VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25503 CVEsRSS

CVE-2026-81943Medium· 6.7
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain active debug functionality in the embedded software. An attacker with privileged access to the device can enable …

▾ SunlitPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.18%via NVD
CVE-2026-81944High· 7.5
1w ago

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain a stack-based buffer overflow in the web server. Insufficient bounds checking on data copied into a stack buffer …

▾ TwilightPLANET Technology Corp. · PLANET IGS-5225-8P2T4S V1EPSS 0.71%via NVD
CVE-2026-75031Critical· 9.8
1w ago

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature

In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unau…

▾ MidnightInterchange · InterchangeEPSS 0.71%via NVD
CVE-2025-14753High· 7.5
1w ago

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system

IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

▾ Twilightibm · cloud_pak_for_dataEPSS 0.46%via NVD
CVE-2026-75883Medium· 6.8
1w ago

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementi…

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementi…

▾ SunlitPPP Project · pppEPSS 0.26%via NVD
CVE-2025-53837Critical· 9.9
1w ago

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc)

XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Prior to versions 14.10.2 and 15.0 RC1, any user who can edit their own user profile o…

▾ Midnightxwiki · xwiki-renderingEPSS 0.64%via NVD
CVE-2025-14754High· 8.8
1w ago

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

▾ Twilightibm · cloud_pak_for_dataEPSS 0.44%via NVD
CVE-2026-93685Medium· 5.4
1w ago

A flaw was found in the multicluster-observability-addon

A flaw was found in the multicluster-observability-addon. A remote attacker can access a debug endpoint without authentication, due to a misconfiguration in the underlying addon-framework library. This allows for the disclosure of sensit…

▾ SunlitRed Hat · redhat-user-workloads/multicluster-observability-addon-acm-213EPSS 0.44%via NVD
CVE-2026-93573Medium· 6.5
1w ago

A flaw was found in Netty's HTTP/1.1 decoder

A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing …

▾ SunlitRed Hat · netty-codec-httpEPSS 0.58%via NVD
CVE-2026-93506Medium· 6.3
1w ago

A vulnerability was determined in SveltyCMS 0.0.6

A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/upload-media of the component File Upload Endpoint. Executing a manipulation can lead to server-side request forgery.…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-93558High· 7.5PoC
1w ago

A flaw was found in Netty's WebSocketServerExtensionHandler

A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unboun…

▾ MidnightRed Hat · netty-codec-httpEPSS 0.79%via NVD
CVE-2026-25684Medium· 4.4
1w ago

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.

▾ SunlitZscaler · ZIA File Type ControlEPSS 0.20%via NVD
CVE-2026-93565High· 7.5
1w ago

A flaw was found in Netty RtspDecoder

A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a spe…

▾ TwilightRed Hat · netty-codec-httpEPSS 0.64%via NVD
CVE-2026-93564High· 7.5
1w ago

A flaw was found in Netty

A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a D…

▾ TwilightRed Hat · netty-codec-haproxyEPSS 0.79%via NVD
CVE-2026-93505Low· 3.5PoC
1w ago

A vulnerability was found in SveltyCMS 0.0.6

A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-service.server.ts of the component SVG Media Upload. Performing a manipulation results in cross site scripting. The a…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-93657High· 7.5
1w ago

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results

hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC proof states through the Resolver::lookup() and Resolver::lookup_ip() APIs, allowing invalid records to be returned as successful results. Attackers controlling the a…

▾ Twilighthickory-dns · hickory-resolverEPSS 0.40%via NVD
CVE-2026-93566Medium· 6.5
1w ago

A flaw was found in Netty

A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker …

▾ SunlitRed Hat · netty-codec-httpEPSS 0.64%via NVD
CVE-2026-10832Medium· 5.9
1w ago

A flaw was found in the DERDecoder class within wildfly-elytron-asn1

A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaustion vulnerability by sending a specially crafted DER (Distinguished Encoding Rules) payload. The decoder attempts to…

▾ SunlitRed Hat · wildfly-elytron-asn1EPSS 0.42%via NVD
CVE-2026-93659High· 8.1PoC
1w ago

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views

Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute …

▾ Midnightconcretecms-community-store · concretecms-community-store/community_storevia NVD
CVE-2026-93658High· 7.0PoC
1w ago

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes…

▾ Midnightuutils · coreutilsEPSS 0.14%via NVD
CVE-2026-93676Low· 3.2
1w ago

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions

xdg-dbus-proxy incorrectly filters D-Bus broadcast messages, bypassing configured path, interface, and member restrictions. This allows a sandboxed Flatpak application to intercept broadcast signals on the D-Bus session bus and AT-SPI bu…

▾ SunlitRed Hat · xdg-dbus-proxyEPSS 0.14%via NVD
CVE-2026-93660Medium· 6.5
1w ago

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards

SQLBot through 1.10.1 fails to verify dashboard ownership in update_resource and update_canvas endpoints, allowing authenticated workspace members to modify other users' private dashboards. Attackers can supply arbitrary dashboard IDs to…

▾ Sunlitdataease · SQLBotEPSS 0.43%via NVD
CVE-2026-93653Medium· 5.5
1w ago

A denial of service flaw was found in Poppler's Splash backend

A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching the int32 boundary can cause SplashOutputDev::tilingPatternFill to compute an attacker-controlled repeat count that dr…

▾ SunlitRed Hat · popplerEPSS 0.15%via NVD
CVE-2026-93567High· 7.5
1w ago

A flaw was found in Netty's HTTP/2 codec

A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker …

▾ TwilightRed Hat · netty-codec-http2EPSS 0.75%via NVD
CVE-2026-77928Medium· 6.5
1w ago

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitizatio…

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary database contents by submitting the msg_id parameter as an array to bypass the clean_requests() sanitizatio…

▾ SunlitMacWarrior · clipbucket-v5EPSS 0.42%via NVD
CVE-2026-85511Medium· 4.2
1w ago

A flaw was found in EAP's Elytron

A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oauth2-introspection would allow parameter substitution due to missing URL encoding.

▾ SunlitRed Hat · eap8-activemq-artemisEPSS 0.28%via NVD
CVE-2026-77927Medium· 6.5
1w ago

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() s…

ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract arbitrary data from the database by submitting the check_photo parameter as an array to bypass the clean_requests() s…

▾ SunlitMacWarrior · clipbucket-v5EPSS 0.42%via NVD
CVE-2026-77929High· 8.8
1w ago

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint

ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote code execution by uploading a PHP file with valid image magic bytes through the photo upload endpoint. The FileUpload:…

▾ TwilightMacWarrior · clipbucket-v5EPSS 0.94%via NVD
CVE-2026-16512Low· 3.1
1w ago

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched on hdr->message_type without first checking that the received frame carries at least sizeof(struct gptp_hdr) (34) by…

▾ Sunlitzephyrproject · zephyrEPSS 0.17%via NVD
CVE-2024-56344Medium· 5.9
1w ago

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security

IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, and 12.1.0 through 12.1.3 FP1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could explo…

▾ SunlitIBM · Cognos AnalyticsEPSS 0.17%via NVD
CVEs tagged “nvd” — page 124 · VulnSea