VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29856 CVEsRSS

CVE-2026-91980Medium· 4.3PoC
2w ago

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members

vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve comp…

▾ Twilightgo-vikunja · vikunjaEPSS 0.31%via NVD
CVE-2026-91972High· 7.5PoC
2w ago

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes

Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential gue…

▾ Midnightgo-vikunja · vikunjaEPSS 0.63%via NVD
CVE-2026-91971Medium· 6.5PoC
2w ago

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts

Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images wit…

▾ Twilightgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91982Medium· 4.3PoC
2w ago

Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication

Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a valid access toke…

▾ Twilightgo-vikunja · vikunjaEPSS 0.35%via NVD
CVE-2026-91981Medium· 4.3PoC
2w ago

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints

Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames ex…

▾ Twilightgo-vikunja · vikunjaEPSS 0.31%via NVD
CVE-2026-91979Medium· 6.5
2w ago

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service

Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausti…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.44%via NVD
CVE-2026-91986Medium· 5.4PoC
2w ago

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs

gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof …

▾ TwilightGitoxideLabs · gitoxideEPSS 0.23%via NVD
CVE-2026-91985High· 7.5PoC
2w ago

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential

Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-…

▾ Midnightgo-vikunja · vikunjaEPSS 0.43%via NVD
CVE-2026-91983Medium· 4.3PoC
2w ago

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters

Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restric…

▾ Twilightgo-vikunja · vikunjaEPSS 0.30%via NVD
CVE-2026-91990High· 7.5PoC
2w ago

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit

Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create lar…

▾ Midnighttornadoweb · tornadoEPSS 0.49%via NVD
CVE-2026-91987Medium· 6.5
2w ago

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table

atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers…

▾ Sunlitdep0we · atomic-agents-stackEPSS 0.48%via NVD
CVE-2026-91984Medium· 4.3
2w ago

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project

Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST o…

▾ Sunlitgo-vikunja · vikunjaEPSS 0.26%via NVD
CVE-2026-91989High· 7.5
2w ago

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths

atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass …

▾ Twilightdep0we · atomic-agents-stackEPSS 1.3%via NVD
CVE-2026-91988High· 8.1
2w ago

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses

atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argume…

▾ Twilightdep0we · atomic-agents-stackEPSS 0.32%via NVD
CVE-2026-65831High· 7.7
2w ago

ArcadeDB is a Multi-Model DBMS

ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions …

▾ TwilightArcadeData · arcadedbEPSS 0.60%via NVD
CVE-2026-91992Medium· 5.9PoC
2w ago

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing

Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through th…

▾ Twilighttornadoweb · tornadoEPSS 0.26%via NVD
CVE-2026-91991Medium· 5.4PoC
2w ago

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie

Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-de…

▾ Twilighttornadoweb · tornadoEPSS 0.28%via NVD
CVE-2026-87793Medium· 5.1
2w ago

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted …

▾ SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.51%via NVD
CVE-2026-87792High· 8.7
2w ago

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" conte…

▾ TwilightDevelopers Italia · design-scuole-wordpress-themeEPSS 0.46%via NVD
CVE-2026-19407High· 7.7
2w ago

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

▾ TwilightGoogle Cloud · Gemini Enterprise Agent Platform SDK for PythonEPSS 0.52%via NVD
CVE-2026-89307Medium· 5.1
2w ago

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (St…

▾ SunlitDevelopers Italia · design-scuole-wordpress-themeEPSS 0.36%via NVD
CVE-2026-88620Medium· 4.3
2w ago

SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint

SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allow…

▾ SunlitEPSS 0.28%via NVD
CVE-2026-91849Medium· 6.3PoC
2w ago

A security flaw has been discovered in WuzhiCMS up to 4.1.0

A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in …

▾ TwilightEPSS 0.37%via NVD
CVE-2026-37152Critical· 9.8PoC
2w ago

TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

▾ AbyssalEPSS 0.51%via NVD
CVE-2026-91842Medium· 4.1PoC
2w ago

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads t…

▾ TwilightOpenBankProject · OBP-APIEPSS 0.38%via NVD
CVE-2026-91836Low· 2.8PoC
2w ago

A flaw has been found in OpenClaw ClawScan up to 0.1.6

A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. …

▾ TwilightOpenClaw · ClawScanEPSS 0.33%via NVD
CVE-2026-88618Medium· 6.5PoC
2w ago

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality

1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.

▾ TwilightEPSS 0.34%via NVD
CVE-2026-88617Critical· 9.8
2w ago

SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint

SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.

▾ MidnightEPSS 0.61%via NVD
CVE-2026-79551High· 7.5PoC
2w ago

Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

▾ MidnightEPSS 0.30%via NVD
CVE-2026-79425High· 8.1PoC
2w ago

An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.

An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.

▾ MidnightEPSS 0.36%via NVD
CVEs tagged “nvd” — page 299 · VulnSea