VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29856 CVEsRSS

CVE-2026-57133High· 8.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tools/utility-tools.ts checks only the first whitespace-delimited token against safeCommands and then passes the compl…

▾ MidnightMervinPraison · PraisonAIEPSS 0.80%via NVD
CVE-2026-86472Medium· 4.8
2w ago

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv

fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3.0.0 through 3.1.7, and from 4.0.0 through 4.1.4, fast-uri folds the host to lowercase before it percent-decodes the …

▾ Sunlitfast-uri · fast-uriEPSS 0.25%via NVD
CVE-2026-57140Critical· 9.4
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authe…

▾ MidnightMervinPraison · PraisonAIEPSS 0.64%via NVD
CVE-2026-57136High· 8.8PoC
2w ago

PraisonAI is a multi-agent teams system

PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sandbox-executor.ts validates only the first whitespace-delimited executable against allowedCommands, then SandboxExec…

▾ MidnightMervinPraison · PraisonAIEPSS 0.55%via NVD
CVE-2026-91859Medium· 5.3
2w ago

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time

Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a re…

▾ SunlitMISP · MISPEPSS 0.47%via NVD
CVE-2026-19515High· 7.0
2w ago

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources

The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary op…

▾ TwilightWSO2 · WSO2 Integrator: MI for Visual Studio CodeEPSS 0.14%via NVD
CVE-2025-5802Medium· 5.3
2w ago

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence

The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error messag…

▾ SunlitWSO2 · WSO2 API ManagerEPSS 0.25%via NVD
CVE-2025-13166Low· 3.7
2w ago

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an …

▾ SunlitWSO2 · WSO2 Identity ServerEPSS 0.22%via NVD
CVE-2026-91857Medium· 5.3
2w ago

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  …

Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist()  …

▾ SunlitMISP · MISPEPSS 0.21%via NVD
CVE-2026-59341Medium· 4.2PoC
2w ago

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints

A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can a…

▾ TwilightBitnami · sealed-secretsEPSS 0.40%via NVD
CVE-2026-91851Medium· 5.3
2w ago

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one…

Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one…

▾ SunlitMISP · MISPEPSS 0.35%via NVD
CVE-2026-91846High· 7.1
2w ago

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselv…

Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselv…

▾ TwilightMISP · MISPEPSS 0.35%via NVD
CVE-2026-91826Medium· 4.4
2w ago

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b821…

▾ SunlitSamsung Opensource · rLottieEPSS 0.14%via NVD
CVE-2026-91782Low· 3.3
2w ago

A vulnerability was detected in GNU Binutils 2.47

A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null poi…

▾ Sunlitgnu · binutilsEPSS 0.18%via NVD
CVE-2026-91781Low· 3.3PoC
2w ago

A security vulnerability has been detected in GNU Binutils 2.47

A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer derefer…

▾ Twilightgnu · binutilsEPSS 0.18%via NVD
CVE-2026-91780Low· 3.3PoC
2w ago

A weakness has been identified in GNU Binutils 2.47

A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally.…

▾ Twilightgnu · binutilsEPSS 0.17%via NVD
CVE-2026-87730None
2w ago

Rejected reason: this is rejected

Rejected reason: this is rejected

▾ Sunlitvia NVD
CVE-2026-80217High· 8.8
2w ago

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

▾ TwilightLITE-ON Technology Corporation · FF-RFI079I4EPSS 0.51%via NVD
CVE-2026-77853High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

▾ TwilightLITE-ON Technology Corporation · FF-RFI079I4EPSS 1.9%via NVD
CVE-2026-76159High· 7.0
2w ago

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attack…

Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attack…

▾ TwilightDuplicati · DuplicatiEPSS 0.13%via NVD
CVE-2026-91825High· 7.1
2w ago

Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distributi…

Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distributi…

▾ TwilightMISP · MISPEPSS 0.39%via NVD
CVE-2026-91779Low· 3.3PoC
2w ago

A security flaw has been discovered in GNU Binutils 2.47

A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dere…

▾ Twilightgnu · binutilsEPSS 0.17%via NVD
CVE-2026-75092High· 7.3
2w ago

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository)

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root…

▾ TwilightRed Hat · leapp-repositoryEPSS 0.13%via NVD
CVE-2026-91819Medium· 6.9
2w ago

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request…

Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request…

▾ SunlitMISP · MISPEPSS 0.20%via NVD
CVE-2026-91091Medium· 4.3PoC
2w ago

A vulnerability was identified in GPAC up to f1219cde

A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption.…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-91090Low· 3.9
2w ago

A vulnerability was determined in GPAC up to f1219cde

A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the file scenegraph/base_scenegraph.c. This manipulation causes stack-based buffer overflow. It is possible to launch the …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-91778High· 7.2
2w ago

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker)

In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would a…

▾ TwilightOctopus Deploy · Octopus ServerEPSS 0.43%via NVD
CVE-2026-91089Medium· 6.3
2w ago

A vulnerability was found in GPAC up to f1219cde

A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegraph/base_scenegraph.c. The manipulation results in use after free. It is possible to launch the attack remotely. The ex…

▾ SunlitEPSS 0.51%via NVD
CVE-2026-91088Medium· 4.8PoC
2w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file utils/url.c of the component URL Handler. The manipulation leads to heap-based buffer overflow. An attack has to be …

▾ TwilightEPSS 0.16%via NVD
CVE-2026-91087High· 7.3PoC
2w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. This vulnerability affects the function gf_mo_get_od_id of the file compositor/media_object.c of the component Compositor. Executing a manipulation can lead to use after free. The attack may …

▾ MidnightEPSS 0.64%via NVD
CVEs tagged “nvd” — page 304 · VulnSea