VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29853 CVEsRSS

CVE-2026-82190Medium· 6.3
2w ago

Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site w…

Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site w…

▾ Sunlitj2commerce.com · J2Store extension for JoomlaEPSS 0.33%via NVD
CVE-2026-82189High· 8.7
2w ago

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue…

Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue…

▾ Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.43%via NVD
CVE-2026-81924Medium· 6.5⚖ disputed
2w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-suppl…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.21%via NVD
CVE-2026-81923Low· 2.7
2w ago

In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving

In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the per-page CSRF token but never called canEditPageProperties() for the target p…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.30%via NVD
CVE-2026-81922Low· 2.7
2w ago

Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap

Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the sitemap Explore dashboard controller, the send_to_top and send_to_bottom reorder tasks ran after only a generic sitem…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.30%via NVD
CVE-2026-81921Medium· 5.4⚖ disputed
2w ago

Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status

Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status. …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81920Medium· 4.3⚖ disputed
2w ago

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did no…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.18%via NVD
CVE-2026-81568High· 8.7
2w ago

Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concate…

Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concate…

▾ Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.50%via NVD
CVE-2026-81567High· 8.7
2w ago

Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g

Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer rec…

▾ Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.39%via NVD
CVE-2026-79411High· 8.8PoC
2w ago

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoin…

▾ MidnightEPSS 0.45%via NVD
CVE-2026-79410High· 8.1PoC
2w ago

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

▾ MidnightEPSS 0.39%via NVD
CVE-2026-79409Medium· 6.5PoC
2w ago

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

▾ TwilightEPSS 0.46%via NVD
CVE-2026-78081High· 7.1
2w ago

Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a victim's active checkout session could silently overwri…

Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a victim's active checkout session could silently overwri…

▾ Twilightj2commerce.com · J2Store extension for JoomlaEPSS 0.21%via NVD
CVE-2026-73467Medium· 6.3
2w ago

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

▾ SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-73466Medium· 6.3
2w ago

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit th…

On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit th…

▾ SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-73465Medium· 6.3
2w ago

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exp…

On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exp…

▾ SunlitArista Networks · EOSEPSS 0.13%via NVD
CVE-2026-69216Medium· 5.4
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the r…

▾ Sunlithttp4s · http4sEPSS 0.37%via NVD
CVE-2026-69214Medium· 6.8
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejec…

▾ Sunlithttp4s · http4sEPSS 0.40%via NVD
CVE-2026-69213High· 7.5
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can c…

▾ Twilighthttp4s · http4sEPSS 0.63%via NVD
CVE-2026-69212Medium· 5.9PoC
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect changes authority, but authority comparison excludes the URI…

▾ Twilighthttp4s · http4sEPSS 0.28%via NVD
CVE-2026-69211Medium· 4.8
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing semicolons or control characters. An a…

▾ Sunlithttp4s · http4sEPSS 0.33%via NVD
CVE-2026-69209High· 7.5
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts dec…

▾ Twilighthttp4s · http4sEPSS 0.63%via NVD
CVE-2026-69208High· 7.5
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is inverted. On an applic…

▾ Twilighthttp4s · http4sEPSS 0.77%via NVD
CVE-2026-69204Critical· 9.2
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing r…

▾ Midnighthttp4s · http4sEPSS 0.57%via NVD
CVE-2026-69201Medium· 5.9
2w ago

Http4s is a Scala interface for HTTP services

Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two dots. A request contai…

▾ Sunlithttp4s · org.http4s:http4s-server_2.12EPSS 0.76%via NVD
CVE-2026-68532Low· 2.3
2w ago

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery

Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type manage…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.30%via NVD
CVE-2026-68531Low· 2.1
2w ago

Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit …

Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit …

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.46%via NVD
CVE-2026-68530Low· 2.1
2w ago

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard

Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-su…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.47%via NVD
CVE-2026-68529Low· 2.1
2w ago

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action

Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly fro…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.44%via NVD
CVE-2026-66790None
2w ago

Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability

Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability. Please use CVE-2026-70496 instead.

▾ Sunlitvia NVD
CVEs tagged “nvd” — page 290 · VulnSea