VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25605 CVEsRSS

CVE-2026-24075High· 7.8
1w ago

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.

▾ Twilightqualcomm · wsa8845h_firmwareEPSS 0.06%via NVD
CVE-2026-24074High· 7.8
1w ago

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.

▾ Twilightqualcomm · iqx5121_firmwareEPSS 0.07%via NVD
CVE-2026-25261Medium· 6.7
1w ago

Memory corruption while processing rear sensor IOCTL calls.

Memory corruption while processing rear sensor IOCTL calls.

▾ Sunlitqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2025-59607High· 7.8
1w ago

Memory Corruption when copying large input data exceeds normal allocation limits.

Memory Corruption when copying large input data exceeds normal allocation limits.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25281High· 7.4
1w ago

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.10%via NVD
CVE-2026-25275High· 7.5
1w ago

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

Transient DOS when processing authentication frames with invalid FILS information element header lengths.

▾ Twilightqualcomm · q-7790_firmwareEPSS 0.19%via NVD
CVE-2026-25282High· 7.9
1w ago

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

Transient DOS when processing unverified data from a neighboring system causes out of bound memory access.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.06%via NVD
CVE-2026-25278High· 7.8
1w ago

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.

▾ Twilightqualcomm · lemans_au_lgit_firmwareEPSS 0.05%via NVD
CVE-2026-25290High· 7.8
1w ago

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

Memory Corruption when validating large data buffers from external sources using addition to check buffer length.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25284High· 7.3
1w ago

Information Disclosure when a pointer is reused after being deallocated.

Information Disclosure when a pointer is reused after being deallocated.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25283High· 8.8
1w ago

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

Memory Corruption when copying unverified data from an external source exceeds the allocated buffer size.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.07%via NVD
CVE-2026-25294High· 7.4
1w ago

Transient DOS while parsing frame during channel usage.

Transient DOS while parsing frame during channel usage.

▾ Twilightqualcomm · cologne_firmwareEPSS 0.10%via NVD
CVE-2026-25280High· 7.8
1w ago

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

Memory corruption when processing escape handling flow with insufficient user buffer sizes.

▾ Twilightqualcomm · wsa8845h_firmwareEPSS 0.07%via NVD
CVE-2026-87935High· 8.1
1w ago

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function

The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_…

▾ Twilightichurakov · Paid DownloadsEPSS 0.91%via NVD
CVE-2026-87796Critical· 9.8PoC
1w ago

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked uplo…

▾ Abyssalsh1zen · Multi Uploader for Gravity FormsEPSS 1.1%via NVD
CVE-2026-86311Medium· 6.4
1w ago

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Shortcode Attributes in all versions up to, and including, 1.8.44 due to insufficient input sanitization…

▾ Sunlit10web · Photo Gallery by 10Web – Mobile-Friendly Image GalleryEPSS 0.26%via NVD
CVE-2026-92839Medium· 4.3
1w ago

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler

Canva Desktop before v1.125.0 performed double decoding in the deeplink handler. A threat actor could cause the application to load arbitrary same-origin content under the user’s session.

▾ SunlitCanva · CanvaEPSS 0.28%via NVD
CVE-2026-50603Medium· 4.9
1w ago

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense

A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstance…

▾ SunlitAcer · Agent ServiceEPSS 0.10%via NVD
CVE-2026-89064Medium· 5.3
1w ago

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to Insufficient Credential Protection in versions up to, and including, 7.110. This is due to the `Ai1wm_Main_Controller::init()` method — registered on the `admin…

▾ Sunlitservmask · All-in-One WP Migration and BackupEPSS 0.50%via NVD
CVE-2026-81546High· 7.7
1w ago

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow

The Affinity by Canva application before 3.3.0 (September 2026 release) did not perform adequate bounds checking when parsing Affinity document files leading to a stack-based buffer overflow. A threat actor could craft a Affinity documen…

▾ TwilightCanva · AffinityEPSS 0.15%via NVD
CVE-2026-92838High· 7.8
1w ago

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application

A DLL hijacking vulnerability exists in the GeoVision GV-Remote E-Map desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in …

▾ TwilightGeoVision Inc. · GV-Remote E-mapEPSS 0.20%via NVD
CVE-2026-55061Low· 1.0
1w ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go parses UNIGET_EDITOR or EDITOR with strings.Split(editor, " ") and passes every space-delimited suffix as a…

▾ Sunlituniget-org · cliEPSS 0.15%via NVD
CVE-2026-55062High· 8.4PoC
1w ago

uniget is a universal installer and updater for (container) tools

uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget/hooks.go concatenates an unvalidated hook filename with the selected hooks directory, allowing parent-directory comp…

▾ Midnightuniget-org · cliEPSS 0.19%via NVD
CVE-2026-54546Medium· 5.0PoC
1w ago

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK

CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.1, the authenticated PUT /api/basemap endpoint passes an attacker-controlled URL through importBasemapURL() in api/ro…

▾ Twilightdfpc-coe · CloudTAKEPSS 0.37%via NVD
CVE-2026-50285High· 7.5PoC
1w ago

Pomerium is an identity and context-aware access proxy

Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs zstd decompression of attacker-controlled data without an output-memory limit when DecryptURLValues processes HPKE V…

▾ Midnightpomerium · pomeriumEPSS 0.74%via NVD
CVE-2026-54504High· 8.8PoC
1w ago

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents

MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13.0 until 1.13.1, the automatically started Web UI in src/server.ts calls startWebServer in src/web-server.ts with STA…

▾ Midnightandrea9293 · mcp-documentation-serverEPSS 0.57%via NVD
CVE-2026-54495Medium· 4.3
1w ago

The OpenFeature Operator allows users to expose feature flags to applications

The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME…

▾ Sunlitopen-feature · open-feature-operatorEPSS 0.31%via NVD
CVE-2026-54451High· 8.2PoC
1w ago

Elixir protobuf is a pure Elixir implementation of Google Protobuf

Elixir protobuf is a pure Elixir implementation of Google Protobuf. From 0.8.0 until 0.16.1, services that decode attacker-controlled protobuf bytes with Protobuf.Decoder can be taken offline when the schema contains a self-referential o…

▾ Midnightelixir-protobuf · protobufEPSS 0.52%via NVD
CVE-2026-54446High· 8.1PoC
1w ago

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-ne…

▾ MidnightLabs64 · NetLicensing-MCPEPSS 0.62%via NVD
CVE-2026-50158High· 7.7
1w ago

yutu is an AI-powered toolkit for managing and growing YouTube channels

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg…

▾ Twilighteat-pray-ai · yutuEPSS 0.23%via NVD
CVEs tagged “nvd” — page 167 · VulnSea