VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25576 CVEsRSS

CVE-2026-68523High· 7.5
1w ago

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants

`fulgur` converts untrusted HTML/CSS into PDF, commonly on a server that processes input supplied by many tenants. In versions prior to 0.19.0, a body-direct child whose CSS-resolved height greatly exceeds the page height was sliced into…

▾ Twilightfulgur-rs · fulgurEPSS 0.61%via NVD
CVE-2026-92992Medium· 6.3PoC
1w ago

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5

A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authoriza…

▾ TwilightDromara · mayfly-goEPSS 0.39%via NVD
CVE-2026-92230High· 7.5
1w ago

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, updat…

▾ TwilightApache Software Foundation · Apache KarafEPSS 0.49%via NVD
CVE-2026-90997High· 7.4
1w ago

A flaw was found in Keycloak

A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vuln…

▾ TwilightKeycloak · keycloak-servicesEPSS 0.40%via NVD
CVE-2026-54649Low· 2.1
1w ago

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox

punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Prior to 1.5.0, handleInbound delivers inbound alias mail with message.forward(), which silently drops the added Reply-…

▾ SunlitPunchIn-App · punchin-emailEPSS 0.84%via NVD
CVE-2026-54571High· 8.7
1w ago

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350

ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3.11.1, the multipart/form-data parser in src/WebRequest.cpp stores _boundaryPosition as an 8-bit value while _parseMu…

▾ TwilightESP32Async · ESPAsyncWebServerEPSS 0.52%via NVD
CVE-2026-54524High· 7.1
1w ago

Frappe HR is an open-source human resources management solution (HRMS)

Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the HR User role can inject SQL through filters in the Salary Payments Based on Payment Mode report. In hrms/payroll/repo…

▾ Twilightfrappe · hrmsEPSS 0.48%via NVD
CVE-2026-54253High· 8.2PoC
1w ago

TS3 Manager is modern web interface for maintaining Teamspeak3 servers

TS3 Manager is modern web interface for maintaining Teamspeak3 servers. Prior to 2.2.6, the /api/download handler in packages/server/routes/api.js passes the attacker-controlled port query parameter to socket.connect(port, host) and retu…

▾ Midnightjoni1802 · ts3-managerEPSS 0.28%via NVD
CVE-2026-54239High· 8.8
1w ago

Faust.js is a headless WordPress toolkit

Faust.js is a headless WordPress toolkit. Prior to 1.8.11, the FaustWP WordPress plugin authenticates only the ciphertext in its token envelope and excludes the 16-byte initialization vector from the HMAC in WPE\FaustWP\Auth\encrypt() an…

▾ Twilightwpengine · faustjsEPSS 0.32%via NVD
CVE-2026-52852Medium· 6.5PoC
1w ago

Traccar is an open source GPS tracking system

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups and request reports can create a cyclic group-parent hierarchy and request a trips or stops report for a device in tha…

▾ Twilighttraccar · traccarEPSS 0.53%via NVD
CVE-2026-52851High· 7.1PoC
1w ago

Traccar is an open source GPS tracking system

Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated, non-readonly user with access to an object usable in a permission pair can submit DELETE /api/permissions with an extra attacker-controlled JSON key. Permi…

▾ Midnighttraccar · traccarEPSS 0.39%via NVD
CVE-2026-52727High· 7.2
1w ago

lxc-ci contains continuous integration and image-build scripts for LXC

lxc-ci contains continuous integration and image-build scripts for LXC. Prior to the 2026-05-28 Arch Linux image publication, images built from images/archlinux.yaml retain the same pacman local-signing private key in /etc/pacman.d/gnupg…

▾ Twilightlxc · lxc-ciEPSS 0.59%via NVD
CVE-2026-19477High· 7.8
1w ago

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution

There is stack-based buffer overflow vulnerability recently discovered in MCC Universal Library for Linux (uldaq).  This may result in information disclosure or arbitrary code execution. This vulnerability affects MCC Universal Library f…

▾ TwilightMCC · Universal Library for Linux (uldaq)via NVD
CVE-2026-92927Medium· 5.3PoC
1w ago

A vulnerability was found in SourceCodester Drug Recommendation System 1.0

A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing of the file /db/drug_recommendor.sql. Performing a manipulation results in information disclosure. The attack is possi…

▾ TwilightSourceCodester · Drug Recommendation SystemEPSS 0.53%via NVD
CVE-2026-92926High· 7.3PoC
1w ago

A vulnerability has been found in code-projects Matrimonial System 1.0

A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the function writepartnerprefs of the file /partner_preference.php. Such manipulation of the argument education leads to sql injection. Th…

▾ Midnightcode-projects · Matrimonial SystemEPSS 0.43%via NVD
CVE-2026-89038Medium· 6.2PoC
1w ago

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co-resident malicious applications to write attacker-controlled bytes outside the intended staging directory by supplyi…

▾ TwilightVerizon · com.vcast.mediamanagerEPSS 0.19%via NVD
CVE-2026-44236High· 7.1PoC
1w ago

rabbitmq-c is a C-language AMQP client library for RabbitMQ

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized connection.tune.frame_max value during amqp_login(), and rabbitmq-c accepts the value in amqp_login_inner() in l…

▾ Midnightalanxz · rabbitmq-cEPSS 0.48%via NVD
CVE-2026-54551Medium· 4.3
1w ago

WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management

WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.3.0, the authenticated GET /api/v0/ws statistics WebSocket in internal/app/api/v0/handlers/endpoint_websocket.go subs…

▾ Sunlith44z · wg-portalEPSS 0.36%via NVD
CVE-2026-44235Medium· 6.5PoC
1w ago

rabbitmq-c is a C-language AMQP client library for RabbitMQ

rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an undersized HEADER or METHOD frame during client login and cause unsigned size_t underflow in amqp_handle_input() in librabb…

▾ Twilightalanxz · rabbitmq-cEPSS 0.36%via NVD
CVE-2026-54053Critical· 9.6
1w ago

Many Notes is a Markdown note-taking web application designed for simplicity

Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segme…

▾ Midnightbrufdev · many-notesEPSS 0.70%via NVD
CVE-2026-54677Medium· 6.5
1w ago

Scoold is a Q&A and a knowledge sharing platform for teams

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of a private space can create content in questions belonging to that space because src/main/java/com/erudika/scoold/cont…

▾ SunlitErudika · scooldEPSS 0.38%via NVD
CVE-2026-54676Medium· 6.5
1w ago

Scoold is a Q&A and a knowledge sharing platform for teams

Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve replies from questions in private spaces they cannot access because src/main/java/com/erudika/scoold/api/ApiControll…

▾ SunlitErudika · scooldEPSS 0.40%via NVD
CVE-2026-52836High· 8.7
1w ago

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS)

OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior to 3.34.0, a network attacker can crash a reachable OpenDDS participant by sending a malformed RTPS UDP submessage w…

▾ TwilightOpenDDS · OpenDDSEPSS 0.74%via NVD
CVE-2026-93296Medium· 5.1
1w ago

MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views

MISP contains a stored cross-site scripting (XSS) vulnerability in the Overmind theme's statistics views. The event General card and the server/feed preview card constructed donut chart legend labels by directly concatenating object name…

▾ Sunlitmisp · mispEPSS 0.39%via NVD
CVE-2026-9314None
1w ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-93295High· 8.7
1w ago

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user

MISP contains a vulnerability in its background job dispatch mechanism that allows remote code execution as the web user. Background job arguments are passed directly as the argv of the CakePHP console process. CakePHP's ShellDispatcher:…

▾ Twilightmisp · mispEPSS 0.64%via NVD
CVE-2026-93292High· 8.5PoC
1w ago

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attac…

▾ MidnightSigNoz · signozEPSS 0.40%via NVD
CVE-2026-8674Medium· 5.3
1w ago

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assert…

▾ SunlitThe GNU C Library · glibcEPSS 0.34%via NVD
CVE-2026-85716Low· 3.7
1w ago

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses

The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, processScramAuthenticationInfo and processAuthenticationInfo compute the SCRAM…

▾ SunlitAsyncHttpClient · async-http-clientEPSS 0.41%via NVD
CVE-2026-54587Medium· 5.8
1w ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local a…

▾ SunlitMidnightBSD · mportEPSS 0.10%via NVD
CVEs tagged “nvd” — page 137 · VulnSea