VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29031 CVEsRSS

CVE-2023-54398Critical· 9.8PoC
2w ago

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialize…

▾ AbyssalYonyou · U8 CloudEPSS 0.64%via NVD
CVE-2026-19780High· 8.80day
2w ago

Koha Eval Code Injection Remote Code Execution Vulnerability

Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific…

▾ AbyssalKoha · KohaEPSS 0.58%via NVD
CVE-2026-89022High· 7.4
2w ago

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing…

BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing…

▾ Twilightbookstackapp · bookstackEPSS 0.46%via NVD
CVE-2026-91853High· 7.4PoC
2w ago

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224

A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpn of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user of the component Export Ovpn Handler. The manipulation…

▾ MidnightTOTOLINK · X5000REPSS 1.8%via NVD
CVE-2026-79699Medium· 4.4
2w ago

A flaw was found in the containers/storage library

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by st…

▾ SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.17%via NVD
CVE-2026-79705Medium· 4.5
2w ago

A flaw was found in the buildah/copier Go package

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…

▾ SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.38%via NVD
CVE-2026-58200High· 7.1
2w ago

Payload Plugins is a collection of plugins designed to enhance Payload CMS

Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose hand…

▾ Twilightjhb-software · payload-pluginsEPSS 0.31%via NVD
CVE-2026-91854Medium· 4.3PoC
2w ago

A vulnerability was identified in code-projects Record Management System 1.0

A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the file main/reg.php. Such manipulation of the argument desc leads to cross site scripting. The attack may be launched remo…

▾ Twilightcode-projects · Record Management SystemEPSS 0.47%via NVD
CVE-2026-88621Low· 2.7
2w ago

OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php

OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application…

▾ SunlitEPSS 0.31%via NVD
CVE-2026-77972Critical· 9.0
2w ago

Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the addre…

Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the addre…

▾ MidnightSlab · safeurlEPSS 0.33%via NVD
CVE-2026-77866Critical· 9.0
2w ago

Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the rese…

Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the rese…

▾ MidnightSlab · safeurlEPSS 0.48%via NVD
CVE-2026-88619High· 8.1
2w ago

1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module

1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a …

▾ TwilightEPSS 0.36%via NVD
CVE-2026-85013High· 7.3PoC
2w ago

A flaw was found in environment-modules

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `…

▾ MidnightRed Hat · environment-modules-mainEPSS 0.22%via NVD
CVE-2026-47215Medium· 4.8
2w ago

SingularityCE and SingularityPRO are open source container platforms

SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a conta…

▾ Sunlitsylabs · singularityEPSS 0.15%via NVD
CVE-2026-87791High· 8.7
2w ago

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme

A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible …

▾ TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.54%via NVD
CVE-2026-91848High· 7.3PoC
2w ago

A vulnerability was identified in WuzhiCMS up to 4.1.0

A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads t…

▾ MidnightEPSS 0.43%via NVD
CVE-2026-91930High· 7.5PoC
2w ago

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs

Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, cre…

▾ MidnightFlowiseAI · FlowiseEPSS 0.40%via NVD
CVE-2024-58384Medium· 5.4
2w ago

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers

Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitr…

▾ Sunlittornadoweb · tornadoEPSS 0.24%via NVD
CVE-2024-14029High· 7.5PoC⚖ disputed
2w ago

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deploye…

▾ Midnighttornadoweb · tornadoEPSS 0.35%via NVD
CVE-2023-54397High· 7.5
2w ago

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters

Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy val…

▾ Twilighttornadoweb · tornadoEPSS 0.37%via NVD
CVE-2026-91932High· 8.5PoC
2w ago

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter

Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean fil…

▾ MidnightFlowiseAI · FlowiseEPSS 0.73%via NVD
CVE-2026-91929High· 7.1
2w ago

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations

Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves i…

▾ TwilightFlowiseAI · FlowiseEPSS 0.35%via NVD
CVE-2026-91937High· 7.5
2w ago

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node

Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to r…

▾ TwilightFlowiseAI · FlowiseEPSS 0.47%via NVD
CVE-2026-91936Medium· 6.8PoC
2w ago

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks

Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shel…

▾ TwilightFlowiseAI · FlowiseEPSS 0.46%via NVD
CVE-2026-91934High· 8.8
2w ago

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files

Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to sy…

▾ TwilightFlowiseAI · FlowiseEPSS 0.74%via NVD
CVE-2026-91941High· 7.5
2w ago

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service

Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to …

▾ Twilightunclecode · crawl4aiEPSS 0.49%via NVD
CVE-2026-91933High· 7.1
2w ago

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid

Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can i…

▾ TwilightFlowiseAI · FlowiseEPSS 0.35%via NVD
CVE-2026-91931High· 8.5PoC
2w ago

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter

Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invok…

▾ MidnightFlowiseAI · FlowiseEPSS 0.68%via NVD
CVE-2026-91940High· 7.5PoC
2w ago

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields

crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies w…

▾ Midnightunclecode · crawl4aiEPSS 0.46%via NVD
CVE-2026-91938High· 7.1
2w ago

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection

Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, inte…

▾ TwilightFlowiseAI · FlowiseEPSS 0.37%via NVD
CVEs tagged “nvd” — page 279 · VulnSea