

A vulnerability was identified in Omega Solution HRM OS up to 20260717

A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of the file /role-permission/permission of the component Role Permission Retrieval Endpoint. Such manipulation of the arg…

▾ TwilightOmega Solution · HRM OSEPSS 0.38%via NVD
CVE-2026-15801High· 8.0⚖ disputed
1w ago

A vulnerability was found in CRI-O related to the container checkpoint and restore feature

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with suffic…

▾ TwilightRed Hat · cri-oEPSS 0.32%via NVD
CVE-2026-94148Medium· 5.3PoC
1w ago

A vulnerability was determined in ScadaBR up to 1.1

A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. T…

▾ TwilightEPSS 0.54%via NVD
CVE-2026-47321High· 7.5
1w ago

The CompressionFilter class uses ZLib to deflate and inflate data sent and received

The CompressionFilter class uses ZLib to deflate and inflate data sent and received. When we inflate incoming data, the filter does not control the resulting size, and create a buffer no matter what. Some compressed data may have a comp…

▾ TwilightApache Software Foundation · org.apache.mina:mina-filter-compressionEPSS 0.49%via NVD
CVE-2026-94218Low· 3.1
1w ago

A flaw was found in the authentication session management of Keycloak, an identity and access management solution

A flaw was found in the authentication session management of Keycloak, an identity and access management solution. The issue occurs when an administrator enforces a stronger authentication flow, such as mandatory two-factor authenticatio…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.31%via NVD
CVE-2026-94217Low· 3.5
1w ago

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak

A flaw was found in the User-Managed Access (UMA) implementation of Keycloak. The issue occurs in the authorization token endpoint when processing permission tickets. If two different users own resources with the same name, the system in…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.24%via NVD
CVE-2026-94146High· 8.8
1w ago

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3

A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in writ…

▾ TwilightBioStar · BIOS Update UtilityEPSS 0.18%via NVD
CVE-2026-94145Low· 3.5PoC
1w ago

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0

A vulnerability has been found in xuxueli xxl-job up to 3.4.2/3.5.0. This vulnerability affects unknown code of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobInfoController.java of the component Task Manag…

▾ Twilightxuxueli · xxl-jobEPSS 0.33%via NVD
CVE-2026-94144High· 7.3PoC
1w ago

A flaw has been found in drogonframework drogon up to 1.9.13

A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the library orm_lib/src/Criteria.cc of the component ORM. Executing a manipulation of the argument filter can lead to sql injection. …

▾ Midnightdrogonframework · drogonEPSS 0.43%via NVD
CVE-2026-90860High· 7.1
1w ago

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView

The Canva Mobile App for HarmonyOS before v1.15.1 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

▾ TwilightCanva · CanvaEPSS 0.30%via NVD
CVEs tagged “nvd” — page 103 · VulnSea