VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

27275 CVEsRSS

CVE-2026-92748High· 8.8PoC
2w ago

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server

BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authenticated operators to write files to arbitrary paths on the C2 server. Attackers can use path traversal sequences in th…

▾ MidnightBC-SECURITY · EmpireEPSS 0.82%via NVD
CVE-2026-63506High· 8.8PoC
2w ago

Tina is a headless content management system

Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected Tin…

▾ Midnighttinacms · tinacmsEPSS 0.52%via NVD
CVE-2026-92749High· 8.1
2w ago

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline

SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, allowing attackers to reconstruct the key offline. Unauthenticated remote attackers who can bound the install timestamp …

▾ Twilightchaitin · SafeLineEPSS 0.71%via NVD
CVE-2026-92759Medium· 6.5
2w ago

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retriev…

▾ SunlitSecObserve · SecObserveEPSS 0.46%via NVD
CVE-2026-92753High· 7.1PoC
2w ago

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering

PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that lack ownership filtering. Authenticated attackers can read platform event history, delete arbitrary events, and modif…

▾ MidnightPatrowl · PatrowlManagerEPSS 0.38%via NVD
CVE-2026-92750Medium· 6.5
2w ago

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to

Harness through 3.3.0 omits access control validation in the infrastructure provider read endpoint, allowing authenticated users to retrieve provider configurations from spaces they do not belong to. Attackers can query the GET /api/v1/i…

▾ Sunlitharness · harnessEPSS 0.28%via NVD
CVE-2026-92761High· 8.8PoC
2w ago

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions

WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform privileged actions. Attackers with read-only grants can power off virtual machines, reset root passwords, install SSH ke…

▾ Midnightretspen · webvirtcloudEPSS 0.61%via NVD
CVE-2026-92754Medium· 4.3PoC
2w ago

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out

PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where the authorization decorator is commented out. Authenticated attackers with low-privilege accounts can enumerate all use…

▾ TwilightPatrowl · PatrowlManagerEPSS 0.34%via NVD
CVE-2026-92751High· 8.1PoC
2w ago

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators

CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints l…

▾ Midnightyahoo · CMAKEPSS 0.26%via NVD
CVE-2026-92760Medium· 6.5PoC
2w ago

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics

Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restricted keys to subscribe to all topics. Attackers with author-only or domain-only keys can access the mercure-info end…

▾ Twilightshlinkio · shlinkEPSS 0.41%via NVD
CVE-2026-92752High· 8.3PoC
2w ago

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions

metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in without enforcing record-level permissions. Attackers can enumerate sequential document identifiers to read, replace,…

▾ Midnightmetasfresh · metasfreshEPSS 0.46%via NVD
CVE-2026-92764Medium· 4.3
2w ago

OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships

OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve ev…

▾ Sunlitopencve · opencveEPSS 0.37%via NVD
CVE-2026-92763High· 8.1PoC
2w ago

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint

Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project archive import endpoint. Attackers with only the import action can replace project configuration files including security…

▾ Midnightrundeck · rundeckEPSS 0.51%via NVD
CVE-2026-92762High· 8.8PoC
2w ago

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks

Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather than server-side authorization checks. Attackers with startup.read permission can craft Livewire state updates to inv…

▾ Midnightpelican · panelEPSS 0.65%via NVD
CVE-2026-92775Medium· 6.5PoC
2w ago

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation

Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches arbitrary URLs without protocol, host, or address validation. Attackers with page editing permissions can inject img…

▾ Twilightrequarks · Wiki.jsEPSS 0.41%via NVD
CVE-2026-92771Medium· 6.5PoC
2w ago

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks

Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing authenticated users to bypass permission checks. Attackers with canReadObjectRecords permission but canReadFieldValue…

▾ Twilighttwentyhq · twentyEPSS 0.44%via NVD
CVE-2026-92770Medium· 6.5PoC
2w ago

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials

Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credentials. Project administrators can exploit fuzzy filtering on the AccessCredential column to recover the scanner adapter…

▾ Twilightgoharbor · harborEPSS 0.45%via NVD
CVE-2026-92774Medium· 4.3PoC
2w ago

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed

Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based access restrictions to be bypassed. Attackers can query the list, tree, tags, searchTags, and links resolvers to retrieve…

▾ Twilightrequarks · Wiki.jsEPSS 0.37%via NVD
CVE-2026-92773High· 7.1
2w ago

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization

Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it to their organization. Attackers can claim another user's GitHub App installation by replaying state cookies and sup…

▾ Twilighttriggerdotdev · trigger.devEPSS 0.32%via NVD
CVE-2026-92765Medium· 6.5PoC
2w ago

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations

ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticated users to read vulnerability findings from other organizations. Attackers can supply arbitrary scan identifiers to r…

▾ Twilightarcherysec · archerysecEPSS 0.45%via NVD
CVE-2026-92780High· 8.8PoC
2w ago

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality

KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated user to access protected functionality. Attackers can call identity-management endpoints to create administrator acc…

▾ Midnightdidi · KnowStreamingEPSS 0.52%via NVD
CVE-2026-92776High· 8.1PoC
2w ago

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders

Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to access pages sharing a prefix with authorized folders. Users granted access to a folder can read and modify unrelated …

▾ Midnightrequarks · Wiki.jsEPSS 0.45%via NVD
CVE-2026-92772High· 7.1PoC
2w ago

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation

Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks permission validation. Authenticated users with limited roles can install marketplace plugins and control arbitrary prope…

▾ MidnightLeantime · leantimeEPSS 0.53%via NVD
CVE-2026-92782High· 8.1PoC
2w ago

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, a…

▾ Midnightchroma-core · chromaEPSS 0.45%via NVD
CVE-2026-92778Medium· 5.4
2w ago

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election schedul…

▾ Sunlityahoo · CMAKEPSS 0.44%via NVD
CVE-2026-92783High· 8.1PoC
2w ago

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships

Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with read access to delete access control relationships. Attackers can revoke the owner's grant and permanently lock legiti…

▾ Midnightyeti-platform · yetiEPSS 0.50%via NVD
CVE-2026-92781Medium· 6.3PoC
2w ago

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten helper that processes builder.userAttributes query parameters without prototype guards. Attackers can craft preview lin…

▾ TwilightBuilderIO · @builder.io/sdk-reactEPSS 0.36%via NVD
CVE-2026-92779High· 7.6
2w ago

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation

Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set helper function that processes content block bindings without validation. Attackers can craft content blocks with bindin…

▾ TwilightBuilderIO · @builder.io/sdk-reactEPSS 0.49%via NVD
CVE-2026-92788High· 8.8
2w ago

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace

Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's workspace. Authenticated attackers can enumerate predictable table identifiers and execute SQL statements against oth…

▾ Twilightcoze-dev · coze-studioEPSS 0.52%via NVD
CVE-2026-92785High· 8.1PoC
2w ago

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation

Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist validation. Unauthenticated network attackers can instantiate arbitrary classes or exhaust coordinator memory by sending…

▾ MidnightAngel-ML · angelEPSS 0.61%via NVD
CVEs tagged “nvd” — page 205 · VulnSea