VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25503 CVEsRSS

CVE-2026-84447High· 7.5PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_i…

▾ Midnightstrukturag · libheifEPSS 0.52%via NVD
CVE-2026-84446High· 7.5
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_…

▾ Twilightstrukturag · libheifEPSS 0.46%via NVD
CVE-2026-84444High· 7.4PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match t…

▾ Midnightstrukturag · libheifEPSS 0.48%via NVD
CVE-2026-84400Low· 3.1
1w ago

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service

CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote debugging service. An attacker on the same local network who satisfies certain device state conditions could make the …

▾ SunlitCareCam · HMT.CM2507 FirmwareEPSS 0.21%via NVD
CVE-2026-84398High· 7.5
1w ago

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service

CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An attacker with network access to the affected device could access privileged management functions and obtain device, user…

▾ TwilightCareCam · HMT.CM2507 FirmwareEPSS 0.41%via NVD
CVE-2026-84384High· 7.5PoC
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective s…

▾ Midnightstrukturag · libheifEPSS 0.52%via NVD
CVE-2026-84383Critical· 9.8PoC⚖ disputed
1w ago

libheif is a HEIF and AVIF file format decoder and encoder

libheif is a HEIF and AVIF file format decoder and encoder. From 1.22.0 until 1.23.2, a crafted HEIF, HEIC, or AVIF item graph using nested iden and auxl references can make HeifPixelImage::transfer_channel_from_image_as() append duplica…

▾ Abyssalstrukturag · libheifEPSS 0.61%via NVD
CVE-2026-81305Medium· 6.8
1w ago

CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity

CM2507 IP cameras automatically execute a predetermined script from removable media without verifying its authenticity or integrity. An attacker with physical access to the device could supply a malicious script and execute arbitrary cod…

▾ SunlitCareCam · HMT.CM2507 FirmwareEPSS 0.28%via NVD
CVE-2026-77960Medium· 5.3
1w ago

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active device across a subset of carriers that were connected to the affected MQTT broker.

▾ SunlitBransys · ELDEPSS 0.33%via NVD
CVE-2026-77568Medium· 4.2
1w ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-15747. Reason: This candidate is a duplicate of CVE-2026-15747. Notes: All CVE users should reference CVE-2026-15747 instead of this candidate.

▾ Sunlitmojolicious · mojoEPSS 0.10%via NVD
CVE-2026-68914High· 8.7
1w ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-14803. Reason: This candidate is a duplicate of CVE-2026-14803. Notes: All CVE users should reference CVE-2026-14803 instead of this candidate.

▾ Twilightmojolicious · mojoEPSS 0.26%via NVD
CVE-2026-67549High· 7.6PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so cal…

▾ MidnightAcademySoftwareFoundation · OpenImageIOEPSS 0.38%via NVD
CVE-2026-65970Medium· 5.3PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, a crafted ZIP-compressed TIFF processed with TIFF multithreading enabled can make TIFFIn…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.40%via NVD
CVE-2026-65969Medium· 5.5
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A truncated tga can leave a pending gif frame that is proce…

▾ SunlitAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-63638High· 8.3PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted cineon image can declare unsupported component bi…

▾ MidnightAcademySoftwareFoundation · OpenImageIOEPSS 0.45%via NVD
CVE-2026-63635Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A crafted psd with an invalid color_mode bypasses normal va…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.20%via NVD
CVE-2026-63422High· 7.8
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A valid tiled openexr image whose width is not a multiple o…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.19%via NVD
CVE-2026-63420Medium· 5.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, An indexed psd with transparency metadata creates fewer sto…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-63419High· 7.8PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.21.0, 3.1.16.0, and 3.2.0.3-beta1, A zbuffer-only tiled iff is exposed with a 16-bit public im…

▾ MidnightAcademySoftwareFoundation · OpenImageIOEPSS 0.19%via NVD
CVE-2026-61682Critical· 9.9
1w ago

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads

kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* i…

▾ Midnightkcp-dev · kcpEPSS 0.38%via NVD
CVE-2026-60115None
1w ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-59956Medium· 6.1PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, An uncompressed 16-bit iff image with a z-buffer makes iffi…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-59181Medium· 6.1PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted cineon file can supply a numberofelements value g…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.17%via NVD
CVE-2026-59156Medium· 6.5PoC
1w ago

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.20.0, 3.1.15.0, and 3.2.0.3-beta1, A crafted fits stream containing consecutive 2880-byte head…

▾ TwilightAcademySoftwareFoundation · OpenImageIOEPSS 0.40%via NVD
CVE-2026-1037Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the We…

▾ SunlitIBM · Common LicensingEPSS 0.20%via NVD
CVE-2026-1031Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the We…

▾ SunlitIBM · Common LicensingEPSS 0.20%via NVD
CVE-2026-1030Medium· 4.3
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data.

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 generates an error message that includes sensitive information about its environment, users, or associated data.

▾ SunlitIBM · Common LicensingEPSS 0.21%via NVD
CVE-2026-11537Medium· 4.3
1w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information about the file system through the FileTransfer servlet.

▾ SunlitIBM · WebSphere Application ServerEPSS 0.18%via NVD
CVE-2026-1029Medium· 5.4
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

▾ SunlitIBM · Common LicensingEPSS 0.16%via NVD
CVE-2026-1025Medium· 6.1
1w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the…

▾ SunlitIBM · Common LicensingEPSS 0.18%via NVD
CVEs tagged “nvd” — page 122 · VulnSea