VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29856 CVEsRSS

CVE-2026-91086Medium· 6.3PoC
2w ago

A security vulnerability has been detected in GPAC up to f1219cde

A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_process of the file filters/reframe_mpgvid.c of the component MPEG Video Reframer. Such manipulation leads to heap-based …

▾ TwilightEPSS 0.55%via NVD
CVE-2026-91005Medium· 6.3
2w ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded_file of the file production/edit_picture.php of the component Profile Picture Upload. Performing a manipulation of t…

▾ SunlitSourceCodester · Online Faculty Clearance SystemEPSS 0.37%via NVD
CVE-2026-90711Critical· 9.1
2w ago

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips

proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with …

▾ Midnightproxy-addr · proxy-addrEPSS 0.33%via NVD
CVE-2026-89141Medium· 6.5
2w ago

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a u…

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.7 via the 'mediaId' parameter due to missing validation on a u…

▾ Sunlittigroumeow · AI Engine – The Chatbot, AI Framework & MCP for WordPressEPSS 0.45%via NVD
CVE-2026-75983High· 7.5
2w ago

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23

The Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.1.23. This is due to the `PermissionManager::manage_permissions…

▾ Twilightarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.70%via NVD
CVE-2026-18063Medium· 6.4
2w ago

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping

The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter in all versions up to, and including, 2.8.1 due to insufficient input sanitization and output escaping. This makes it …

▾ Sunlitblueglassch · Job PostingsEPSS 0.20%via NVD
CVE-2026-15402Medium· 6.4
2w ago

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, …

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'etn_shedule_objective' schedule_slot Parameter in all versions up to, and including, …

▾ Sunlitarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.25%via NVD
CVE-2026-91004High· 7.3PoC
2w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. The impacted element is an unknown function of the file /delete_faculty1.php. Such manipulation of the argument ID leads to sql injection. The attack c…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-91003Critical· 9.1PoC
2w ago

A flaw has been found in D-Link DI-8300 16.07

A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exp…

▾ AbyssalD-Link · DI-8300EPSS 0.98%via NVD
CVE-2026-91002Medium· 5.3PoC
2w ago

A weakness has been identified in stamparm maltrail up to 3.0.1

A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of the file core/httpd.py of the component Blacklist Endpoint. Executing a manipulation can lead to missing authenticatio…

▾ Twilightstamparm · maltrailEPSS 0.77%via NVD
CVE-2026-91001Critical· 9.9PoC
2w ago

A security flaw has been discovered in D-Link DI-8400 16.07

A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip resul…

▾ AbyssalD-Link · DI-8400EPSS 0.93%via NVD
CVE-2026-86701Low· 2.5
2w ago

Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components

Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its components. A malicious application installed on the user's Android device may exploit the affected component via an Intent, p…

▾ SunlitNTT DOCOMO BUSINESS, Inc. · ManabiPocket for ParentsEPSS 0.14%via NVD
CVE-2026-81320Medium· 5.5
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and wri…

▾ SunlitRed Hat · rhbac-4/hawtio-rhel9EPSS 0.19%via NVD
CVE-2026-81303Medium· 6.3
2w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without valida…

▾ SunlitRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.49%via NVD
CVE-2026-18232Medium· 5.3
2w ago

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved …

The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning its content through one of its public AJAX actions, allowing unauthenticated attackers to read draft and unapproved …

▾ SunlitEPSS 0.21%via NVD
CVE-2026-17495Medium· 5.9
2w ago

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates

moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 through 2.30.1, a specially crafted non-string object passed to moment.locale() can bypass the locale-name path-traversal…

▾ Sunlitmoment · momentEPSS 0.36%via NVD
CVE-2026-16593Medium· 6.8
2w ago

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL in…

The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them in a SQL statement, allowing authenticated users with access to the page builder (Editor and above) to perform SQL in…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-16592Low· 2.7
2w ago

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-…

The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its shortcodes, allowing users with a role as low as Contributor to disclose non-public listing content, including password-…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-15758Medium· 5.3
2w ago

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter

The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.16.20 via the 'id' parameter. This makes it possible…

▾ Sunlitiberezansky · 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image GalleryEPSS 0.27%via NVD
CVE-2026-90881Medium· 5.3PoC
2w ago

A weakness has been identified in D-Link DIR-882 up to 20260814

A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.cgi of the component CGI Binary. Executing a manipulation can lead to information disclosure. The attack may be launc…

▾ TwilightD-Link · DIR-882EPSS 0.83%via NVD
CVE-2026-90880High· 7.4PoC
2w ago

A security flaw has been discovered in D-Link DSL-3782 2016-07-28

A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr resul…

▾ MidnightD-Link · DSL-3782EPSS 1.9%via NVD
CVE-2026-90879High· 7.3PoC
2w ago

A vulnerability was identified in zyx0814 FilePress up to 3.0.1

A vulnerability was identified in zyx0814 FilePress up to 3.0.1. This vulnerability affects unknown code of the file dzz/publish/search.php of the component Publish Module. Such manipulation of the argument orderby/order leads to sql inj…

▾ Midnightzyx0814 · FilePressEPSS 0.43%via NVD
CVE-2026-90878Medium· 4.3PoC
2w ago

A vulnerability was determined in vllm-project vLLM up to 0.27.1

A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/completions of the component Jinja Template Rendering. This manipulation of the argument chat_template causes resource co…

▾ Twilightvllm-project · vLLMEPSS 0.53%via NVD
CVE-2026-90877High· 7.3PoC
2w ago

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injec…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90876High· 7.3PoC
2w ago

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0

A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql inject…

▾ MidnightSourceCodester · Online Faculty Clearance SystemEPSS 0.43%via NVD
CVE-2026-90858High· 7.3PoC
2w ago

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578

A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of …

▾ Midnightsubhajitkhan · online-clinic-management-systemEPSS 0.52%via NVD
CVE-2026-90857Medium· 6.3PoC
2w ago

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0

A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown function of the file /dashboard/userprofile.php of the component Profile Upload. Performing a manipulation of the argument…

▾ TwilightSourceCodester · College Notes Gallery Management SystemEPSS 0.37%via NVD
CVE-2026-90856High· 7.3PoC
2w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. This impacts an unknown function of the file signup.php of the component Registration Flow. Such manipulation of the argument role …

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.50%via NVD
CVE-2026-90855High· 7.3PoC
2w ago

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0

A weakness has been identified in SourceCodester/katojkalemba Online Food Ordering System 1.0. This affects an unknown function of the file /web/order.php. This manipulation of the argument ID causes sql injection. The attack can be init…

▾ MidnightSourceCodester · Online Food Ordering SystemEPSS 0.41%via NVD
CVE-2026-90854High· 7.3
2w ago

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0

A security flaw has been discovered in SourceCodester/katojkalemba Online Food Ordering System 1.0. The impacted element is an unknown function of the file /web/category-foods.php. The manipulation of the argument ID results in sql injec…

▾ TwilightSourceCodester · Online Food Ordering SystemEPSS 0.41%via NVD
CVEs tagged “nvd” — page 305 · VulnSea