VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25134 CVEsRSS

CVE-2026-80430Medium· 4.6
2d ago

Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside the st…

Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to create files and directories at paths outside the st…

▾ SunlitKovid Goyal · kittyEPSS 0.15%via NVD
CVE-2026-80431Medium· 6.8
2d ago

Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command…

Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command…

▾ SunlitKovid Goyal · kittyEPSS 0.14%via NVD
CVE-2026-100174Medium· 5.1
2d ago

The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS)

The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS). A user with the ability to create a custom tag could embed an HTML payload containing JavaScript event handlers (e.g…

▾ Sunlitail project · ail frameworkEPSS 0.40%via NVD
CVE-2026-100172High· 8.5
2d ago

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message…

The AIL Framework (ail-project/ail-framework) contains a stored cross-site scripting (XSS) vulnerability in two Jinja2 templates that render popovers for matched, tracked, or tagged content: var/www/templates/chats_explorer/block_message…

▾ Twilightail project · ail frameworkEPSS 0.27%via NVD
CVE-2026-100187Medium· 6.9
2d ago

The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), wit…

The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as valid .onion targets based solely on a length check (exactly 69 characters) and a suffix check (ending in ".onion"), wit…

▾ Sunlitail project · ail frameworkEPSS 0.43%via NVD
CVE-2026-100177Medium· 6.3
2d ago

The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task

The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a user supplied a cookiejar UUID to attach to a one-shot or scheduled crawler task. The original code only verified tha…

▾ Sunlitail project · ail frameworkEPSS 0.34%via NVD
CVE-2026-100176High· 8.5
2d ago

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS)

The AIL Framework's username timeline feature is vulnerable to stored cross-site scripting (XSS). Usernames imported from chats and crawled forums are stored without character restrictions. When an authenticated analyst views the usernam…

▾ Twilightail project · ail frameworkEPSS 0.35%via NVD
CVE-2026-97865High· 7.3
2d ago

A security flaw has been discovered in Open-Web-Analytics up to 1.8.1

A security flaw has been discovered in Open-Web-Analytics up to 1.8.1. Affected is the function Event::loadFromArray of the file queue.php of the component Remote Event Queue Endpoint. Performing a manipulation results in deserialization…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-85750High· 7.2PoC
2d ago

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing fo…

▾ MidnightPiwigo · PiwigoEPSS 1.2%via NVD
CVE-2026-97864Medium· 5.3PoC
2d ago

A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01

A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the file modules/Planner/units_add_blockAjax.php of the component Unit Planner. The manipulation of the argument gibbonUn…

▾ TwilightGibbonEdu · GibbonEPSS 0.73%via NVD
CVE-2026-97222Medium· 5.5
2d ago

A heap use-after-free flaw was found in Gnumeric

A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed SheetObjectComponent element, the XML parser can dereference a freed sheet-object component, causing Gnumeric to crash.

▾ SunlitGNOME · gnumericEPSS 0.12%via NVD
CVE-2026-93834High· 8.8PoC
2d ago

A use-after-free vulnerability was found in QEMU's 9pfs subsystem

A use-after-free vulnerability was found in QEMU's 9pfs subsystem. A race condition between the main thread and a worker thread when processing concurrent Tlcreate and Twalk requests allows a malicious guest user to craft a fid path cont…

▾ MidnightRed Hat · qemu-kvmEPSS 0.38%via NVD
CVE-2026-93642Critical· 9.3
2d ago

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.23%via NVD
CVE-2026-85542High· 8.8⚠ ExploitedPoC
2d ago

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality

IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the GIM bundle import functionality. An authenticated attacker can provide a crafted GIM bundle that causes attacker-controlled arguments to be passed …

▾ MidnightIBM · Guardium Data ProtectionEPSS 2.4%via NVD
CVE-2026-100190Medium· 6.3
2d ago

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)

The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS). User-supplied data originating from imported crawler captures—specifically item IDs, URLs, and screenshot file path…

▾ Sunlitail project · ail frameworkEPSS 0.32%via NVD
CVE-2026-93641Critical· 9.3
2d ago

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.27%via NVD
CVE-2026-85029High· 7.5
2d ago

IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.

IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.54%via NVD
CVE-2026-93643Critical· 9.8
2d ago

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.96%via NVD
CVE-2026-93647Critical· 9.3
2d ago

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

▾ MidnightZimbra · Zimbra Collaboration Suite (ZCS)EPSS 0.23%via NVD
CVE-2026-84893High· 7.6
2d ago

IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service

IBM Guardium Data Protection 12.2 is vulnerable to SQL injection in the PESI service. An authenticated attacker could exploit this vulnerability to access sensitive information in the internal database.

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.18%via NVD
CVE-2026-84884High· 7.5
2d ago

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format

IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an ad…

▾ TwilightIBM · Guardium Data ProtectionEPSS 0.24%via NVD
CVE-2026-52622High· 7.5
2d ago

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

An issue in Wellav Technologies Co., Ltd Wellav WES Emergency Broadcast Terminal WES100, WES270, WES280, and WES290 before 08-08-2023 allows a remote attacker to obtain sensitive information via the global API request wrapper function

▾ TwilightEPSS 0.30%via NVD
CVE-2026-51772NonePoC
2d ago

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance

A Server-Side Request Forgery (SSRF) vulnerability exists in the Image API (v2) of OpenStack Glance. When the show_multiple_locations configuration option is enabled in glance-api.conf, an authenticated attacker can manipulate the locati…

▾ TwilightEPSS 0.31%via NVD
CVE-2026-51773High· 8.1PoC
2d ago

An issue in the VMware datastore driver of OpenStack glance_store

An issue in the VMware datastore driver of OpenStack glance_store. When an authenticated attacker provides a maliciously crafted image location URI pointing to an external server, the _retry_request function fails to validate the destina…

▾ MidnightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.32%via NVD
CVE-2026-88420None
2d ago

A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute arbitrary code in the context of the …

A reflected cross-site scripting (XSS) vulnerability in the EntryAbstract.save() component of APSL puput v1.2.1 through v2.2.0 allows authenticated attackers with Wagtail Editor privileges to execute arbitrary code in the context of the …

▾ SunlitEPSS 0.15%via NVD
CVE-2026-78902Medium· 6.1PoC
2d ago

Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package

Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via the pfBlockerNG package

▾ TwilightEPSS 0.30%via NVD
CVE-2026-95832Critical· 9.3
2d ago

Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in…

Improper Neutralization of Special Elements in Output Used by a Downstream Component in the colour control escape code handler in kitty from 0.47.3 before 0.49.0 allows a program writing to the terminal to execute an arbitrary command in…

▾ MidnightKovid Goyal · kittyEPSS 0.16%via NVD
CVE-2026-88421High· 7.5PoC
2d ago

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the si…

Incorrect access control in the BlogPage.get_entries() component of APSL puput v1.2.1 through v2.2.0 allows unauthenticated attackers to view restricted blog entries via the blog index, the tag, category, author and date archives, the si…

▾ MidnightEPSS 0.30%via NVD
CVE-2025-51457High· 8.8PoC
2d ago

D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint

D-Link DAP-2610 up to 2.06B08r099 contains an authenticated command injection vulnerability within the web interface at the /index.xgi endpoint. An attacker with authenticated access can exploit some parameters to execute arbitrary syste…

▾ MidnightEPSS 1.3%via NVD
CVE-2026-79153High· 7.8
2d ago

Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected s…

Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected s…

▾ TwilightEPSS 0.09%via NVD
CVEs tagged “nvd” — page 21 · VulnSea