VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25555 CVEsRSS

CVE-2026-40533Medium· 5.3
1w ago

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.

An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.

▾ SunlitSynology · DiskStation Manager (DSM)EPSS 0.38%via NVD
CVE-2026-40539High· 7.1
1w ago

An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct de…

An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct de…

▾ TwilightSynology · DiskStation Manager (DSM)EPSS 0.12%via NVD
CVE-2026-40536Medium· 4.3
1w ago

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users t…

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users t…

▾ SunlitSynology · DiskStation Manager (DSM)EPSS 0.42%via NVD
CVE-2026-93494High· 7.5
1w ago

A flaw was found in Netty's StompSubframeDecoder component

A flaw was found in Netty's StompSubframeDecoder component. A remote attacker can exploit this vulnerability by sending a specially crafted STOMP frame body without its terminating null byte. This causes the decoder to allocate a ByteBuf…

▾ TwilightRed Hat · netty-codec-stompEPSS 0.58%via NVD
CVE-2026-93493Medium· 5.9
1w ago

A flaw was found in Netty's `netty-handler-ssl-ocsp` component

A flaw was found in Netty's `netty-handler-ssl-ocsp` component. A remote attacker can exploit this vulnerability by providing an Online Certificate Status Protocol (OCSP) response that omits the optional `nextUpdate` field. This omission…

▾ SunlitRed Hat · netty-handler-ssl-ocspEPSS 0.28%via NVD
CVE-2026-92622Medium· 6.4
1w ago

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping

The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lightbox_class' Shortcode Attribute in all versions up to, and including, 3.3.8 due to insufficient input sanitization and output escaping. Th…

▾ Sunlitwpchill · Strong TestimonialsEPSS 0.33%via NVD
CVE-2026-92554Medium· 6.1
1w ago

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all versions up to, and including, 3.5.1 due to insufficien…

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query-String Parameter Name in all versions up to, and including, 3.5.1 due to insufficien…

▾ Sunlitdevitemsllc · ShopLentor – All-in-One WooCommerce Growth & Store Enhancement PluginEPSS 0.37%via NVD
CVE-2026-92249Medium· 6.1
1w ago

The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping

The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 1.11 due to insufficient input sanitization and output escaping. This makes it p…

▾ Sunlitqodeinteractive · Qi Addons For ElementorEPSS 0.37%via NVD
CVE-2026-90981Medium· 6.1
1w ago

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output…

The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nn' parameter in all versions up to, and including, 9.3.8 due to insufficient input sanitization and output…

▾ Sunlitsatollo · Newsletter – Send awesome emails from WordPressEPSS 0.38%via NVD
CVE-2026-85705High· 7.5
1w ago

The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter …

The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude' REST API Parameters in all versions up to, and including, 2.3.38 due to insufficient escaping on the user supplied parameter …

▾ TwilightAyeCode Ltd · Location ManagerEPSS 0.46%via NVD
CVE-2026-85652Medium· 6.5
1w ago

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injection via 'album_id' Shortcode Attribute in all versions up to, and including, 1.8.44 due to insufficient escaping on the…

▾ Sunlit10web · Photo Gallery by 10Web – Mobile-Friendly Image GalleryEPSS 0.55%via NVD
CVE-2026-75961Medium· 4.9
1w ago

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user su…

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the 'additional_params' parameter in all versions up to, and including, 9.3.0 due to insufficient escaping on the user su…

▾ Sunlitwebaways · NEX-Forms – Ultimate Forms Plugin for WordPressEPSS 0.51%via NVD
CVE-2026-75157High· 7.5PoC
1w ago

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`

Apache Airflow's asset queued-events DELETE endpoints checked the caller's Dag-axis permission with `READ` instead of `EDIT`. Any authenticated user who could read a Dag could therefore delete that Dag's queued asset events, silently sup…

▾ MidnightApache Software Foundation · apache-airflowEPSS 0.44%via NVD
CVE-2026-67103High· 7.6
1w ago

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover…

HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which could allow an attacker to inject unsanitized malicious scripts that execute in a victim's browser, enabling session hijacking, account takeover…

▾ TwilightHCL Software · HCL BigFix Service ManagementEPSS 0.28%via NVD
CVE-2026-67102High· 8.1
1w ago

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

HCL BigFix Service Management is affected by a high-severity Broken Access Control vulnerability, which could allow a low-privileged user to gain unauthorized access to administrative screens and functions reserved for higher-privileged …

▾ TwilightHCL Software · HCL BigFix Service ManagementEPSS 0.35%via NVD
CVE-2026-67101Critical· 9.3
1w ago

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

HCL BigFix Service Management is affected by a Server-Side Request Forgery (SSRF) vulnerability in its search functionality, which could allow an attacker to force the application server to send requests to internal systems that are not …

▾ MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.34%via NVD
CVE-2026-67100Critical· 9.8
1w ago

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities

HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerabilities. which could allow an authenticated attacker to inject database commands to extract sensitive system details, as well a…

▾ MidnightHCL Software · HCL BigFix Service ManagementEPSS 0.47%via NVD
CVE-2026-18442High· 7.5
1w ago

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escap…

The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'wcfmmp_user_location_lng' parameter in all versions up to, and including, 3.8.2 due to insufficient escap…

▾ Twilightwclovers · WCFM Marketplace – Multivendor Marketplace for WooCommerceEPSS 0.50%via NVD
CVE-2026-17607Medium· 6.5
1w ago

The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1

The WP Inventory Manager plugin for WordPress is vulnerable to SQL Injection via the 'where' shortcode attribute of the [wpinventory] shortcode in versions up to, and including, 2.5.1. This is due to insufficient escaping on the user-sup…

▾ Sunlitchuck1982 · WP Inventory ManagerEPSS 0.34%via NVD
CVE-2026-17586Medium· 6.4
1w ago

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, and including, 9.118.0 due to insufficient input sanitization and output …

The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'vkExUnit_cta_img_position' Post Meta in all versions up to, and including, 9.118.0 due to insufficient input sanitization and output …

▾ Sunlitkurudrive · VK All in One Expansion UnitEPSS 0.31%via NVD
CVE-2026-16777Medium· 4.9
1w ago

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter

The Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.0 via the 'filename' parameter parameter. This makes i…

▾ Sunlitjkohlbach · Store Exporter – Export WooCommerce Products, Orders, Subscriptions, CustomersEPSS 0.66%via NVD
CVE-2026-15275High· 7.5
1w ago

The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied par…

The WP Multi Store Locator Pro plugin for WordPress is vulnerable to generic SQL Injection via the 'store_locatore_search_radius' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied par…

▾ Twilightwpexpertsio · WP Multi Store Locator ProEPSS 0.37%via NVD
CVE-2026-15004Medium· 5.4
1w ago

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and out…

The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image alt text in all versions up to, and including, 6.5.6 due to insufficient input sanitization and out…

▾ Sunlitninjateam · FileBird – WordPress Media Library Folders & File ManagerEPSS 0.24%via NVD
CVE-2026-14472Medium· 6.4
1w ago

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping

The Kubio AI Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via kubio/copyright Block Content in all versions up to, and including, 2.8.4 due to insufficient input sanitization and output escaping. This ma…

▾ Sunlitextendthemes · Kubio AI Page BuilderEPSS 0.26%via NVD
CVE-2026-14323High· 7.5
1w ago

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.8.5 via the 'mockups' parameter. This makes it possible for unauthenticated att…

▾ Twilightprintcart · Printcart Store – Web to Print Product Designer for WooCommerceEPSS 0.94%via NVD
CVE-2026-13471Medium· 4.3
1w ago

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to …

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.3 via the LatePointAbilityDeleteBooking::execute due to …

▾ Sunlitlatepoint · Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressEPSS 0.33%via NVD
CVE-2026-12954High· 8.8
1w ago

The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function

The Mapster WP Maps plugin for WordPress is vulnerable to Arbitrary User Meta Write in all versions up to, and including, 1.23.0 via the `my_profile_update()` function. This is due to the function performing no nonce verification, no cap…

▾ Twilightmapster · Mapster WP MapsEPSS 0.46%via NVD
CVE-2026-12739Medium· 4.3
1w ago

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is author…

▾ Sunlitsaadiqbal · WP Easy Pay – Payment and Donation Form Builder for SquareEPSS 0.34%via NVD
CVE-2026-12384High· 8.8
1w ago

Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early ab…

Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early ab…

▾ TwilightTECHIN2B · TECHIN2B ApplicationEPSS 0.31%via NVD
CVE-2026-11757Medium· 6.1
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in KA Informatics Technologies Ltd. Co. Bar Association Website allows Reflected XSS. This issue affects Bar Association Website: through…

▾ SunlitKA Informatics Technologies Ltd. Co. · Bar Association WebsiteEPSS 0.18%via NVD
CVEs tagged “nvd” — page 128 · VulnSea