VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25136 CVEsRSS

CVE-2026-97877High· 7.3PoC
2d ago

A vulnerability was determined in zhistaredu StarTraining up to 3.8.1

A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id…

▾ Midnightzhistaredu · StarTrainingEPSS 0.45%via NVD
CVE-2026-67242Medium· 6.3PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, OAuth2 isinteger(Exp) guard skips token-expiry checks for float exp. validatetokenexpiry/1 (lines 208-214) and expirytimestamp/1 (138-144) both guard with 'w…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.46%via NVD
CVE-2026-67409High· 8.2PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9, 4.1.14, 4.0.23, and 3.13.18, JWKS Fetch Ignores HTTP Response Status Code - Signing Key Destruction Causes Authentication DoS (CWE-252). the JWKS key fetching …

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.49%via NVD
CVE-2026-67415Medium· 5.9PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.9 and 4.3.3, the Shovel parameter parser converted attacker-controlled runtime parameter values into non-garbage-collected Erlang atoms before bounding them or checking a…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-97878High· 7.3PoC
2d ago

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1

A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Impacted is the function anonymous of the file /druid/index.html of the component Druid Console. Such manipulation leads to missing authentication. The attack may be …

▾ Midnightzhistaredu · StarTrainingEPSS 0.63%via NVD
CVE-2026-67413Medium· 6.0
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.23, 4.1.14, 4.2.9, and 4.3.3, the optional rabbitmq_jms_topic_exchange plugin's x-jms-topic exchange accepted a client-controlled rjms_erlang_selector binding expression …

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-61837Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET /bindings exposes full binding topology to any authenticated AMQP user without resource/management permission checks…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.25%via NVD
CVE-2026-67407Medium· 5.1
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3 and 4.2.9 and 4.1.14 and 4.0.23, Incomplete fix for CVE-2026-44838: escaperegexchar/1 does not escape -, leaving room for an MQTT topic permission bypass. the CVE-2026-…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.25%via NVD
CVE-2026-67226Medium· 6.9PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: PUT /api/users tags list. settags/2 maps rabbitdatacoercion:toatom/1 over the user's tags list. The 20 MB management …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-67410High· 8.2PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.3.3 and 4.2.9, OAuth2 Client Secret Exposed via Unauthenticated JavaScript Endpoint (CWE-200). when OAuth2 authentication is enabled for the RabbitMQ Management UI and the …

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.40%via NVD
CVE-2026-67406Medium· 4.6
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, Shovel does not format state logged by the crash reporter and can leave unencrypted credentials in a crash dump file. the shovel worker gens…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-67227Medium· 5.9
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1, Atom exhaustion: toatom on global-parameter :name. resourceexists/2 (and the PUT/DELETE handlers) call rabbitdatacoercion:toatom/1 on t…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.29%via NVD
CVE-2026-95835Medium· 5.6
2d ago

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

Missing Authorization in the askpass escape code handler in kitty from 0.25.0 before 0.49.0 allows a local user other than the one running the terminal to obtain the text typed into a prompt that kitty itself displays, because handle_rem…

▾ SunlitKovid Goyal · kittyEPSS 0.10%via NVD
CVE-2026-67408High· 7.1PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.1.0 until 4.3.3, 4.2.9, and 4.1.11, Stream Management Super-Stream Binding Keys Allocation Allows Low-Privilege Node Denial of Service. rabbitMQ 4.3.1 with rabbitmqstreammanagement ena…

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.34%via NVD
CVE-2026-91837High· 7.8
2d ago

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager

A flaw was found in NetworkManager-iodine, the iodine VPN plugin for NetworkManager. A local unprivileged user can exploit a vulnerability in how the 'nameserver' setting is processed when establishing an iodine VPN connection. By embedd…

▾ TwilightGNOME · network-manager-iodineEPSS 0.14%via NVD
CVE-2026-67421Medium· 4.5PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ Management rendered an AMQP authorization-error reason containing an attacker-controlled queue name as HTML when the OAu…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-97879Medium· 5.3PoC
2d ago

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1

A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. The affected element is an unknown function of the file SecurityConfig.java of the component api-docs Endpoint. Performing a manipulation results in missing auth…

▾ Twilightzhistaredu · StarTrainingEPSS 0.65%via NVD
CVE-2026-97871High· 7.3PoC
2d ago

A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76

A vulnerability has been found in Zhonglun CloudPos up to 3.0.1.76. This issue affects the function OpenLocalBrowser of the file ZlPos/ZlPos/Bizlogic/JSBridge.cs of the component JSBridge. Such manipulation of the argument url leads to c…

▾ MidnightZhonglun · CloudPosEPSS 0.52%via NVD
CVE-2026-67419High· 7.1PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same t…

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.33%via NVD
CVE-2026-67420Low· 2.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAuth credential refresh retains revoked runtime tags. when an existing AMQP connection refreshes from an OAuth token th…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.24%via NVD
CVE-2026-67225Medium· 6.3
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol stored the FrameMax value negotiated during the Tune handshake but did not compare it with an inbound frame's declare…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.32%via NVD
CVE-2026-66073Medium· 6.0
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exhaustion via management API node field. pUT /api/queues/:vhost/:name (and the exchanges and bindings endpoints) accepts…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.33%via NVD
CVE-2026-94445High· 8.8
2d ago

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctl…

A malicious txtar could escape the intended execution context and force arbitrary writes to the playground host's trusted filesystem. Disjointly, one of the three possible paths to invoke go vet on the playground host did not correctl…

▾ Twilightgolang.org/x/playground · golang.org/x/playgroundEPSS 0.36%via NVD
CVE-2026-67239High· 7.6
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18 and 4.0.23 and 4.1.14 and 4.2.9 and 4.3.3, Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11). lines 102/106/110 render peercertsubject…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.27%via NVD
CVE-2026-67412Medium· 6.0PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 4.3.3, 4.2.9 , 4.1.14, 4.0.24, and 3.13.18, Federation upstream in RabbitMQ skips vhost authorization allowing cross-vhost message access. what the bug lets you do. A policy…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-56724High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, summary An issue with permission checks in the knowledge base management area has been identified. Under certain conditions, data validation for linked i…

▾ Twilightzammad · zammadEPSS 0.27%via NVD
CVE-2026-100237Medium· 6.1
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects Mediawiki - Thanks Extension: from * befor…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Thanks Extension allows Stored XSS. This issue affects Mediawiki - Thanks Extension: from * befor…

▾ SunlitThe Wikimedia Foundation · Mediawiki - Thanks ExtensionEPSS 0.15%via NVD
CVE-2026-93363Medium· 4.3
2d ago

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly

The @payloadcms/storage-vercel-blob storage adapter for Payload contains an improper access control vulnerability that allows authenticated users to bypass collection-level permissions by accessing the client-upload route directly. Attac…

▾ Sunlitpayloadcms · payloadEPSS 0.18%via NVD
CVE-2026-56723High· 7.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, a customer who can view a ticket cannot see internal ticket articles through the article listing API. However, the same customer can directly request an …

▾ Twilightzammad · zammadEPSS 0.27%via NVD
CVE-2026-18312Medium· 6.1
2d ago

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping

Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or escaping. The application interpolates untrusted values directly into URL strings and inserts them into the DOM via …

▾ SunlitReadwise · ReaderEPSS 0.19%via NVD
CVEs tagged “nvd” — page 18 · VulnSea