VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25441 CVEsRSS

CVE-2026-93989Low· 3.1
1w ago

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer()

vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in SamplingParams.update_from_tokenizer(). Attackers can supply out-of-bounds token indices that corrupt logits memory of …

▾ Sunlitvllm · vllmvia NVD
CVE-2026-93992High· 8.1PoC
1w ago

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory

Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write arbitrary files outside the extraction directory. Attackers can craft malicious archives with entries containing dir…

▾ MidnightGopeedLab · gopeedEPSS 0.91%via NVD
CVE-2026-94055Low· 3.7
1w ago

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.

▾ Sunlitexim · eximEPSS 0.29%via NVD
CVE-2026-93993High· 8.8PoC
1w ago

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation

Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes git hooks before trust validation. Attackers can supply a repository with a crafted post-checkout hook that executes…

▾ Midnightmistralai · mistral-vibeEPSS 0.77%via NVD
CVE-2026-93954Medium· 4.3PoC
1w ago

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of …

▾ Twilightgrimmory-tools · grimmoryEPSS 0.39%via NVD
CVE-2026-82672Medium· 6.3PoC
1w ago

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabli…

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on a pooled connection, enabli…

▾ Twilightelixir-mint · mintEPSS 0.52%via NVD
CVE-2026-82560High· 7.5
1w ago

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the outp…

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width. Each =over adds its indent to the margin, which wrap() subtracts from the outp…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-94000Medium· 6.6
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue occurs in the group-membership endpoints where the system fails to check if a group grants administrative privileges be…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.40%via NVD
CVE-2026-93999Medium· 4.2
1w ago

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the OIDC protocol implementation of Keycloak, an open-source identity and access management solution. The issue occurs during the token refresh process when the server restores requested audiences from stored client I…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.23%via NVD
CVE-2026-94001Medium· 6.5
1w ago

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint used for deleting user credentials does not correctly check for fine-grained reset-password permissions. This allows…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.44%via NVD
CVE-2026-93981Medium· 4.7
1w ago

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the roo…

▾ Sunlithonojs · honoEPSS 0.23%via NVD
CVE-2026-93983Medium· 5.0
1w ago

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics…

▾ SunlitOpenpanel-dev · openpanelEPSS 0.33%via NVD
CVE-2026-93982Low· 3.3PoC
1w ago

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems c…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.17%via NVD
CVE-2026-93986Low· 3.1
1w ago

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names

rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allowing path traversal sequences in object names. Attackers can craft special names containing forward slashes and parent…

▾ Sunlitrclone · rcloneEPSS 0.29%via NVD
CVE-2026-93985Critical· 9.9PoC
1w ago

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can c…

▾ AbyssalOpenpanel-dev · openpanelEPSS 0.67%via NVD
CVE-2026-93984Medium· 5.3PoC
1w ago

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitr…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.41%via NVD
CVE-2026-93987Low· 3.4PoC⚖ disputed
1w ago

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin

rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin. newVolume() in cmd/serve/docker/volume.go computes a volume's mountpoint as filepath.Join(drv.root, name) from the a…

▾ Twilightrclone · rcloneEPSS 0.15%via NVD
CVE-2026-78030Critical· 9.8
1w ago

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a mo…

▾ MidnightEPSS 0.42%via NVD
CVE-2026-5410Medium· 6.4
1w ago

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping

The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the spinner field in versions up to, and including, 4.5.13 This is due to insufficient input sanitization and output escaping. In the user_meta_sav…

▾ Sunlitdavidanderson · Redux FrameworkEPSS 0.38%via NVD
CVE-2026-8354Medium· 6.4
1w ago

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping

The Gum Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pop_tag' parameter in all versions up to, and including, 1.3.15 due to insufficient input sanitization and output escaping. This makes…

▾ Sunlitcelomitan · Gum Addon for ElementorEPSS 0.35%via NVD
CVE-2026-1255High· 7.5
1w ago

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it…

▾ Twilightysinnovations · YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & SubscribersEPSS 0.29%via NVD
CVE-2026-9289Medium· 5.3
1w ago

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.54.10 via the JSON-LD REST API endpoints. This is due to the plugin registering the /word…

▾ Sunlitwordlift · WordLift – AI powered SEO – SchemaEPSS 0.62%via NVD
CVE-2026-18346Medium· 5.3
1w ago

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1

The TikTok plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible fo…

▾ Sunlittiktokbusinessplugin · TikTokEPSS 0.26%via NVD
CVE-2026-1256Medium· 6.4
1w ago

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management action…

The YS LeadGen plugin for WordPress is vulnerable to authorization bypass and Stored Cross-Site Scripting via multiple AJAX endpoints in all versions up to, and including, 2.1.4 due to missing capability checks on popup management action…

▾ Sunlitysinnovations · YS LeadGen – Popup Builder, Popup Maker & Form Builder for WordPress | Lead Generation, Email Marketing, Sales, Conversions, Opt-Ins & SubscribersEPSS 0.20%via NVD
CVE-2026-9858Medium· 4.3
1w ago

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions

The Partial Shipment for Woocommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.4 via the wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped AJAX actions. This is d…

▾ Sunlitwpexpertshub · Partial Shipment for WooCommerceEPSS 0.35%via NVD
CVE-2026-9766Medium· 4.3
1w ago

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1

The Empik for Woocommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

▾ Sunlitempik · Empik for WoocommerceEPSS 0.40%via NVD
CVE-2026-76579Medium· 4.7
1w ago

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping

The LiteSpeed Cache plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'esi' parameter in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping. This makes it possible…

▾ Sunlitlitespeedtech · LiteSpeed CacheEPSS 0.38%via NVD
CVE-2026-9613Medium· 4.3
1w ago

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65

The Datalogics Ecommerce Delivery – Datalogics plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.65. This is due to the plugin not properly verifying that a user is authorized to perform…

▾ Sunlitdatalogics · Datalogics Ecommerce Delivery – DatalogicsEPSS 0.60%via NVD
CVE-2026-93742Critical· 9.9PoC
1w ago

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack can be init…

▾ AbyssalTotolink · A3002MUEPSS 2.3%via NVD
CVE-2026-11608Medium· 6.1
1w ago

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping

The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpcr3_fname' parameter in all versions up to, and including, 3.7.8 due to insufficient input sanitization and output escaping. This mak…

▾ Sunlitbompus · WP Customer ReviewsEPSS 0.33%via NVD
CVEs tagged “nvd” — page 109 · VulnSea