VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

28071 CVEsRSS

CVE-2026-77692High· 7.5
2w ago

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9…

An attacker can cause `named` to abort by sending a crafted DNS-over-HTTPS request with a cryptographically invalid SIG(0) record, and then closing the transport connection prematurely. This issue affects BIND 9 versions 9.20.0 through 9…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-19941Medium· 5.9
2w ago

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…

An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an attacker at the same or an upstream level of the zone name to mask the existence of a victim's wildcard record. This…

▾ SunlitISC · BIND 9EPSS 0.23%via NVD
CVE-2026-19662Medium· 5.9
2w ago

An attacker may be able to cause a `named` resolver to abort

An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send multiple queries for a DNSSEC-signed zone hosted by an authoritative server under the control of the attacker. If the …

▾ SunlitISC · BIND 9EPSS 0.45%via NVD
CVE-2026-73177High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01

Nozomi Networks Labs identified a CWE-345: Insufficient Verification of Data Authenticity vulnerability in the firmware upgrade mechanism of the Advantech EKI-1242EIMS in firmware version V1.06.01. The device accepts firmware images thro…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.15%via NVD
CVE-2026-92362High· 7.3
2w ago

A vulnerability was detected in ag-ui-protocol ag-ui 1.0

A vulnerability was detected in ag-ui-protocol ag-ui 1.0. This impacts an unknown function of the file crates/ag-ui-client/src/sse.rs of the component SSE Frame Parser. Performing a manipulation results in resource consumption. The attac…

▾ Twilightag-ui-protocol · ag-uiEPSS 0.53%via NVD
CVE-2026-91843Critical· 9.8PoC
2w ago

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

▾ Abyssalcheckpoint · Quantum Security ManagementEPSS 0.52%via NVD
CVE-2026-92469High· 8.1PoC
2w ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the file-center module DELETE /files/{id} endpoint that performs no ownership validation. Authenticated attackers can enumerate file identifie…

▾ Midnightzlt2000 · microservices-platformEPSS 0.54%via NVD
CVE-2026-92467High· 8.3PoC
2w ago

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check

zlt2000 microservices-platform through 6.0.0 contains an unverified password change vulnerability in the PUT /users/password endpoint that allows authenticated users to change any account password by omitting the current password check. …

▾ Midnightzlt2000 · microservices-platformEPSS 0.46%via NVD
CVE-2026-56719Medium· 6.5
2w ago

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a m…

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a m…

▾ SunlitMikroTik · RouterOSEPSS 0.39%via NVD
CVE-2026-92468Medium· 6.5PoC
2w ago

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service that allows authenticated attackers to read any Elasticsearch index by specifying the index name in POST /search/{in…

▾ Twilightzlt2000 · microservices-platformEPSS 0.48%via NVD
CVE-2026-89028High· 7.5
2w ago

MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX ha…

MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX ha…

▾ TwilightMikroTik · RouterOSEPSS 0.58%via NVD
CVE-2026-92466High· 8.8PoC
2w ago

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication

zlt2000 microservices-platform through 6.0.0 contains a missing authorization vulnerability where the zlt.security.auth.urlPermission.enable flag defaults to false, disabling all permission checks after authentication. Authenticated user…

▾ Midnightzlt2000 · microservices-platformEPSS 0.91%via NVD
CVE-2026-92363Medium· 4.3
2w ago

A flaw has been found in ag-ui-protocol ag-ui 1.0

A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp of the component JSON Parser. Executing a manipulation can lead to resource consumption. The attack may be performed…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.55%via NVD
CVE-2026-85104Medium· 5.3
2w ago

In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters.

In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation parameters.

▾ SunlitSooma · Sooma tDCS Home TherapyEPSS 0.16%via NVD
CVE-2026-19667High· 7.5
2w ago

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes

If an attacker-controlled authoritative server can produce a negative answer that is exactly 65536 bytes, then a flaw in `named` results in a negative cache entry of 0 bytes. When this entry is subsequently read, `named` aborts. This iss…

▾ TwilightISC · BIND 9EPSS 0.55%via NVD
CVE-2026-92364Medium· 6.3PoC
2w ago

A vulnerability has been found in itsourcecode Leave Management System 1.0

A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /module/employee/index.php. The manipulation of the argument ID leads to sql injection. It…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.33%via NVD
CVE-2026-81736High· 7.5
2w ago

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 t…

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, and is then queried for the root of that tree, the resolver will spend disproportionate CPU time constructing the response. This issue affects BIND 9 versions 9.18.0 t…

▾ TwilightISC · BIND 9EPSS 0.86%via NVD
CVE-2026-61590High· 7.4
2w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's observability endpoints expose live view/session state and a remote method-invocation surface …

▾ Twilightdjust-org · djustEPSS 0.36%via NVD
CVE-2026-92361Medium· 4.3
2w ago

A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0

A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdks/community/go/pkg/client/sse/client.go of the component SSE Client. Such manipulation leads to resource consumption.…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.53%via NVD
CVE-2026-61598High· 7.1
2w ago

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance

djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, `djust.mixins.model_binding.ModelBindingMixin` provides a default `update_model` event handler and is …

▾ Twilightdjust · djustEPSS 0.43%via NVD
CVE-2026-73176High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-73175High· 7.1
2w ago

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust…

Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption vulnerability in the OPC UA gateway component of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows an adjacent unauthenticated attacker to exhaust…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.26%via NVD
CVE-2026-73174High· 8.7
2w ago

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive o…

Nozomi Networks Labs identified a CWE-319: Cleartext Transmission of Sensitive Information vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a network-adjacent passive o…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.16%via NVD
CVE-2026-73173High· 8.8
2w ago

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attack…

Nozomi Networks Labs identified a CWE-306: Missing Authentication for Critical Function vulnerability in the edgserver management protocol of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote unauthenticated attack…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.71%via NVD
CVE-2026-73172Critical· 9.3
2w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the edgserver management service of Advantech EKI-1242EIMS in firmware version V1.06.01…

▾ MidnightAdvantech · EKI-1242IEIMSEPSS 2.2%via NVD
CVE-2026-73171High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite …

Nozomi Networks Labs identified a CWE-73: External Control of File Name or Path vulnerability in the backup-restore workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated attacker to overwrite …

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.52%via NVD
CVE-2026-73170High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated…

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import workflow of Advantech EKI-1242EIMS in firmware version V1.06.01 that allows a remote authenticated…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.54%via NVD
CVE-2026-73169Medium· 6.3
2w ago

Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.…

Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in the Modbus transaction management interface of Advantech EKI-1242EIMS in firmware version V1.…

▾ SunlitAdvantech · EKI-1242IEIMSEPSS 0.54%via NVD
CVE-2026-73167High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-73166High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote authenticated …

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.70%via NVD
CVEs tagged “nvd” — page 221 · VulnSea