VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29909 CVEsRSS

CVE-2026-90843High· 8.3PoC
2w ago

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25

A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipul…

▾ MidnightSabyasachiRana · WebMapEPSS 2.2%via NVD
CVE-2026-85657Medium· 5.4
2w ago

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up…

▾ Sunlitpublishpress · Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress AuthorsEPSS 0.24%via NVD
CVE-2026-85575Medium· 6.4
2w ago

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ …

▾ Sunlitroxnor · ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo WidgetsEPSS 0.26%via NVD
CVE-2026-90842Low· 3.7PoC
2w ago

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0

A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/c…

▾ TwilightPHPGurukul · Blood Donor Management SystemEPSS 0.31%via NVD
CVE-2026-90841High· 7.3PoC
2w ago

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0

A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The m…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.43%via NVD
CVE-2026-90840High· 7.3PoC
2w ago

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0

A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to i…

▾ MidnightPHPGurukul · Blood Donor Management SystemEPSS 0.69%via NVD
CVE-2026-59971Critical· 10.0
2w ago

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases

MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_se…

▾ Midnightdesigncomputer · mysql_mcp_serverEPSS 0.42%via NVD
CVE-2026-59973High· 8.5PoC
2w ago

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP)

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISp…

▾ Midnightagentfront · frontmcpEPSS 0.39%via NVD
CVE-2026-56831Medium· 6.5PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Di…

▾ Twilightshopperlabs · shopperEPSS 0.43%via NVD
CVE-2026-56830Medium· 6.5
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used …

▾ Sunlitshopperlabs · shopperEPSS 0.39%via NVD
CVE-2026-56829High· 8.1PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56827High· 8.1PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, groupedBulkActions in packages/admin/src/Livewire/Pages/Attribute/Browse.php, packages/admin/src/Livewire/Pages/Tag/Index.php, packages/admin/src/Livewire/Pages/Brand/Index.ph…

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-56825High· 8.1PoC
2w ago

Shopper is a Headless e-commerce Admin Panel

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Collection/CollectionProducts.php exposes Action::make('delete') and DeleteBulkAction::make() without delete_collections authorization, …

▾ Midnightshopperlabs · shopperEPSS 0.50%via NVD
CVE-2026-59965High· 7.1PoC
2w ago

Payload Plugins is a collection of plugins designed to enhance Payload CMS

Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts a…

▾ Midnightjhb-software · payload-pluginsEPSS 0.38%via NVD
CVE-2026-59160High· 8.8PoC
2w ago

Yeger is a monorepo for npm packages maintained under the yeger scope

Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by defaul…

▾ MidnightDerYeger · yegerEPSS 0.49%via NVD
CVE-2026-59157Medium· 6.5
2w ago

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests

webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParam…

▾ Sunlitncarlier · webhookdEPSS 0.60%via NVD
CVE-2026-55864High· 7.8
2w ago

GeoNetwork is a catalog application to manage spatially referenced resources

GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validati…

▾ Twilightgeonetwork · core-geonetworkEPSS 0.59%via NVD
CVE-2026-50024Medium· 5.3
2w ago

GitHacker is a tool that restores Git repositories from exposed .git directories

GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs…

▾ SunlitWangYihang · GitHackerEPSS 0.45%via NVD
CVE-2026-44282Medium· 4.8
2w ago

Decidim is a participatory democracy framework

Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_titl…

▾ Sunlitdecidim · decidimEPSS 0.39%via NVD
CVE-2026-53710Critical· 10.0
2w ago

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs

MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw geta…

▾ MidnightIBM · mcp-context-forgeEPSS 1.1%via NVD
CVE-2026-54050Medium· 6.5PoC
2w ago

Sakai is a Collaboration and Learning Environment (CLE)

Sakai is a Collaboration and Learning Environment (CLE). From 23.0 until 23.5 and 25.3, the DELETE /api/users/{userId}/profile/image endpoint allows an authenticated user to delete another user's profile image because ProfileController.r…

▾ Twilightsakaiproject · sakaiEPSS 0.31%via NVD
CVE-2026-54167High· 8.2
2w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processi…

▾ Twilighttektoncd · pipelines-as-codeEPSS 0.27%via NVD
CVE-2026-54168Medium· 6.5
2w ago

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories

Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, a GitHub App installation token created during webhook processing is not scoped to the …

▾ Sunlittektoncd · pipelines-as-codeEPSS 0.59%via NVD
CVE-2026-54251High· 8.7
2w ago

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty

netty-incubator-codec-ohttp implements Oblivious HTTP (OHTTP) gateway and client functionality using Netty. Prior to 0.0.23.Final, the OHTTP gateway decryption path in codec-ohttp/src/main/java/io/netty/incubator/codec/ohttp/OHttpRequest…

▾ Twilightnetty · netty-incubator-codec-ohttpEPSS 0.51%via NVD
CVE-2026-55149High· 7.5PoC
2w ago

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module

Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the val…

▾ Midnightvouch · vouch-proxyEPSS 0.72%via NVD
CVE-2026-53941Medium· 6.9
2w ago

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.27.0 until 0.53.1, the uprobe library resolver can allow an unprivileged container to co…

▾ Sunlitinspektor-gadget · inspektor-gadgetEPSS 0.52%via NVD
CVE-2026-53957High· 7.7PoC
2w ago

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API

Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-…

▾ Midnightcontentful · contentful-mcp-serverEPSS 0.41%via NVD
CVE-2026-53966High· 7.1
2w ago

XWiki Platform is a generic wiki platform

XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Data edit REST API allows a user who can edit a page to change that page's rights without executing the normal document…

▾ Twilightxwiki · xwiki-platformEPSS 0.77%via NVD
CVE-2026-54688Medium· 6.5PoC
2w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, web_url_read passes a caller-supplied URL to the server-side fetch path while assertUrlAllow…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.50%via NVD
CVE-2026-54689Medium· 6.3PoC
2w ago

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG

mcp-searxng is a Model Context Protocol server that gives AI assistants web search and URL-reading capabilities through SearXNG. Prior to 1.2.0, the web_url_read URL policy in src/url-reader.ts can be bypassed while MCP_HTTP_HARDEN is en…

▾ Twilightihor-sokoliuk · mcp-searxngEPSS 0.19%via NVD
CVEs tagged “nvd” — page 308 · VulnSea