VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29852 CVEsRSS

CVE-2026-90852High· 7.3PoC
2w ago

A vulnerability has been found in luben zstd-jni up to 1.5.7-13

A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after …

▾ Midnightluben · zstd-jniEPSS 0.54%via NVD
CVE-2026-88262High· 8.7
2w ago

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affects xClick: R2, R3, and R3.1.

▾ Twilightbizwell · xClickEPSS 0.58%via NVD
CVE-2026-88261Medium· 5.1
2w ago

Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.

Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.1.

▾ Sunlitbizwell · xClickEPSS 0.38%via NVD
CVE-2026-91774Medium· 4.3
2w ago

Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to read full team records

Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in user to read full team records. Attackers can supply a known team identifier to retrieve sensitive team data including …

▾ SunlitYaoApp · yaoEPSS 0.34%via NVD
CVE-2026-91773Medium· 4.3
2w ago

Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access

Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users to read lock metadata from repositories they cannot access. Attackers with write access to any repository can enumera…

▾ Sunlitcharmbracelet · soft-serveEPSS 0.34%via NVD
CVE-2026-91772Medium· 6.1PoC
2w ago

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter

Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the uri query parameter. Attackers can craft malicious links on the trusted Halo domain that redirect visitors to arbi…

▾ Twilighthalo-dev · haloEPSS 0.32%via NVD
CVE-2026-91771High· 8.8
2w ago

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks

Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal s…

▾ Twilightwandb · wandbEPSS 1.2%via NVD
CVE-2026-91770Medium· 6.5PoC
2w ago

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records

IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, cer…

▾ Twilightgamonoid · icehrmEPSS 0.45%via NVD
CVE-2026-90851Medium· 6.3PoC
2w ago

A flaw has been found in PHPGurukul Hostel Management System 3.0

A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the a…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90850Low· 2.4PoC
2w ago

A vulnerability was detected in PHPGurukul Hostel Management System 3.0

A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be lau…

▾ TwilightPHPGurukul · Hostel Management SystemEPSS 0.37%via NVD
CVE-2026-90849High· 7.3PoC
2w ago

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0

A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User le…

▾ MidnightSourceCodester · College Notes Gallery Management SystemEPSS 0.43%via NVD
CVE-2026-90848Medium· 4.3
2w ago

A weakness has been identified in Governikus AusweisApp up to 2.5.4

A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The…

▾ SunlitGovernikus · AusweisAppEPSS 0.45%via NVD
CVE-2026-91752High· 7.5PoC
2w ago

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data

GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarO…

▾ MidnightGNU · libextractorEPSS 0.74%via NVD
CVE-2026-91751High· 8.3PoC
2w ago

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory

Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal seq…

▾ Midnightflextype · flextypeEPSS 0.54%via NVD
CVE-2026-91750Medium· 6.5PoC
2w ago

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs

WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation…

▾ TwilightTencent · WeKnoraEPSS 0.44%via NVD
CVE-2026-90847Critical· 9.1PoC
2w ago

A vulnerability was determined in EFM ipTIME C200E 1.094

A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the at…

▾ AbyssalEFM · ipTIME C200EEPSS 3.4%via NVD
CVE-2026-90846High· 7.3PoC
2w ago

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is …

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90845Low· 3.5PoC
2w ago

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1

A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. …

▾ TwilightPHPGurukul · Daily Expense Tracker SystemEPSS 0.35%via NVD
CVE-2026-90844High· 7.3PoC
2w ago

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1

A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injec…

▾ MidnightPHPGurukul · Daily Expense Tracker SystemEPSS 0.43%via NVD
CVE-2026-90843High· 8.3PoC
2w ago

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipul…

▾ MidnightSabyasachiRana · WebMapEPSS 2.2%via NVD
CVE-2026-85657Medium· 5.4
2w ago

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

▾ Sunlitpublishpress · Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress AuthorsEPSS 0.24%via NVD
CVE-2026-85575Medium· 6.4
2w ago

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

▾ Sunlitroxnor · ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgetsEPSS 0.26%via NVD
CVE-2026-90842Low· 3.7PoC
2w ago

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/c…

▾ TwilightPHPGurukul · Blood Donor Management SystemEPSS 0.31%via NVD
CVE-2026-90841High· 7.3PoC
2w ago

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.43%via NVD
CVE-2026-90840High· 7.3PoC
2w ago

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to i…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.69%via NVD
CVE-2026-59971Critical· 10.0
2w ago

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_se…

▾ Midnightdesigncomputer · mysql_mcp_serverEPSS 0.42%via NVD
CVE-2026-59973High· 8.5PoC
2w ago

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISp…

▾ Midnightagentfront · frontmcpEPSS 0.39%via NVD
CVE-2026-56831Medium· 6.5PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…

▾ Twilightshopperlabs · shopperEPSS 0.43%via NVD
CVE-2026-56830Medium· 6.5
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …

▾ Sunlitshopperlabs · shopperEPSS 0.39%via NVD
CVE-2026-56829High· 8.1PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVEs tagged “nvd” — page 306 · VulnSea