VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29856 CVEsRSS

CVE-2026-92064High· 8.8⚖ disputed
2w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.11%via NVD
CVE-2026-92073High· 8.8⚖ disputed
2w ago

Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-92072High· 8.0⚖ disputed
2w ago

Incorrect boundary conditions in the Safe Browsing component

Incorrect boundary conditions in the Safe Browsing component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.24%via NVD
CVE-2026-92065High· 8.8⚖ disputed
2w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.11%via NVD
CVE-2026-92003Medium· 6.9
2w ago

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests…

Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API authentication failure branches wrote directly to the Log model:  - API requests with no authentication key;  - requests…

▾ SunlitMISP · MISPEPSS 0.57%via NVD
CVE-2026-91998Critical· 9.9PoC
2w ago

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizati…

▾ Abyssalcasdoor · casdoorEPSS 0.59%via NVD
CVE-2026-91997Medium· 5.3PoC
2w ago

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint

evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restricti…

▾ Twilightevolution-foundation · evolution-apiEPSS 0.45%via NVD
CVE-2026-91996High· 7.5PoC
2w ago

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map

lamp-cloud through 5.10.0 whitelists the path pattern /*/anno/** for anonymous access, allowing unauthenticated attackers to read the server's full JVM system property map. Attackers can send POST requests to /defGenProject/anno/getPrope…

▾ Midnightdromara · lamp-cloudEPSS 0.50%via NVD
CVE-2026-91995Critical· 9.1
2w ago

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password

pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username wit…

▾ Midnightpig-mesh · pigEPSS 0.88%via NVD
CVE-2026-91994Medium· 6.5PoC
2w ago

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware

Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddleware. Attackers with guest or task_runner roles can read all project environments including plaintext secrets, credenti…

▾ Twilightsemaphoreui · semaphoreEPSS 0.41%via NVD
CVE-2026-91993Medium· 4.3PoC
2w ago

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces

Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoint, allowing authenticated users to access repositories from other workspaces. Attackers can submit repository identif…

▾ Twilightdromara · JpomEPSS 0.34%via NVD
CVE-2026-91926Low· 3.7
2w ago

A flaw was found in gss-ntlmssp

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not …

▾ SunlitRed Hat · gssntlmsspEPSS 0.37%via NVD
CVE-2026-89308Critical· 9.3
2w ago

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

▾ MidnightTREXOM · TrxTimeATTENDANCEEPSS 2.1%via NVD
CVE-2026-92002Medium· 5.1
2w ago

Affected versions of MISP use Redis to throttle repeated authentication-failure log entries

Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid excessive duplicate logs while still recording failed authentication activity. However, User->setupRedis() returns fals…

▾ SunlitMISP · MISPEPSS 0.53%via NVD
CVE-2026-91925High· 8.8PoC
2w ago

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code

Polyaxon through 2.16.4 renders operation specification fields with an unsandboxed Jinja2 environment during server-side run preparation, allowing authenticated users to execute arbitrary code. Attackers can submit runs with Jinja2 paylo…

▾ Midnightpolyaxon · polyaxonEPSS 0.78%via NVD
CVE-2026-91924High· 8.5PoC
2w ago

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings

pgweb through 0.17.0 leaves the POST /api/connect endpoint unguarded when connect-backend authorization is configured, allowing attackers to supply arbitrary database connection strings. Attackers can bypass the resource-to-database mapp…

▾ Midnightsosedoff · pgwebEPSS 0.42%via NVD
CVE-2026-91923High· 7.7
2w ago

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions

KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply ar…

▾ Twilightkubesphere · kubesphereEPSS 0.45%via NVD
CVE-2026-91922Medium· 6.1PoC
2w ago

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements

Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/page/render endpoint that fails to properly escape query parameters in inline script elements. Attackers can craft mali…

▾ Twilightsteedos · steedos-platformEPSS 0.34%via NVD
CVE-2026-91786Medium· 6.1
2w ago

A flaw was found in GNOME Shell

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search pro…

▾ SunlitRed Hat · gnome-shellEPSS 0.13%via NVD
CVE-2026-86818Medium· 4.8
2w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parser in version 4.1.3. In versions 4.1.3 and 4.1.4, the mailto parser compares each query field name to the reserved nam…

▾ Sunlitfast-uri · fast-uriEPSS 0.25%via NVD
CVE-2026-80489Medium· 5.9
2w ago

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to h…

▾ SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-77117Medium· 5.9
2w ago

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to…

▾ SunlitThe GNU C Library · glibcEPSS 0.41%via NVD
CVE-2026-1759Medium· 6.5
2w ago

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

▾ SunlitSecomea · GateManagerEPSS 0.26%via NVD
CVE-2026-1758High· 8.3
2w ago

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

▾ TwilightSecomea · GateManagerEPSS 0.24%via NVD
CVE-2026-57141Critical· 9.8
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklis…

▾ MidnightMervinPraison · PraisonAIEPSS 0.74%via NVD
CVE-2026-57138Critical· 9.9
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blockl…

▾ MidnightMervinPraison · PraisonAIEPSS 0.73%via NVD
CVE-2026-57137High· 8.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, createAgentLoop() in src/praisonai-ts/src/ai/agent-loop.ts passes executable tools to generateText() before invoking the onToolCall approval callback. Because the wrapped A…

▾ MidnightMervinPraison · PraisonAIEPSS 0.51%via NVD
CVE-2026-57135High· 7.6PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment…

▾ MidnightMervinPraison · PraisonAIEPSS 0.42%via NVD
CVE-2026-57134High· 8.2PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, MCPSecurity.evaluatePolicy() in src/praisonai-ts/src/mcp/security.ts invokes the configured credential validator only when AuthMethod is api-key or bearer. Basic and OAuth …

▾ MidnightMervinPraison · PraisonAIEPSS 0.41%via NVD
CVE-2026-57139Critical· 9.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication …

▾ AbyssalMervinPraison · PraisonAIEPSS 0.75%via NVD
CVEs tagged “nvd” — page 303 · VulnSea