VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

27498 CVEsRSS

CVE-2026-77401Medium· 6.8
2w ago

Zope AccessControl provides a general security framework for use in Zope

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map …

▾ Sunlitzopefoundation · AccessControlEPSS 0.47%via NVD
CVE-2026-92380High· 7.3PoC
2w ago

A flaw has been found in WuzhiCMS up to 4.1.0

A flaw has been found in WuzhiCMS up to 4.1.0. The impacted element is the function ckditor::saveRemote of the file coreframe/app/attachment/index.php of the component Remote Image Fetch. This manipulation of the argument source[] causes…

▾ MidnightEPSS 0.50%via NVD
CVE-2026-77408Critical· 9.1
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, the writeShortstr function in write.go casts the byte length of AMQP shortstr property values to uint8 without first rejecting values longer than 255 bytes. An application t…

▾ Midnightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-92395Critical· 9.1
2w ago

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips

@fastify/proxy-addr is a Fastify plugin that determines a request's client address behind trusted reverse proxies, and it backs Fastify request.ip and request.ips. In versions 3.0.0 through 5.1.0, a trust subnet written in IPv4-mapped IP…

▾ Midnight@fastify/proxy-addr · @fastify/proxy-addrEPSS 0.33%via NVD
CVE-2026-77407High· 7.0
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection…

▾ Twilightrabbitmq · amqp091-goEPSS 0.13%via NVD
CVE-2026-77406High· 8.2
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

▾ Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77403High· 8.9
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not en…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-92616Medium· 6.8
2w ago

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interfa…

FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege attackers to gain unauthorized read and write access by exploiting improper session isolation between the WebDAV interfa…

▾ Sunliterror311 · FileRiseEPSS 0.39%via NVD
CVE-2026-77410High· 8.9
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation …

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-92568Medium· 5.4PoC
2w ago

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses

MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows authenticated users to make the API server send arbitrary HTTP requests to internal addresses. Attackers can update …

▾ Twilightmlrun · mlrunEPSS 0.33%via NVD
CVE-2026-92569Medium· 4.3PoC
2w ago

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter

Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that fail to validate the clientAddress parameter. Authenticated attackers can supply arbitrary hostnames and ports to trig…

▾ Twilightopengoofy · hippo4jEPSS 0.34%via NVD
CVE-2026-92566High· 8.2PoC
2w ago

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI

DataGear through 6.0.0 contains a server-side request forgery vulnerability in the /dataSet/preview/Http endpoint that allows unauthenticated attackers to execute arbitrary HTTP requests by supplying a caller-controlled URI. Attackers ca…

▾ Midnightdatageartech · datagearEPSS 0.54%via NVD
CVE-2026-92565Medium· 5.3
2w ago

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers

Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns scheduled-event invitee names and email addresses to unauthenticated callers. Attackers can access a poll's urlId from pub…

▾ Sunlitlukevella · ralllyEPSS 0.46%via NVD
CVE-2026-92570Medium· 6.5PoC
2w ago

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files

reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any authenticated user to read bundled recon tool configuration files. Attackers with low-privilege Auditor roles can ac…

▾ Twilightyogeshojha · rengineEPSS 0.44%via NVD
CVE-2026-92567Medium· 6.5
2w ago

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data

TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update endpoint that allows authenticated users to overwrite other users' form submission data. Attackers can discover submi…

▾ SunlitTDuckCloud · tduck-survey-formEPSS 0.42%via NVD
CVE-2026-77404High· 8.7
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, URI.String in uri.go concatenates CertFile, KeyFile, CACertFile, and ServerName values directly into an AMQPS query string instead of encoding them as URL query parameters w…

▾ Twilightrabbitmq · amqp091-goEPSS 0.10%via NVD
CVE-2026-82964High· 8.8PoC
2w ago

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox…

▾ MidnightGen Digital · Avast Free Antivirus, Avast One, Avast Premium Security, Avast Ultimate, Avast Business SecurityEPSS 0.16%via NVD
CVE-2026-77412High· 8.9
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readField in read.go reads the length of an AMQP byte-array field with type tag x into a signed int32 and passes the value directly to make when allocating the field buffer.…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77405Critical· 9.4
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, tlsConfigFromURI in uri.go creates tls.Config values without setting MinVersion to tls.VersionTLS12. Builds using a Go runtime whose default permits TLS 1.0 or TLS 1.1 can t…

▾ Midnightrabbitmq · amqp091-goEPSS 0.28%via NVD
CVE-2026-92381Low· 3.5PoC
2w ago

A weakness has been identified in PbootCMS up to 3.2.22

A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title…

▾ TwilightEPSS 0.35%via NVD
CVE-2026-84997High· 7.5PoC
2w ago

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP

react/http is an event-driven, streaming HTTP client and server implementation for ReactPHP. From 0.6.0 until 1.11.1, React\Http\Io\ChunkedDecoder could enter an infinite loop while processing a malformed Transfer-Encoding: chunked body …

▾ Midnightreactphp · httpEPSS 0.66%via NVD
CVE-2026-77411Critical· 9.5
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, readLongstr in read.go returns an empty string and a nil error when a declared AMQP longstr length exceeds 0x7FFFFFFF instead of returning ErrSyntax. The function leaves the…

▾ Midnightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77409High· 8.2
2w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.dispatch in channel.go, confirms.confirm in confirms.go, and Connection.dispatch0 in connection.go synchronously send publisher confirmations, flow-control events, c…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-63128High· 7.5PoC
2w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-fo…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.63%via NVD
CVE-2026-63127High· 8.2PoC
2w ago

RMCP is an official Rust SDK for the Model Context Protocol

RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's OAuth implementation in crates/rmcp/src/transport/auth.rs omits the RFC 9728 resource field from ResourceServerMetadata and allows discover_oau…

▾ Midnightmodelcontextprotocol · rust-sdkEPSS 0.20%via NVD
CVE-2026-84860High· 8.8
2w ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-met…

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-met…

▾ TwilightScada-LTS · Scada-LTSEPSS 0.48%via NVD
CVE-2026-84858High· 8.8
2w ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supp…

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supp…

▾ TwilightScada-LTS · Scada-LTSEPSS 0.84%via NVD
CVE-2026-84859Medium· 6.5
2w ago

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array

ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values in this array are concatenated directly into the SQ…

▾ SunlitScada-LTS · Scada-LTSEPSS 0.36%via NVD
CVE-2026-18212High· 7.5
2w ago

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zl…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.52%via NVD
CVE-2026-74909High· 8.1
2w ago

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …

▾ TwilightRed Hat · rhbk/keycloak-operator-bundleEPSS 0.85%via NVD
CVEs tagged “nvd” — page 216 · VulnSea