VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25576 CVEsRSS

CVE-2026-50275High· 7.5
1w ago

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP

The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddtrace_deserialize_baggage in ext/distributed_tracing_headers.c parses incoming W3C baggage HTTP headers without enforc…

▾ TwilightDataDog · dd-trace-phpEPSS 0.68%via NVD
CVE-2026-50022Medium· 5.8
1w ago

Metacat is data repository software that helps researchers preserve, share, and discover data

Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSolrIndex.query forwards the client-controlled qt parameter through Apache SolrJ from search endpoints such as /d1/mn/v…

▾ SunlitNCEAS · metacatEPSS 0.40%via NVD
CVE-2026-54460Critical· 9.8
1w ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1.1, POST /api/auth/passkeys accepts a request-body userId and attacker-supplied passkey without an authenticated sess…

▾ Midnightopen-reception · appointment-booking-softwareEPSS 0.70%via NVD
CVE-2026-45143Critical· 9.0
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private Message.content without server-side sanitization and renders it as HTML in assets/vue/views/message/MessageShow.vue a…

▾ Midnightchamilo · chamilo-lmsEPSS 0.49%via NVD
CVE-2021-3030Medium· 6.1PoC
1w ago

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx

Cute Editor for ASP.NET 6.4 is vulnerable to reflected cross-site scripting caused by improper validation of the Theme GET parameter in colorpicker_more.aspx. A remote, unauthenticated attacker can craft a URL that, once opened by a vict…

▾ TwilightEPSS 0.27%via NVD
CVE-2026-54501Critical· 9.4
1w ago

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance

Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Cust…

▾ Midnightwebrecorder · browsertrixEPSS 1.2%via NVD
CVE-2026-54237Critical· 9.3
1w ago

Wavelog is web-based amateur radio logging software

Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /install/includes/interface_assets/triggers.php after installation without an installation lock or permission check. Unsanit…

▾ Midnightwavelog · wavelogEPSS 0.76%via NVD
CVE-2026-50277High· 7.5
1w ago

dd-trace-cpp is the Datadog distributed tracing library for C++

dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggage headers without enforcing DD_TRACE_BAGGAGE_MAX_ITEMS or DD_TRACE_BAGGAGE_MAX_BYTES on the extraction path, even tho…

▾ TwilightDataDog · dd-trace-cppEPSS 0.79%via NVD
CVE-2026-54521Medium· 6.1
1w ago

FairEmail is a fully featured, open source, privacy-friendly email app for Android

FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP message renderer in app/src/main/java/eu/faircode/email/ActivityAMP.java enables JavaScript in its WebView but incom…

▾ SunlitM66B · FairEmailEPSS 0.33%via NVD
CVE-2025-55787Critical· 9.8
1w ago

In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.

In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.

▾ MidnightEPSS 0.32%via NVD
CVE-2026-54565Medium· 4.7
1w ago

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly

rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox extension 0.2.4, the browser extensions use an all-URLs host permission to detect HWP and HWPX links on visited pages,…

▾ Sunlitedwardkim · rhwpEPSS 0.19%via NVD
CVE-2026-45140Critical· 9.8PoC
1w ago

Chamilo LMS is an open-source learning management system

Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote attacker to execute arbitrary code on the server. The authoritative advisory does not identify the affected endpoint, …

▾ Abyssalchamilo · chamilo-lmsEPSS 1.3%via NVD
CVE-2026-92757Medium· 5.5
1w ago

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.

▾ Sunlitmongodb · entity_framework_core_providerEPSS 0.07%via NVD
CVE-2026-57846None
1w ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-54752Critical· 9.6PoC
1w ago

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox

NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The validation test harness can deserialize pull-request-controlled tracked pickle cache files through pickle.load in the rea…

▾ Abyssalnetbox-community · devicetype-libraryEPSS 0.66%via NVD
CVE-2026-54716High· 7.5
1w ago

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data

Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earlier, a POST request to /sources_to_targets containing an exclude_polygons ring formed by three collinear points can ca…

▾ Twilightvalhalla · valhallaEPSS 0.46%via NVD
CVE-2026-54692High· 7.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to 1.0.0, sail_codec_load_frame_v8_xbm() in src/sail-codecs/xbm/xbm.c allocates the decoded pixel buffer using t…

▾ MidnightHappySeaFox · sailEPSS 0.19%via NVD
CVE-2026-54627Critical· 9.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, psd_private_sail_pixel_format() in src/sail-codecs/psd/helpers.c resolves a one-channel PSD in …

▾ AbyssalHappySeaFox · sailEPSS 0.78%via NVD
CVE-2026-54626Critical· 9.8PoC
1w ago

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. In 0.9.10 and earlier, the TGA_INDEXED_RLE path selected by image_type == 9 allocates an image buffer using the one-by…

▾ AbyssalHappySeaFox · sailEPSS 0.78%via NVD
CVE-2026-54618Critical· 9.4PoC
1w ago

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults

Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MC…

▾ Abyssaljimprosser · obsidian-web-mcpEPSS 0.51%via NVD
CVE-2026-54594Medium· 5.3PoC
1w ago

OmniBlocks is a monorepo for the OmniBlocks project

OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/disc.yml runs for the issues opened event and the issues edited event and invokes the createDiscussion mutation whenev…

▾ TwilightOmniBlocks · monorepoEPSS 0.45%via NVD
CVE-2026-45726High· 7.6
1w ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle…

▾ Twilightsiderolabs · omniEPSS 0.14%via NVD
CVE-2026-45723Low· 2.7
1w ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClie…

▾ Sunlitsiderolabs · omniEPSS 0.49%via NVD
CVE-2026-45720High· 7.0
1w ago

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud

Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state ope…

▾ Twilightsiderolabs · omniEPSS 0.14%via NVD
CVE-2026-92756Medium· 5.5
1w ago

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…

Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…

▾ Sunlitmongodb · entity_framework_core_providerEPSS 0.07%via NVD
CVE-2026-93337High· 7.8
1w ago

NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu propert…

NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows local users with VPN connection creation permissions to inject arbitrary pppd directives by supplying mru or mtu propert…

▾ Twilightnm-l2tp · NetworkManager-l2tpEPSS 0.20%via NVD
CVE-2026-92943High· 8.1
1w ago

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AW…

Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for Python 1.5.3 through 1.6.0 on Python 3.7 and later might allow an adversary-in-the-middle actor to impersonate the AW…

▾ TwilightAWS · AWSIoTPythonSDKEPSS 0.38%via NVD
CVE-2026-92758Medium· 5.5
1w ago

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive information (if in use) such as passwords and AWS secure access keys.

▾ Sunlitmongodb · entity_framework_core_providerEPSS 0.15%via NVD
CVE-2026-92993Medium· 6.3PoC
1w ago

A vulnerability was detected in Dromara mayfly-go up to 1.11.5

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of …

▾ TwilightDromara · mayfly-goEPSS 1.5%via NVD
CVE-2026-68537High· 7.5
1w ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

▾ Twilightfulgur-rs · fulgurEPSS 0.61%via NVD
CVEs tagged “nvd” — page 136 · VulnSea