VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25133 CVEsRSS

CVE-2026-100369High· 8.4
2d ago

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes

CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs and wrapping executable processes. `CliInvoke` versions 2.0.0 through 2.8.4, 2.9.0 through 2.9.3, 2.10.0 through 2.1…

▾ Twilightalastairlundy · CliInvokeEPSS 0.36%via NVD
CVE-2025-1218Low· 3.4
2d ago

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them

The mysqlnd wire protocol parser reads fields out of server packets before checking that the packet still holds enough bytes for them. A malicious or compromised MySQL server can send a truncated packet and make the client read past the …

▾ SunlitPHP Group · ext-mysqlndEPSS 0.18%via NVD
CVE-2025-14181Medium· 6.5PoC
2d ago

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger

The SOAP HTTP client guards its response buffer growth with a check that relies on signed integer overflow, which is undefined behaviour and is not guaranteed to trigger. When the check is optimised away, a malicious SOAP server can make…

▾ TwilightPHP Group · ext-soapEPSS 0.34%via NVD
CVE-2026-96876Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-96875Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-96878Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-96877Medium· 6.9
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.26%via NVD
CVE-2026-93682Medium· 5.8PoC
2d ago

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location

When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redirect code reads one byte past the end of the heap buffer holding the location. The value of that out-of-bounds byte d…

▾ TwilightPHP Group · ext-standardEPSS 0.35%via NVD
CVE-2026-57861None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-53990None
2d ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-5267High· 7.5
2d ago

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication

Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service c…

▾ TwilightCiena · Navigator NCSEPSS 0.36%via NVD
CVE-2026-100373Medium· 4.1PoC
2d ago

OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses

OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function that fails to properly resolve DNS hostnames and validate internal addresses. Users permitted to create or update Ev…

▾ Twilightopen-metadata · OpenMetadataEPSS 0.26%via NVD
CVE-2026-100372High· 7.2
2d ago

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter

ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Atta…

▾ TwilightMacWarrior · clipbucket-v5EPSS 1.1%via NVD
CVE-2026-100368High· 8.4
2d ago

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt

CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide specialized wrappers for shells such as PowerShell and Windows Command Prompt. `CliInvoke.Specializations` versions 2.2.…

▾ Twilightalastairlundy · CliInvoke.SpecializationsEPSS 0.58%via NVD
CVE-2026-100310High· 7.0
2d ago

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks

GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environment variable without proper privilege checks. A local attacker can exploit this by setting LIBEXTRACTOR_PREFIX to a dir…

▾ TwilightGNU · libextractorEPSS 0.14%via NVD
CVE-2026-100208High· 7.5
2d ago

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft 365 Apps for EnterpriseEPSS 0.35%via NVD
CVE-2026-97064Critical· 9.1
2d ago

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed

X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the database seed. Unauthenticated attackers can authenticate as any user by submitting the public master code to the emai…

▾ Midnightyzcheng90 · X-SpringBootEPSS 0.30%via NVD
CVE-2026-97060High· 7.2
2d ago

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification

X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to modify or delete users without ownership verification. Attackers with user-management permissions can reset passwords …

▾ Twilightyzcheng90 · X-SpringBootEPSS 0.31%via NVD
CVE-2026-100192Medium· 6.5
2d ago

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering

X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint without authentication or field filtering. Unauthenticated attackers can retrieve these credentials and use them to send ar…

▾ Sunlityzcheng90 · X-SpringBootEPSS 0.32%via NVD
CVE-2026-84460Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the REST endpoint for getting a tag list and receive the tag names for the given ticket, regardless of whether they have …

▾ Sunlitzammad · zammadEPSS 0.26%via NVD
CVE-2026-63205Medium· 5.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email signature, Zammad processes inline images referenced in the signature body. If a signature body contains an HTML img t…

▾ Sunlitzammad · zammadEPSS 0.32%via NVD
CVE-2026-84463Medium· 6.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing rights for a category can embed a video widget in a published answer with a specially crafted value. When the answer i…

▾ Sunlitzammad · zammadEPSS 0.15%via NVD
CVE-2026-63206Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which blocks remote images in ticket articles and email views, can be bypassed using a shortened URL format that omits the doubl…

▾ Sunlitzammad · zammadEPSS 0.28%via NVD
CVE-2026-63216Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are rendered in the configuration dialogs of AI Agents within Zammad's admin UI. When rendering the list of selected options, t…

▾ Sunlitzammad · zammadEPSS 0.24%via NVD
CVE-2026-84465High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when Zammad checks the digital signature on an incoming S/MIME-signed email, it does not verify that the signing certificate is genuinely trusted, it onl…

▾ Twilightzammad · zammadEPSS 0.12%via NVD
CVE-2026-63207Medium· 6.9
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator can obtain stored integration credentials in cleartext through the integration administration API. Certain responses d…

▾ Sunlitzammad · zammadEPSS 0.17%via NVD
CVE-2026-63006Medium· 5.3
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound emails or tickets could bypass the image URL sanitizer using path traversal sequences. When an authenticated agent vi…

▾ Sunlitzammad · zammadEPSS 0.48%via NVD
CVE-2026-49469Medium· 4.6
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner or technician can submit crafted criteria through the user import feature to bypass the configured default LDAP filter…

▾ Sunlitglpi-project · glpiEPSS 0.40%via NVD
CVE-2026-97896Low· 3.5
2d ago

A vulnerability was identified in krayin laravel-crm up to 2.2.5

A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Function…

▾ Sunlitkrayin · laravel-crmEPSS 0.24%via NVD
CVE-2026-53628Medium· 5.9
2d ago

GLPI is a free asset and IT management software package

GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding the Update auth and sync or Update auth, sync and 2FA right can change the authentication method and disable two-factor…

▾ Sunlitglpi-project · glpiEPSS 0.45%via NVD
CVEs tagged “nvd” — page 15 · VulnSea