VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25452 CVEsRSS

CVE-2026-84084High· 8.8
1w ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.25%via NVD
CVE-2026-84083High· 7.8
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance

IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argumen…

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.15%via NVD
CVE-2026-84082Critical· 9.8
1w ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.67%via NVD
CVE-2026-84081High· 8.1
1w ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to improper certificate validation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.31%via NVD
CVE-2026-84078Critical· 9.9
1w ago

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet

IBM Guardium Data Protection 12.2 is vulnerable to a missing authentication vulnerability in the LoadBalancerServlet. An unauthenticated user can access privileged load-balancer operations, potentially resulting in unauthorized actions a…

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.47%via NVD
CVE-2026-84077High· 8.1
1w ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.26%via NVD
CVE-2026-84076High· 7.6
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.41%via NVD
CVE-2026-84075Critical· 9.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to missing authentication for the ChangeTrackerServlet.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.59%via NVD
CVE-2026-84074High· 8.9
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of input during web page generation.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.52%via NVD
CVE-2026-84073Critical· 9.1
1w ago

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL commands due to improper neutralization of special elements used in an SQL command.

▾ MidnightIBM · Guardium Data ProtectionEPSS 0.43%via NVD
CVE-2026-76902Medium· 5.0
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, ShiroFilter configures /attachment/preview/{id} and /pic/preview/{id} as anonymous, and both routes call Att…

▾ Sunlit1Panel-dev · CordysCRMEPSS 0.27%via NVD
CVE-2026-76901Medium· 5.8
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.4, GET /pool/lead/get/{id} in PoolClueController.get and GET /pool/account/get/{id} in PoolCustomerController.g…

▾ Sunlit1Panel-dev · CordysCRMEPSS 0.40%via NVD
CVE-2026-76900Medium· 6.8PoC
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. In version 1.7.3, ApprovalResourceService.sendWebHook reads WebHookConfig.webHookUrl from stored approval-node configuration…

▾ Twilight1Panel-dev · CordysCRMEPSS 0.50%via NVD
CVE-2026-76899Medium· 5.7
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. From 1.7.0 until 1.7.4, POST /account-pool/page allows an authenticated caller with MODULE_SETTING_UPDATE to place an arbitr…

▾ Sunlit1Panel-dev · CordysCRMEPSS 0.40%via NVD
CVE-2026-63647Critical· 9.3PoC
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, SseController exposes the anonymous /sse/subscribe, /sse/broadcast, and /sse/close endpoints because ShiroFi…

▾ Abyssal1Panel-dev · CordysCRMEPSS 0.50%via NVD
CVE-2026-63646Medium· 6.9PoC
1w ago

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment

CordysCRM is an open source AI-powered customer relationship management system that supports private deployment. Prior to 1.7.2, GET /mcp/form/config/{formKey} calls McpController.getMcpField without authentication because ShiroFilter.ad…

▾ Twilight1Panel-dev · CordysCRMEPSS 0.66%via NVD
CVE-2026-61822Medium· 6.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance() handles exceptions outside the loop that processes rows from part_config, so an exception for one partition set immedia…

▾ Sunlitpgpartman · pg_partmanEPSS 0.53%via NVD
CVE-2026-61821High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, drop_partition_id() and drop_partition_time() use part_config.retention_schema as the target for ALTER TABLE SET SCHEMA and accept any no…

▾ Twilightpgpartman · pg_partmanEPSS 0.38%via NVD
CVE-2026-61820High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_template_properties() manually surrounds primary-key column names from pg_attribute.attname with double quotes without escaping e…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61819High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verb…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61818High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_partition() reads part_config.time_encoder as unrestricted text and interpolates it without identifier quoting into a dynamically ex…

▾ Twilightpgpartman · pg_partmanEPSS 0.51%via NVD
CVE-2026-61817High· 8.5
1w ago

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID

pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_maintenance(), show_partitions(), show_partition_info(), undo_partition(), and partition_data_time() interpolate the writable part_co…

▾ Twilightpgpartman · pg_partmanEPSS 0.73%via NVD
CVE-2026-61723Medium· 6.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned expression cues * 4 + cbsize without checking whether the multiplication …

▾ SunlitFluidSynth · fluidsynthEPSS 0.18%via NVD
CVE-2026-61722Medium· 6.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that …

▾ SunlitFluidSynth · fluidsynthEPSS 0.20%via NVD
CVE-2026-61721High· 8.0
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_valid…

▾ TwilightFluidSynth · fluidsynthEPSS 0.19%via NVD
CVE-2026-61720Medium· 6.2
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A cr…

▾ SunlitFluidSynth · fluidsynthEPSS 0.18%via NVD
CVE-2026-61714High· 7.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap…

▾ TwilightFluidSynth · fluidsynthEPSS 0.18%via NVD
CVE-2026-58264Critical· 9.8
1w ago

FluidSynth is a software synthesizer based on the SoundFont 2 specifications

FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied valu…

▾ MidnightFluidSynth · fluidsynthEPSS 0.80%via NVD
CVE-2026-57226Low· 3.7
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, HTTP SWF decompression with the non-default swf-decompression feature and an unsafe decompre…

▾ Sunlitoisf · suricatavia NVD
CVE-2026-57224Medium· 6.5
1w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the DHCP parser in rust/src/dhcp/dhcp.rs creates stateless transactions without recording their…

▾ Sunlitoisf · suricatavia NVD
CVEs tagged “nvd” — page 114 · VulnSea