VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25136 CVEsRSS

CVE-2026-93364Medium· 4.3
2d ago

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

Bludit CMS through 3.22.0 contains a mass assignment vulnerability that allows authenticated users with the Author role to modify privileged page fields reserved for administrators by injecting reserved parameters into a content save req…

▾ SunlitBludit · Bludit CMSEPSS 0.19%via NVD
CVE-2026-80432Medium· 6.0
2d ago

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

Missing Authorization in the drop handling path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to obtain the contents of files dragged over the window even when the user never co…

▾ SunlitKovid Goyal · kittyEPSS 0.12%via NVD
CVE-2026-56729Low· 2.1
2d ago

Zammad is a web based open source helpdesk/customer support system

Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have different editor roles assigned, a user with knowledge_base.editor in one category can see answer titles and updated_at …

▾ Sunlitzammad · zammadEPSS 0.38%via NVD
CVE-2026-18320Medium· 6.1
2d ago

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule

Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due to a wildcard attribute rule. This configuration fails to remove script-capable attributes such as event handlers (e.…

▾ SunlitReadwise · ReaderEPSS 0.16%via NVD
CVE-2026-67411Medium· 6.0PoC
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.18, 4.0.23, 4.1.14, 4.2.9, and 4.3.3, native MQTT and MQTT over WebSocket behind a trusted PROXY Protocol frontend could lose the proxy-derived client address before th…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.39%via NVD
CVE-2026-18311Medium· 6.1
2d ago

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata

Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its processing of imported document metadata. Attacker-controlled fields such as the author meta tag are inserted into a WebVie…

▾ SunlitReadwise · ReaderEPSS 0.16%via NVD
CVE-2026-93365Medium· 6.5
2d ago

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

Bludit CMS through 3.22.0 contains a missing authorization vulnerability that allows authenticated users holding the Author or Editor role to read the full content of private drafts and scheduled posts belonging to any other user, includ…

▾ SunlitBludit · Bludit CMSEPSS 0.21%via NVD
CVE-2026-95834Medium· 4.6
2d ago

Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag_remote_file_…

Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag_remote_file_…

▾ SunlitKovid Goyal · kittyEPSS 0.13%via NVD
CVE-2026-97868Low· 3.5PoC
2d ago

A security vulnerability has been detected in sheshbabu zen up to 1.5.0

A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerouslySetInnerHTML of the file features/notes/NotesEditor.jsx of the component Note Editor. The manipulation leads to cr…

▾ Twilightsheshbabu · zenEPSS 0.19%via NVD
CVE-2026-96874Low· 2.3
2d ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. This issue affects Mediawiki - Cargo extension: through 3.9.4.

▾ SunlitThe Wikimedia Foundation · Mediawiki - Cargo extensionEPSS 0.20%via NVD
CVE-2026-97869Medium· 4.1PoC
2d ago

A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27

A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the function AgenticScopeSerializer.fromJson of the file AgenticScopeJsonSerializationIT.java of the component LangChain4j-a…

▾ TwilightEPSS 0.38%via NVD
CVE-2026-85290Medium· 5.3
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Cron::recur() method writes an invalid cron key from the URL path directly to the application log without …

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.24%via NVD
CVE-2026-54790Medium· 6.0
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores an administrator-controlled custom_field_table value without validating it against the allowed custom…

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.23%via NVD
CVE-2026-39372Medium· 4.9
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane stores and serves uploaded image attachments without stripping EXIF metadata. When an administrator uploads …

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.28%via NVD
CVE-2026-85292Medium· 4.8
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's User_Controller compares the session user_type value with the required role by using PHP's loose inequalit…

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.25%via NVD
CVE-2026-85291Medium· 6.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Users::change_password() method accepts a user_id from the URL and updates that account's password without…

▾ SunlitInvoicePlane · InvoicePlaneEPSS 0.26%via NVD
CVE-2026-85274Medium· 6.5PoC
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.17%via NVD
CVE-2026-39353Critical· 9.1PoC
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an …

▾ AbyssalInvoicePlane · InvoicePlaneEPSS 0.45%via NVD
CVE-2026-97469Medium· 4.3
2d ago

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt

PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() function and collects (seed, hash_output) pairs to perform an offline brute-force attack and deduce the salt. A maske…

▾ SunlitDALIBO · PostgreSQL AnonymizerEPSS 0.12%via NVD
CVE-2026-50547High· 7.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and i…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.46%via NVD
CVE-2026-33639High· 7.2
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for …

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.40%via NVD
CVE-2026-49850High· 7.5
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POS…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.33%via NVD
CVE-2026-100230Medium· 5.3
2d ago

Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is writt…

Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, mishandles the / versus \ distinction and allows directory traversal, with resultant code execution if a file is writt…

▾ Sunlitinput-leap · Input LeapEPSS 0.65%via NVD
CVE-2026-42324High· 7.2PoC
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The store…

▾ MidnightPiwigo · PiwigoEPSS 0.92%via NVD
CVE-2026-62262Critical· 9.1
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then o…

▾ MidnightPiwigo · PiwigoEPSS 0.30%via NVD
CVE-2026-42323High· 7.2
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager f…

▾ TwilightPiwigo · PiwigoEPSS 0.37%via NVD
CVE-2026-44642High· 8.1PoC
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_mag…

▾ MidnightPiwigo · PiwigoEPSS 1.3%via NVD
CVE-2026-42322Critical· 9.1
2d ago

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo whe…

▾ MidnightPiwigo · PiwigoEPSS 0.53%via NVD
CVE-2026-85289Medium· 6.5PoC
2d ago

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane omits ensure_valid_post_request() from delete methods including Payments::delete(), Recurring::delete(), and…

▾ TwilightInvoicePlane · InvoicePlaneEPSS 0.17%via NVD
CVE-2026-67236High· 8.2
2d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, a successful POST /login caused is_authorized/2 to set an auth cookie containing base64-encoded username:password credentials without HttpOnly, Secure, SameS…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.12%via NVD
CVEs tagged “nvd” — page 19 · VulnSea