VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

28073 CVEsRSS

CVE-2026-73165High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-92359Low· 3.1
2w ago

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0

A security flaw has been discovered in ag-ui-protocol ag-ui 0.3.0. The affected element is the function create_strands_app of the file integrations/aws-strands/python/src/ag_ui_strands/utils.py of the component CORSMiddleware. The manipu…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.27%via NVD
CVE-2026-19535High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to …

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the LuCI administrative web interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 that allows a remote unauthenticated attacker to …

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 0.24%via NVD
CVE-2026-88817High· 8.7
2w ago

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, …

An authenticated, non-guest user of Curiosity Workspace could enroll themselves as an administrator and member of an existing access group without an invitation or approval. It did not grant application-wide administrator privileges, …

▾ TwilightCuriosity GmbH · Curiosity WorkspaceEPSS 0.35%via NVD
CVE-2026-92360Medium· 6.3
2w ago

A weakness has been identified in ag-ui-protocol ag-ui 1.0

A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of the file agent/agent.ts of the component Event Application Layer. This manipulation of the argument TEXT_MESSAGE_STA…

▾ Sunlitag-ui-protocol · ag-uiEPSS 0.21%via NVD
CVE-2026-73163High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-73164High· 8.6
2w ago

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the web management interface of Advantech EKI-1242IEIMS in firmware version V1.06.01 th…

▾ TwilightAdvantech · EKI-1242IEIMSEPSS 1.2%via NVD
CVE-2026-92455Medium· 4.3PoC
2w ago

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers

yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, allowing any authenticated back-office user to send SMS and email to arbitrary customers. Attackers can invoke POST /a…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.36%via NVD
CVE-2026-92458Medium· 4.3PoC
2w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that allows authenticated back-office users to modify product sale status. Attackers can invoke the GET /admin-api/produc…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.35%via NVD
CVE-2026-92457Medium· 6.5PoC
2w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint that allows authenticated back-office users to issue arbitrary invoices. Attackers can call the PUT /admin-api/crm/i…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-92456High· 7.1PoC
2w ago

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

yshop-crm through 2.1.3 fails to enforce authorization on the saveRedisSet and getRedisSet endpoints in CrmCustomerController, allowing any authenticated back-office user to read and modify installation-wide lead-allocation and customer …

▾ Midnightguchengwuyue · yshop-crmEPSS 0.50%via NVD
CVE-2026-92463Medium· 6.5PoC
2w ago

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @PreAuthorize annotation is commented out, allowing authenticated back-office users without system:user:list permission t…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.46%via NVD
CVE-2026-92460Medium· 6.5PoC
2w ago

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail

yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any authenticated back-office user to access the installation-wide audit trail. Attackers can query the operation log to …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.45%via NVD
CVE-2026-92461Medium· 4.3PoC
2w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoint that allows any logged-in back-office user to access approval workflow data. Attackers can retrieve approval chain …

▾ Twilightguchengwuyue · yshop-crmEPSS 0.38%via NVD
CVE-2026-92459Medium· 6.5PoC
2w ago

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks

yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoint that allows authenticated back-office users to claim sales leads without proper permission checks. Attackers can in…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-40854High· 8.7
2w ago

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component

WNC T-Mobile 5G Box IDU router contains an authentication bypass vulnerability in the portal.cgi component. The session verification mechanism improperly validates the sessionid cookie by checking for the existence of a corresponding fil…

▾ TwilightWNC · T-Mobile 5G Box IDUEPSS 0.32%via NVD
CVE-2026-92462Medium· 6.5PoC
2w ago

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps

yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing any authenticated back-office user to delete arbitrary approval workflow steps. Attackers can invoke the DELETE /adm…

▾ Twilightguchengwuyue · yshop-crmEPSS 0.43%via NVD
CVE-2026-58146Critical· 9.4
2w ago

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability

WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the /cgi-bin/portal.cgi endpoint, specifically through the cli_cookie POST parameter. The cli_cookie parameter value is d…

▾ MidnightWNC · T-Mobile 5G Box IDUEPSS 2.9%via NVD
CVE-2026-40855Critical· 9.3
2w ago

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection

WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality within the /cgi-bin/portal.cgi endpoint, specifically affecting the ping_ip, ping_size, and ping_times POST parameter…

▾ MidnightWNC · T-Mobile 5G Box IDUEPSS 1.6%via NVD
CVE-2026-92465High· 7.6
2w ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum WP Mega Menu allows Blind SQL Injection. This issue affects WP Mega Menu: from n/a through 1.4.2.

▾ TwilightThemeum · wp-megamenuEPSS 0.38%via NVD
CVE-2026-40857High· 8.4
2w ago

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component

WNC T-Mobile 5G Box IDU router contains a cross-site request forgery (CSRF) vulnerability in the portal.cgi component. The anti-CSRF mechanism fails to validate the csrf_token_value parameter, accepting any arbitrary value as valid. This…

▾ TwilightWNC · T-Mobile 5G Box IDUEPSS 0.20%via NVD
CVE-2026-40856High· 7.1
2w ago

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control

WNC T-Mobile 5G Box IDU router is vulnerable to improper access control. The vulnerability exists in the wnc_maccheck.cgi endpoint, which is accessible without authentication. It allows a remote attacker to retrieve sensitive configurati…

▾ TwilightWNC · T-Mobile 5G Box IDUEPSS 0.37%via NVD
CVE-2026-58147Critical· 9.3
2w ago

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality

WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password change functionality. The application improperly neutralizes special elements in the http_passwd_hidden and http_passwdC…

▾ MidnightWNC · T-Mobile 5G Box IDUEPSS 1.6%via NVD
CVE-2026-92357Medium· 4.3
2w ago

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0

A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-processor.ts of the component Model Processor. The manipulation of the argument current[segment] leads to information disc…

▾ Sunlita2ui-project · a2uiEPSS 0.39%via NVD
CVE-2026-86585High· 7.7
2w ago

The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

The lack of signature verification of firmware update packages in VEO and VEO-XS Wi-Fi monitors, in versions prior to 01.48.001, allows an attacker who controls the delivery of an update to install unauthorised firmware.

▾ TwilightFermax Electronica S.A.U. · DUOX PLUS monitor firmware (VEO Wi-Fi range)EPSS 0.16%via NVD
CVE-2026-14916High· 7.7
2w ago

A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise

A JWT signature verification vulnerability affects Kong components that perform JWT validation for MCP OAuth2 or DataKit integrations inside Kong API Gateway Enterprise. The affected code does not properly validate that the JWT signing a…

▾ TwilightKong · Kong Enteprise GatewayEPSS 0.67%via NVD
CVE-2026-92356Medium· 4.3
2w ago

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1

A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption.…

▾ Sunlita2ui-project · a2uiEPSS 0.52%via NVD
CVE-2026-8462High· 8.9
2w ago

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service…

SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all platforms allows a remote unauthenticated attacker to access or modify metering event data, and potentially cause denial of service…

▾ Twilightopenmeter · openmeterEPSS 0.51%via NVD
CVE-2026-89795High· 8.4
2w ago

In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset on s390 On s390 systems, which use a machine level hypervisor, PCI devices are always accessed through a form of PC…

In the Linux kernel, the following vulnerability has been resolved: PCI: Allow per function PCI slots to fix slot reset on s390 On s390 systems, which use a machine level hypervisor, PCI devices are always accessed through a form of PC…

▾ TwilightLinux · LinuxEPSS 0.17%via NVD
CVE-2026-89794None
2w ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: zero pipe read compound padding Compound response handling extends the last response iov to an eight-byte boundary. smb2_read_pipe() allocates only the payload…

In the Linux kernel, the following vulnerability has been resolved: ksmbd: zero pipe read compound padding Compound response handling extends the last response iov to an eight-byte boundary. smb2_read_pipe() allocates only the payload…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVEs tagged “nvd” — page 222 · VulnSea