VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25555 CVEsRSS

CVE-2026-93594High· 8.1PoC
1w ago

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 enforces its per-type/per-record access-control rules only in LocalBucket, keyed on file id. Query-execution paths that reach record data through LSM index files or th…

▾ MidnightArcadeData · arcadedbEPSS 0.44%via NVD
CVE-2026-93593High· 8.1PoC
1w ago

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets

ArcadeDB before 26.9.1 fails to enforce security-group types ACL entries for TimeSeries types because the ACL resolver builds permissions from bucket IDs, but TimeSeries types do not own normal record buckets. An authenticated low-privil…

▾ MidnightArcadeData · arcadedbEPSS 0.36%via NVD
CVE-2026-93592High· 7.5PoC
1w ago

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs

vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a nega…

▾ Midnightvllm · vllmvia NVD
CVE-2026-93598High· 7.1PoC
1w ago

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare clas…

ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1 contains an incomplete deny-list in the polyglot script sandbox: com.arcadedb.query.polyglot.HostClassLookupFilter.DENIED lists java.util.ResourceBundle as a bare clas…

▾ MidnightArcadeData · arcadedbEPSS 0.63%via NVD
CVE-2026-93597High· 7.7PoC
1w ago

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands

ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addresses in the SSRF guard used by IMPORT DATABASE and server commands. Authenticated attackers can supply URLs resolving to NAT64, 6to4, or Teredo addresses embedding RFC…

▾ MidnightArcadeData · arcadedbEPSS 0.35%via NVD
CVE-2026-93595Medium· 6.5
1w ago

ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints

ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI chat endpoints. The tool executes queries without binding the authenticated principal to DatabaseContext, causing pe…

▾ SunlitArcadeData · arcadedbEPSS 0.38%via NVD
CVE-2026-93601Low· 2.2
1w ago

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name

rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101.0 and prior to 0.103.12 and 0.104.0-alpha.6 incorrectly accepted permitted-subtree DNS name constraints for certificates asserting a wildcard name. For example, a name…

▾ Sunlitrustls · webpkiEPSS 0.18%via NVD
CVE-2026-93599High· 7.5PoC
1w ago

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs

rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.104.0-alpha.7) contains a reachable panic in bit_string_flags() in src/der.rs. The input guard fails to reject a named-bit BIT STRING whose content is exactly [0x00] (ze…

▾ Midnightrustls · webpkiEPSS 0.49%via NVD
CVE-2026-93596Medium· 4.3PoC
1w ago

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}

ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the DatabaseAsyncTransaction async worker threads used by the parallel edge-connect phase of POST /api/v1/batch/{database}. Be…

▾ TwilightArcadeData · arcadedbEPSS 0.29%via NVD
CVE-2026-93603Critical· 10.0PoC
1w ago

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.…

vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js): when sandboxed code calls a host-provided non-strict (sloppy-mode) function without a receiver — e.…

▾ Abyssalpatriksimek · vm2EPSS 0.73%via NVD
CVE-2026-93602Medium· 4.4
1w ago

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints

rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares only the first distributionPoint against each CRL's IssuingDistributionPoint, ignoring additional distributionPoints. At…

▾ Sunlitrustls · webpkiEPSS 0.21%via NVD
CVE-2026-93600Low· 2.2
1w ago

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced

rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0.104.0-alpha releases before 0.104.0-alpha.6 ignore X.509 name constraints that apply to URI names, causing such constraints to be accepted rather than enforced. Becaus…

▾ Sunlitrustls · webpkiEPSS 0.18%via NVD
CVE-2026-93606Critical· 10.0PoC
1w ago

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromis…

▾ Abyssalpatriksimek · vm2EPSS 0.71%via NVD
CVE-2026-93604High· 7.2PoC
1w ago

vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto'])

vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allowlists the crypto builtin for a NodeVM (require.builtin: ['crypto']). The builtin sanitizer (sanitizeCryptoModule in l…

▾ Midnightpatriksimek · vm2EPSS 0.34%via NVD
CVE-2026-93605Critical· 10.0
1w ago

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary co…

▾ Midnightpatriksimek · vm2EPSS 0.73%via NVD
CVE-2026-93492Medium· 5.3
1w ago

A flaw was found in Netty's HTTP/2 HpackEncoder

A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, l…

▾ SunlitRed Hat · netty-codec-http2EPSS 0.64%via NVD
CVE-2026-93491High· 7.5
1w ago

A flaw was found in Netty's HttpServerCodec

A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to gr…

▾ TwilightRed Hat · netty-codec-httpEPSS 0.87%via NVD
CVE-2026-93488High· 7.5
1w ago

A flaw was found in Netty

A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can…

▾ TwilightRed Hat · netty-codec-httpEPSS 0.70%via NVD
CVE-2026-28197High· 8.8
1w ago

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permission…

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially crafted input to a privileged administrative command, causing it to execute arbitrary code with root-level permission…

▾ TwilightCohesity · NetBackup Flex OSEPSS 0.67%via NVD
CVE-2026-21806Low· 3.1
1w ago

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability

HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows multiple simultaneous authenticated sessions for the same administrative account, which could enable an unauthorized…

▾ SunlitHCL Software · HCL BigFix Service ManagementEPSS 0.15%via NVD
CVE-2026-28198High· 8.8
1w ago

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential

An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptographic signature verification step of a privileged support command by supplying a specially formed access credential. …

▾ TwilightCohesity · NetBackup Flex OSEPSS 0.34%via NVD
CVE-2026-28199Low· 3.3
1w ago

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command

An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underlying operating system by supplying a specially crafted path argument to a diagnostic command. Successful exploitatio…

▾ SunlitCohesity · NetBackup Flex OSEPSS 0.10%via NVD
CVE-2026-93578Medium· 5.9PoC
1w ago

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client

A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate is…

▾ TwilightRed Hat · netty-handler-ssl-ocspEPSS 0.29%via NVD
CVE-2026-93575High· 7.5
1w ago

A flaw was found in Netty's MqttDecoder

A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Re…

▾ TwilightRed Hat · netty-codec-mqttEPSS 0.66%via NVD
CVE-2026-93572High· 7.5
1w ago

A flaw was found in Netty's `RedisArrayAggregator` component

A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly prealloca…

▾ TwilightRed Hat · netty-codec-redisEPSS 0.58%via NVD
CVE-2026-93563High· 7.5
1w ago

A flaw was found in Netty's `SmtpResponseDecoder` component

A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without …

▾ TwilightRed Hat · netty-codec-smtpEPSS 0.56%via NVD
CVE-2026-81627High· 8.2PoC
1w ago

A flaw was found in QEMU

A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias remains within the option ROM window. A privileged guest user on a Q35/KVM machine can position this alias over locked S…

▾ MidnightRed Hat · qemu-kvmEPSS 0.19%via NVD
CVE-2026-93561Medium· 6.5
1w ago

A flaw was found in io.netty/netty-codec-memcache

A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and `extrasLength` as signed Java types instead of unsigned, as specified by the protocol. A malicious Memcache server ca…

▾ SunlitRed Hat · netty-codec-memcacheEPSS 0.29%via NVD
CVE-2026-92976Medium· 5.1
1w ago

A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite

A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the fields containing their personal data…

▾ SunlitT-Systems · TAOEPSS 0.38%via NVD
CVE-2026-87743High· 7.5
1w ago

A flaw was found in Quarkus HTTP security

A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normalized between the security matcher and HTTP request dispatchers. This allows the attacker to craft a URL that the secu…

▾ TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.52%via NVD
CVEs tagged “nvd” — page 126 · VulnSea