VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25608 CVEsRSS

CVE-2026-54446High· 8.1PoC
1w ago

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing

NetLicensing MCP Server is a natural-language interface that enables agentic applications to manage the software-licensing lifecycle in Labs64 NetLicensing. Prior to 0.1.6, network-reachable HTTP transport requests to /mcp that omit x-ne…

▾ MidnightLabs64 · NetLicensing-MCPEPSS 0.62%via NVD
CVE-2026-50158High· 7.7
1w ago

yutu is an AI-powered toolkit for managing and growing YouTube channels

yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool accepts a caller-controlled file parameter through cmd/caption/download.go and passes it to Caption.Download() in pkg…

▾ Twilighteat-pray-ai · yutuEPSS 0.23%via NVD
CVE-2026-50125High· 7.5PoC
1w ago

MKP is a Model Context Protocol server for Kubernetes

MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoint and pkg/mcp/server.go registers the unauthenticated get_resource tool, which accepts attacker-controlled limitByt…

▾ MidnightStacklokLabs · mkpEPSS 0.49%via NVD
CVE-2026-47252Critical· 9.0PoC
1w ago

Anyquery is an SQL query engine built on top of SQLite

Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brav…

▾ Abyssaljulien040 · anyqueryEPSS 0.70%via NVD
CVE-2026-54617Critical· 9.8
1w ago

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3

GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274…

▾ MidnightGravitLauncher · LauncherEPSS 0.68%via NVD
CVE-2026-49292Low· 0.0
1w ago

Kiwi TCMS is an open source test management system

Kiwi TCMS is an open source test management system. Prior to 16.0, the unauthenticated /init-db/ page handled by InitDBView in tcms/core/views.py remains reachable after initial setup and proxies repeated requests to Kiwi/manage.py migra…

▾ Sunlitkiwitcms · KiwiEPSS 0.44%via NVD
CVE-2026-85789None
1w ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-65388High· 7.5
1w ago

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host

A remote attacker who controls a container registry may be able to direct a client's token request to a host of the attacker's choice, and disclose the victim's registry credentials to that host. This vulnerability is addressed in contai…

▾ TwilightApple · containerizationEPSS 0.43%via NVD
CVE-2026-61599High· 8.8
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the djust live transport resolves the LiveView to mount from a client-supplied dotted path by calling …

▾ Twilightdjust-org · djustEPSS 0.60%via NVD
CVE-2026-61589Medium· 6.3
1w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest` via `RequestFac…

▾ Sunlitdjust-org · djustEPSS 0.18%via NVD
CVE-2026-92577High· 7.5
1w ago

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers

In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by …

▾ TwilightWWBN · AVideoEPSS 0.43%via NVD
CVE-2026-92576High· 8.6PoC
1w ago

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses

HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instruc…

▾ MidnightHKUDS · nanobotEPSS 0.45%via NVD
CVE-2026-64684Medium· 6.8
1w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransport in crates/rmcp/src/transport/common/reqwest/streamable_http_client.rs builds its default_http_client with reqwest…

▾ Sunlitmodelcontextprotocol · rust-sdkEPSS 0.50%via NVD
CVE-2026-92581Medium· 4.3PoC
1w ago

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters

In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed li…

▾ TwilightWWBN · AVideoEPSS 0.29%via NVD
CVE-2026-89034Medium· 6.5PoC
1w ago

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, o…

TCH QRing smart ring model R20_B006 running firmware RT09R20_1.00.00_250318 contains an unauthenticated Bluetooth Low Energy access vulnerability that allows any nearby attacker to connect to the device without pairing, authentication, o…

▾ TwilightTCH · QRingEPSS 0.33%via NVD
CVE-2026-85469High· 8.0
1w ago

A flaw was found in quay-builder-qemu

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inj…

▾ TwilightRed Hat · quay/quay-builder-qemu-rhcos-rhel8EPSS 0.52%via NVD
CVE-2026-92580High· 8.8PoC
1w ago

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection

In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync…

▾ MidnightWWBN · AVideoEPSS 1.4%via NVD
CVE-2026-92579Medium· 5.4PoC
1w ago

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions

In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugi…

▾ TwilightWWBN · AVideoEPSS 0.27%via NVD
CVE-2026-92578High· 8.1PoC
1w ago

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify()

WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attacke…

▾ MidnightWWBN · AVideoEPSS 0.62%via NVD
CVE-2026-92584Medium· 6.1
1w ago

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability

AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's…

▾ SunlitWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-92583Medium· 6.5PoC
1w ago

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concu…

▾ TwilightWWBN · AVideoEPSS 0.30%via NVD
CVE-2026-92582High· 7.1
1w ago

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery

AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global…

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-92587Medium· 5.0
1w ago

n8n is a workflow automation platform

n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git …

▾ Sunlitn8n-io · n8nEPSS 0.31%via NVD
CVE-2026-92586Medium· 4.3PoC
1w ago

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted vide…

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and group-restricted vide…

▾ TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-92585Medium· 4.3PoC
1w ago

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos

AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted videos. Attackers can …

▾ TwilightWWBN · AVideoEPSS 0.26%via NVD
CVE-2026-92591Medium· 5.9
1w ago

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever P…

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever P…

▾ Sunlitcraftcms · cmsEPSS 0.41%via NVD
CVE-2026-92589Medium· 4.3
1w ago

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries)…

▾ Sunlitcraftcms · cmsEPSS 0.26%via NVD
CVE-2026-92588Medium· 4.4
1w ago

n8n is a workflow automation platform

n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead o…

▾ Sunlitn8n-io · n8nEPSS 0.32%via NVD
CVE-2026-92595Medium· 5.9PoC
1w ago

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.resolveContent()` us…

▾ Twilightnodemailer · nodemailerEPSS 0.29%via NVD
CVE-2026-92592High· 8.8
1w ago

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bou…

Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bou…

▾ Twilightcraftcms · cmsEPSS 0.65%via NVD
CVEs tagged “nvd” — page 168 · VulnSea