VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

27273 CVEsRSS

CVE-2026-75513Critical· 9.1PoC
2w ago

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL

Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQ…

▾ AbyssalJasperFx · martenEPSS 0.47%via NVD
CVE-2026-92808Critical· 10.0
2w ago

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker'…

▾ MidnightAltium · Altium Enterprise ServerEPSS 0.56%via NVD
CVE-2026-92526Medium· 6.3PoC
2w ago

A flaw has been found in itsourcecode Leave Management System 1.0

A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/leave/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched re…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-81870Low· 2.0PoC
2w ago

OpenTelemetry-Go is the Go implementation of OpenTelemetry

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 1.5.0 to 1.44.0, sdk/trace.NewTracerProvider emits a TracerProvider created internal Info-level diagnostic event whose MarshalLog implementations recursively includ…

▾ Twilightopen-telemetry · opentelemetry-goEPSS 0.19%via NVD
CVE-2026-62949Medium· 6.5
2w ago

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework

AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.24.0, _process_channel_open and _process_channel_open_confirmation in a…

▾ Sunlitronf · asyncsshEPSS 0.39%via NVD
CVE-2026-92474Low· 3.3PoC
2w ago

A security flaw has been discovered in GPAC 26.08-DEV

A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attac…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-76646High· 7.5
2w ago

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recomme…

▾ TwilightApache Software Foundation · Apache MyFacesEPSS 0.58%via NVD
CVE-2026-87976High· 8.1
2w ago

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests

Apache NiFi Registry 0.4.0 through 2.11.0 are subject to path manipulation when storing extension bundle content using group, artifact, and version coordinates from uploaded NAR manifests. The default file persistence provider used coord…

▾ Twilightapache · nifiEPSS 0.79%via NVD
CVE-2026-86089High· 7.1⚖ disputed
2w ago

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods ag…

▾ Twilightapache · nifiEPSS 0.44%via NVD
CVE-2026-81866Medium· 4.3⚖ disputed
2w ago

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Conn…

▾ Sunlitapache · nifiEPSS 0.56%via NVD
CVE-2026-86865High· 7.2
2w ago

Tanium addressed a SQL injection vulnerability in Asset.

Tanium addressed a SQL injection vulnerability in Asset.

▾ TwilightTanium · AssetEPSS 0.45%via NVD
CVE-2026-82561Medium· 6.5
2w ago

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase…

Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that replace the entire contents of a Process Group using a client-supplied flow definition, covering Process Group flow replacement together with versioned flow update and rebase…

▾ Sunlitapache · nifiEPSS 0.48%via NVD
CVE-2026-70469High· 7.5
2w ago

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding

Apache NiFi 2.11.0 disabled support for gzip-encoded HTTP requests for the application REST API and rejected requests that included the standard Content-Encoding header indicating gzip encoding. The framework enforcement filter did not c…

▾ Twilightapache · nifiEPSS 0.62%via NVD
CVE-2026-87116Medium· 6.5
2w ago

Tanium addressed a server-side request forgery vulnerability in Threat Response.

Tanium addressed a server-side request forgery vulnerability in Threat Response.

▾ SunlitTanium · Threat ResponseEPSS 0.34%via NVD
CVE-2026-87076Medium· 6.5
2w ago

Tanium addressed an information disclosure vulnerability in Discover.

Tanium addressed an information disclosure vulnerability in Discover.

▾ SunlitTanium · DiscoverEPSS 0.38%via NVD
CVE-2026-87024High· 7.2
2w ago

Tanium addressed a SQL injection vulnerability in Asset.

Tanium addressed a SQL injection vulnerability in Asset.

▾ TwilightTanium · AssetEPSS 0.45%via NVD
CVE-2026-87113Medium· 6.3
2w ago

Tanium addressed an improper access controls vulnerability in Threat Response.

Tanium addressed an improper access controls vulnerability in Threat Response.

▾ SunlitTanium · Threat ResponseEPSS 0.26%via NVD
CVE-2026-87105High· 8.8
2w ago

Tanium addressed a SQL injection vulnerability in Threat Response.

Tanium addressed a SQL injection vulnerability in Threat Response.

▾ TwilightTanium · Threat ResponseEPSS 0.43%via NVD
CVE-2026-92475Medium· 5.3PoC
2w ago

A weakness has been identified in GPAC 26.08-DEV

A weakness has been identified in GPAC 26.08-DEV. This impacts the function wait_for_header_and_parse of the file src/utils/downloader.c. This manipulation of the argument Content-Range causes out-of-bounds read. The attack requires loca…

▾ TwilightEPSS 0.16%via NVD
CVE-2026-88592Critical· 9.1PoC
2w ago

kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF)

kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filt…

▾ AbyssalEPSS 0.21%via NVD
CVE-2026-87026Low· 3.8
2w ago

Tanium addressed an improper access controls vulnerability in Threat Response.

Tanium addressed an improper access controls vulnerability in Threat Response.

▾ SunlitTanium · Threat ResponseEPSS 0.26%via NVD
CVE-2026-86831High· 8.7
2w ago

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namesp…

Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS Network Policy Agent before v1.4.0 might allow an authenticated remote user to bypass NetworkPolicy enforcement on co-located pods in other namesp…

▾ TwilightAWS · aws-network-policy-agentEPSS 0.64%via NVD
CVE-2026-89083Critical· 9.3
2w ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

▾ MidnightHP Inc · HP AC Print & ScanEPSS 0.70%via NVD
CVE-2026-89082Critical· 9.3
2w ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

▾ MidnightHP Inc · HP AC Print & ScanEPSS 0.70%via NVD
CVE-2026-89084High· 8.8
2w ago

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the …

▾ TwilightHP Inc · HP AC Print & ScanEPSS 0.78%via NVD
CVE-2026-92473Low· 3.3PoC
2w ago

A vulnerability was identified in GPAC 26.08-DEV

A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gf_sg_command_del of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to b…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-86071Low· 3.7
2w ago

Junrar is an open source Java RAR archive library

Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a cr…

▾ Sunlitjunrar · junrarEPSS 0.36%via NVD
CVE-2026-73462Medium· 6.5
2w ago

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

On affected platforms running Arista EOS with IGMP (Internet Group Management Protocol) snooping configured (enabled by default on all VLANs), a network-adjacent unauthenticated attacker can send malformed network packets on an affected …

▾ SunlitArista Networks · EOSEPSS 0.28%via NVD
CVE-2026-63325High· 7.8
2w ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descript…

▾ TwilightRedocly · redocly-cliEPSS 0.22%via NVD
CVE-2026-63225Medium· 4.4
2w ago

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…

▾ SunlitRedocly · redocly-cliEPSS 0.18%via NVD
CVEs tagged “nvd” — page 207 · VulnSea