VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29934 CVEsRSS

CVE-2026-46623High· 7.4
2w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.67%via NVD
CVE-2026-48785Medium· 4.8
2w ago

Apptainer is an open source container platform

Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix matching to the limit container paths directive in apptainer.conf, so an allowed path such as /data/safe also author…

▾ Sunlitapptainer · apptainerEPSS 0.15%via NVD
CVE-2026-45051Critical· 9.2
2w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInp…

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.69%via NVD
CVE-2026-45052Critical· 9.3
2w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into …

▾ MidnightOpenIdentityPlatform · OpenAMEPSS 0.77%via NVD
CVE-2026-45794High· 7.7
2w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.63%via NVD
CVE-2026-46498High· 7.6
2w ago

Open Access Management (OpenAM) is an access management solution

Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a…

▾ TwilightOpenIdentityPlatform · OpenAMEPSS 0.41%via NVD
CVE-2026-48722Medium· 5.5
2w ago

Nextflow is a DSL for data-driven computational pipelines

Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth login writes Seqera Platform OIDC bearer tokens to ${NXF_HOME:-~/.nextflow}/seqera-auth.config through AuthCommandImpl.…

▾ Sunlitnextflow-io · nextflowEPSS 0.14%via NVD
CVE-2026-55374Medium· 4.8
2w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, Request::buildRequestUrl() joins values returned by Request::getPathVariables() without encoding individual path segments, including the sch…

▾ Sunlitjleehr · canto-saas-apiEPSS 0.36%via NVD
CVE-2026-55375Medium· 5.3
2w ago

canto-saas-api is a PHP library for interacting with the Canto SaaS API

canto-saas-api is a PHP library for interacting with the Canto SaaS API. Prior to version 3.0.0, OAuth2Request::getQueryParams() places app_id, app_secret, refresh_token, and code in the URL query string of token POST requests, allowing …

▾ Sunlitjleehr · canto-saas-apiEPSS 0.38%via NVD
CVE-2026-55690High· 7.5
2w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes…

▾ TwilightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-55691High· 8.6PoC
2w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/Embed…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.48%via NVD
CVE-2026-55828Medium· 6.0
2w ago

qbee transport is a remote access transport protocol implementation

qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A c…

▾ Sunlitqbee-io · transportEPSS 0.38%via NVD
CVE-2026-55650Medium· 4.4PoC
2w ago

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite

Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangero…

▾ Twilightouterbase · studioEPSS 0.19%via NVD
CVE-2026-55692High· 7.5PoC
2w ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent…

▾ MidnightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.49%via NVD
CVE-2026-55770Medium· 6.8PoC
2w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/lda…

▾ Twilightopenbao · openbaoEPSS 0.53%via NVD
CVE-2026-55774Low· 2.1
2w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known…

▾ Sunlitopenbao · openbaoEPSS 0.56%via NVD
CVE-2026-55775Low· 2.3⚖ disputed
2w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespa…

▾ Sunlitopenbao · openbaoEPSS 0.48%via NVD
CVE-2026-55776Medium· 6.5PoC
2w ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type paramete…

▾ Twilightopenbao · openbaoEPSS 0.61%via NVD
CVE-2026-55701Medium· 6.9
2w ago

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector

The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiv…

▾ Sunlitopen-telemetry · opentelemetry-collector-contribEPSS 0.70%via NVD
CVE-2026-55591Medium· 5.8PoC
2w ago

Signal K Server is a server application that runs on a central hub in a boat

Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalK…

▾ TwilightSignalK · signalk-serverEPSS 0.30%via NVD
CVE-2026-18116Medium· 6.1
2w ago

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block

Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user per…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.15%via NVD
CVE-2026-14986Medium· 6.8
2w ago

The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO int…

The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO int…

▾ Sunlitzephyrproject · zephyrEPSS 0.18%via NVD
CVE-2026-81900Medium· 6.1
2w ago

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting

Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with e…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.26%via NVD
CVE-2026-91201Medium· 5.4
2w ago

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin

DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window…

▾ Sunlitarc53 · DocsGPTEPSS 0.21%via NVD
CVE-2026-91198Medium· 5.3
2w ago

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints

GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experime…

▾ Sunlitgrowthbook · growthbookEPSS 0.42%via NVD
CVE-2026-77191Low· 2.6
2w ago

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the …

An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the …

▾ SunlitArista Networks · EOSEPSS 0.22%via NVD
CVE-2026-91199Medium· 5.0
2w ago

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address

Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make th…

▾ Sunlitrefly-ai · reflyEPSS 0.34%via NVD
CVE-2026-91197Medium· 6.5PoC
2w ago

Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources

Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers wit…

▾ Twilightflowable · flowable-engineEPSS 0.46%via NVD
CVE-2026-75943Low· 2.6
2w ago

A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout

A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass w…

▾ SunlitArista Networks · EOSEPSS 0.20%via NVD
CVE-2026-91200High· 8.8
2w ago

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream

DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the d…

▾ Twilightdevspace · devspaceEPSS 0.65%via NVD
CVEs tagged “nvd” — page 312 · VulnSea