VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25129 CVEsRSS

CVE-2026-100521Medium· 6.1
yesterday

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping

Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in the search plugin highlight parameter that performs no HTML or JavaScript escaping. Attackers can craft malicious links with injected JavaScript in the high…

▾ SunlitCotonti · CotontiEPSS 0.20%via NVD
CVE-2026-100520High· 8.8
yesterday

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory

Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory tra…

▾ Twilightcrivion · LaranodeEPSS 0.94%via NVD
CVE-2026-100505Medium· 4.4
yesterday

Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length

Ghidra versions 11.2 through 12.1.4 contain a heap out-of-bounds read vulnerability in StringManager::getCodepoint when decoding multi-byte UTF-8, UTF-16, or UTF-32 characters without validating remaining buffer length. Attackers can cra…

▾ SunlitNationalSecurityAgency · ghidraEPSS 0.12%via NVD
CVE-2026-100504High· 7.0
yesterday

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code

Ghidra versions through 12.1.4 contain a stack-based out-of-bounds write vulnerability in the decompiler's leftshift128 function when processing negative shift amounts from p-code. Attackers can craft malicious binaries with specific ins…

▾ TwilightNationalSecurityAgency · ghidraEPSS 0.13%via NVD
CVE-2026-100503Low· 3.3
yesterday

Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references

Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter function caused by stale INDIRECT effect-op references. Attackers can craft a malicious binary with a specific x86-64 …

▾ SunlitNationalSecurityAgency · ghidraEPSS 0.12%via NVD
CVE-2026-96795High· 8.8
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Pyt…

▾ Twilighthorilla · horilla-hrEPSS 0.30%via NVD
CVE-2026-86066Medium· 5.9
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-reque…

▾ Sunlithorilla · horilla-hrEPSS 0.20%via NVD
CVE-2026-57449High· 7.1
2d ago

Actual is a local-first personal finance tool

Actual is a local-first personal finance tool. Prior to 26.7.0, Actual Sync Server's CORS proxy is intended to let authenticated users fetch resources only from repositories listed in the official plugin allowlist. When `ACTUAL_GITHUB_TO…

▾ Twilightactualbudget · actualEPSS 0.21%via NVD
CVE-2026-9655None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-9652None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-88003High· 7.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane fails to revoke administrative privileges after a role downgrade because Admin_Controller trusts the user_ty…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.30%via NVD
CVE-2026-7800None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-7799None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-71483High· 8.5
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft …

▾ Twilighthorilla · horilla-hrEPSS 0.27%via NVD
CVE-2026-63432Medium· 6.5
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at /recruitment/get-mail-preview/ and /…

▾ Sunlithorilla · horilla-hrEPSS 0.32%via NVD
CVE-2026-63431Medium· 6.5
2d ago

Horilla is an HR and CRM software

Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records sel…

▾ Sunlithorilla · horilla-hrEPSS 0.21%via NVD
CVE-2026-53973None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-53972None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-53971None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-49118None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-49117None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45241None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45240None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45239None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45238None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45237None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45236None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45235None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-45234None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-100502Medium· 5.0
2d ago

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters

Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. At…

▾ Sunlitpawelmalak · flameEPSS 0.29%via NVD
CVEs tagged “nvd” — page 13 · VulnSea