VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25609 CVEsRSS

CVE-2026-81632High· 7.2
1w ago

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

Use of HTTP Request With Sensitive Query String vulnerability in team-alembic AshAuthenticationPhoenix allows someone able to read access logs, proxy logs or browser history to recover a single-use sign-in token and authenticate as its o…

▾ Twilightteam-alembic · ash_authentication_phoenixEPSS 0.21%via NVD
CVE-2026-80218High· 7.6
1w ago

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.Sig…

Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker holding a sign-in token for one authenticated resource to be signed in as a user of a different resource. AshAuthentication.Strategy.Password.Sig…

▾ Twilightteam-alembic · ash_authenticationEPSS 0.64%via NVD
CVE-2026-82761Critical· 9.1
1w ago

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configur…

▾ Midnightteam-alembic · ash_authenticationEPSS 0.56%via NVD
CVE-2026-81637Low· 2.3
1w ago

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticat…

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim's OAuth2 state value to replay the callback and sign that victim into an attacker-controlled account. AshAuthenticat…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.61%via NVD
CVE-2026-78223Medium· 6.9
1w ago

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthenticatio…

Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the token revocation action to neutralise a revocation or write arbitrary rows into the token resource. AshAuthenticatio…

▾ Sunlitteam-alembic · ash_authenticationEPSS 0.44%via NVD
CVE-2026-86533Critical· 9.1
1w ago

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_p…

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_p…

▾ Midnightteam-alembic · ash_authenticationEPSS 0.91%via NVD
CVE-2026-85500Critical· 9.1
1w ago

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.…

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.…

▾ Midnightteam-alembic · ash_authenticationEPSS 0.77%via NVD
CVE-2026-92932Medium· 5.1
1w ago

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching

In the MISP sachertortephp library, the Xml::build() static method in lib/Cake/Utility/Xml.php contains a logic error in the conditional that gates network-based XML fetching. The original condition was written as: $options['readFile'] &…

▾ Sunlitmisp · sachertortephpEPSS 0.39%via NVD
CVE-2026-92921Medium· 4.9PoC
1w ago

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function

admin3 through 3.0.0 stores account passwords using single-round MD5 with only the username as salt and no key derivation function. Attackers with database access can recover plaintext passwords through offline dictionary or brute-force …

▾ Twilightcjbi · admin3EPSS 0.30%via NVD
CVE-2026-92920Medium· 5.4PoC
1w ago

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions

admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers to retain authenticated access with original permissions. Attackers can continue using bearer tokens issued before account disab…

▾ Twilightcjbi · admin3EPSS 0.32%via NVD
CVE-2026-92919High· 8.1PoC
1w ago

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments

admin3 through 3.0.0 fails to sanitize client-supplied filenames in the upload handler, allowing authenticated users to write files outside the storage root on Windows deployments. Attackers can use dot-dot path segments in filenames to …

▾ Midnightcjbi · admin3EPSS 0.58%via NVD
CVE-2026-92918High· 8.8PoC
1w ago

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events

admin3 through 3.0.0 persists user session tokens in the audit log event body when publishing UserLoggedIn domain events. Attackers with log:view permission can read the JSON response from the GET /logs endpoint to harvest session tokens…

▾ Midnightcjbi · admin3EPSS 0.65%via NVD
CVE-2026-92904Medium· 4.3
1w ago

A flaw was found in the foreman_remote_execution plugin's template invocations controller

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filt…

▾ SunlitRed Hat · rubygem-foreman_remote_executionEPSS 0.34%via NVD
CVE-2026-81481High· 7.5
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially …

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.53%via NVD
CVE-2026-53681None
1w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

▾ Sunlitvia NVD
CVE-2026-53679None
1w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

▾ Sunlitvia NVD
CVE-2026-11874None
1w ago

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.

▾ Sunlitvia NVD
CVE-2026-81475High· 8.1
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading…

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.70%via NVD
CVE-2026-78296Medium· 5.3
1w ago

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

Insufficient Verification of Data Authenticity vulnerability in WP ManageNinja LLC FluentAuth allows Identity Spoofing. This issue affects FluentAuth: from n/a through 2.1.2.

▾ SunlitWP ManageNinja LLC · fluent-securityEPSS 0.16%via NVD
CVE-2026-92912Medium· 6.5PoC
1w ago

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second

AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 uses cryptographically weak uniqid() values for RTMP publish keys in LiveTransmition, reducing key entropy to approximately one million possibilities per creation second. Attackers …

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-81477High· 7.2
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.62%via NVD
CVE-2026-92916High· 7.5
1w ago

Grav is a flat-file CMS

Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.debugger.enabled: true, which is not the default), the Clockwork profiler endpoint is exposed without authentication: …

▾ Twilightgetgrav · gravEPSS 0.50%via NVD
CVE-2026-92915High· 7.3PoC
1w ago

WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php

WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/userVerifyEmail.php. The script disables the login requirement ($global['ignoreUserMustBeLoggedIn'] = 1), takes users_id…

▾ MidnightWWBN · AVideoEPSS 0.42%via NVD
CVE-2026-92914High· 8.1
1w ago

AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable

AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares challenge responses using loose equality against an uninitialized session variable. Attackers with a victim's passwor…

▾ TwilightWWBN · AVideoEPSS 0.47%via NVD
CVE-2026-92917High· 7.5PoC
1w ago

Grav is a flat-file CMS

Grav is a flat-file CMS. In versions 2.0.0-rc.1 through 2.0.21, the Twig content sandbox fails to restrict the dump and serialize filters (print_r, vardump, json_encode, yaml_encode, string): GravExtension::assertSandboxDumpSafe() determ…

▾ Midnightgetgrav · gravEPSS 0.46%via NVD
CVE-2026-81478High· 8.1
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unaut…

▾ TwilightDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.38%via NVD
CVE-2026-92925High· 7.1
1w ago

A flaw was found in Redis community

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacke…

▾ TwilightRed Hat · redis:7EPSS 0.57%via NVD
CVE-2026-90822Critical· 9.8
1w ago

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected manageme…

▾ MidnightFatPipe Networks · MPVPNEPSS 1.4%via NVD
CVE-2026-81441Medium· 4.0
1w ago

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability

Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading …

▾ SunlitDell · OpenManage Server Administrator Managed Node (Patch) for WindowsEPSS 0.17%via NVD
CVE-2026-90823Critical· 9.8
1w ago

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management…

▾ MidnightFatPipe Networks · MPVPNEPSS 0.68%via NVD
CVEs tagged “nvd” — page 164 · VulnSea