VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25569 CVEsRSS

CVE-2026-93308Medium· 4.3PoC
1w ago

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of the component VES Collector. Performing a manipulation results in allocation of resources. The attack may be initiate…

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.52%via NVD
CVE-2026-93451Medium· 6.5
1w ago

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allocate output arrays by dividing uncompressed length by element size but pass the undivided length to native code. Atta…

▾ Sunlitxerial · snappy-javaEPSS 0.50%via NVD
CVE-2026-93450High· 7.5PoC
1w ago

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit

go-openapi/swag jsonutils before 0.27.1 contains a stack overflow vulnerability in ordered JSON parsing and serialization due to unbounded recursion with no depth limit. Remote unauthenticated attackers can submit deeply nested JSON docu…

▾ Midnightgo-openapi · swagEPSS 0.92%via NVD
CVE-2026-62874Critical· 10.0
1w ago

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

Insufficient verification of data authenticity in Azure Billing allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure BillingEPSS 0.43%via NVD
CVE-2026-85878Critical· 9.9
1w ago

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

Improper authorization in Azure Database for PostgreSQL allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_horizondbEPSS 0.78%via NVD
CVE-2026-83946High· 8.2
1w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · azure_portalEPSS 0.32%via NVD
CVE-2026-69843Critical· 10.0
1w ago

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · fabricEPSS 0.90%via NVD
CVE-2026-93454Medium· 5.4PoC
1w ago

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms end…

▾ TwilightWebkul · Aureus ERPEPSS 0.30%via NVD
CVE-2026-85887High· 7.7
1w ago

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

▾ Twilightmicrosoft · 365_copilotvia NVD
CVE-2026-93453High· 8.3PoC
1w ago

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains

SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing unauthenticated attackers to redirect recovery tokens to attacker-controlled domains. Attackers can submit password re…

▾ MidnightAlinto · SOGoEPSS 0.49%via NVD
CVE-2026-93452High· 7.5PoC
1w ago

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer

snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in Snappy.compress(ByteBuffer, ByteBuffer) that writes past the end of the destination buffer. Attackers can supply incompressible data that exceeds the destination bu…

▾ Midnightxerial · snappy-javaEPSS 0.68%via NVD
CVE-2026-2585Medium· 6.4
1w ago

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping

The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ parameter in all versions up to, and including, 2.8.14 due to insufficient input sanitization and output escaping. This m…

▾ Sunlitthemefusecom · Brizy – Page BuilderEPSS 0.26%via NVD
CVE-2026-18441Medium· 4.3
1w ago

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missi…

The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.6.9 via the set_customer_object due to missi…

▾ Sunlitlatepoint · Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPressEPSS 0.24%via NVD
CVE-2026-93309Medium· 4.3PoC
1w ago

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10

A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of the component VES Collector. Executing a manipulation can lead to allocation of resources. The attack may be launched …

▾ TwilightO-RAN-SC · SMO OAMEPSS 0.52%via NVD
CVE-2026-54147Medium· 6.5
1w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest ignores its configured algorithm parameter and verifies every Digest response wit…

▾ Sunlithttp4k · http4kEPSS 0.26%via NVD
CVE-2026-54148High· 8.1
1w ago

http4k is a functional toolkit for Kotlin HTTP applications

http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the …

▾ Twilighthttp4k · http4kEPSS 0.58%via NVD
CVE-2026-87886High· 7.8CISA KEV0dayPoC
1w ago

Local privilege escalation due to insecure file permissions

Local privilege escalation due to insecure file permissions. The following products are affected: Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021, Acronis Backup extension for Plesk (Linux) before build 1.8.11.638,…

▾ Abyssalacronis · acronis_backupEPSS 0.23%via NVD
CVE-2026-87701Critical· 9.6
1w ago

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Cosmos DBEPSS 0.79%via NVD
CVE-2026-85917High· 7.5
1w ago

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Server-side request forgery (ssrf) in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

▾ Twilightmicrosoft · foundryEPSS 0.97%via NVD
CVE-2026-85889Critical· 10.0
1w ago

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_ai_foundryEPSS 0.67%via NVD
CVE-2026-85885Critical· 9.9
1w ago

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · 365_copilotEPSS 0.72%via NVD
CVE-2026-83944Critical· 10.0
1w ago

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_logic_appsEPSS 0.44%via NVD
CVE-2026-78501High· 7.4
1w ago

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

▾ TwilightMicrosoft · Microsoft 365 Copilot's Business ChatEPSS 0.89%via NVD
CVE-2026-77903Critical· 9.0
1w ago

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · dataverseEPSS 0.37%via NVD
CVE-2026-70200Critical· 10.0
1w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_logic_appsEPSS 0.60%via NVD
CVE-2026-70009Critical· 9.3
1w ago

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

▾ Midnightmicrosoft · azure_arcEPSS 0.53%via NVD
CVE-2026-69865Critical· 10.0
1w ago

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.

▾ MidnightMicrosoft · Azure Container RegistryEPSS 0.81%via NVD
CVE-2026-69399Critical· 10.0
1w ago

Azure Arc Elevation of Privilege Vulnerability

Azure Arc Elevation of Privilege Vulnerability

▾ Midnightmicrosoft · azure_arcEPSS 0.48%via NVD
CVE-2026-68791High· 8.6
1w ago

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

▾ Twilightmicrosoft · azure_machine_learningEPSS 0.54%via NVD
CVE-2026-65323None
1w ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVEs tagged “nvd” — page 132 · VulnSea