VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29980 CVEsRSS

CVE-2026-17156High· 7.8
2w ago

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to execute arbitrary code due to insecure deserialization.

▾ TwilightIBM · App Connect EnterpriseEPSS 0.14%via NVD
CVE-2026-15412Medium· 6.5
2w ago

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted We…

▾ SunlitIBM · WebSphere Application ServerEPSS 0.23%via NVD
CVE-2026-90812Medium· 4.3PoC
2w ago

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0

A security vulnerability has been detected in cosmicstack-labs mercury-agent up to 1.2.0. This impacts the function checkShellCommand of the file src/capabilities/permissions.ts of the component Shell Command Permission. The manipulation…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.39%via NVD
CVE-2026-82519Medium· 4.3
2w ago

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an u…

Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an u…

▾ Sunlitreallysimpleplugins · Really Simple SecurityEPSS 0.36%via NVD
CVE-2026-82049High· 8.4
2w ago

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link

In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification …

▾ TwilightPython Software Foundation · CPythonEPSS 0.21%via NVD
CVE-2013-1446None
2w ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Was assigned for an old issue in the brltty daemon and never published completely.

▾ Sunlitvia NVD
CVE-2026-90808Medium· 6.3PoC
2w ago

A vulnerability was determined in HKUDS nanobot up to 0.2.1

A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. This manipulation causes incomplete blackli…

▾ TwilightHKUDS · nanobotEPSS 0.41%via NVD
CVE-2026-89020Medium· 4.3
2w ago

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by sup…

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by sup…

▾ SunlitMikroTik · RouterOSEPSS 0.49%via NVD
CVE-2026-86830High· 7.2
2w ago

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or r…

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or r…

▾ TwilightAWS · iam-identity-center-teamEPSS 0.69%via NVD
CVE-2026-77884High· 7.1PoC
2w ago

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network

Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

▾ MidnightBrain Trust · Gallery - Private Photo VaultEPSS 0.25%via NVD
CVE-2026-89021Medium· 6.9
2w ago

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…

MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extraction that allows attackers to write files outside the container root by supplying a crafted container image with symlink…

▾ SunlitMikroTik · RouterOSEPSS 0.38%via NVD
CVE-2026-90809High· 7.3
2w ago

A vulnerability was identified in HKUDS nanobot up to 0.2.1

A vulnerability was identified in HKUDS nanobot up to 0.2.1. The affected element is the function ExecTool._guard_command/ExecTool._spawn of the file nanobot/agent/tools/shell.py of the component ExecTool. Such manipulation leads to argu…

▾ TwilightHKUDS · nanobotEPSS 0.56%via NVD
CVE-2026-89023High· 8.6
2w ago

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can ret…

▾ TwilightThemeAtelier · Domain For SaleEPSS 0.39%via NVD
CVE-2026-19543Medium· 6.2
2w ago

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side

IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can m…

▾ SunlitIBM · Common LicensingEPSS 0.12%via NVD
CVE-2026-18515Medium· 4.3
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the…

▾ SunlitIBM · iEPSS 0.28%via NVD
CVE-2026-90810Medium· 6.3PoC
2w ago

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13

A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.37%via NVD
CVE-2026-82035High· 7.1
2w ago

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name …

PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name …

▾ TwilightPyMuPDF · PyMuPDFEPSS 0.32%via NVD
CVE-2026-90811Low· 3.3PoC
2w ago

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0

A weakness has been identified in cosmicstack-labs mercury-agent up to 1.2.0. This affects the function PermissionManager.checkShellCommand of the file mercury-agent/src/capabilities/permissions.ts of the component Shell Permission Manif…

▾ Twilightcosmicstack-labs · mercury-agentEPSS 0.15%via NVD
CVE-2026-18151Medium· 4.2
2w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

▾ SunlitIBM · iEPSS 0.14%via NVD
CVE-2026-15893Medium· 6.5
2w ago

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max…

net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max…

▾ Sunlitzephyrproject · zephyrEPSS 0.20%via NVD
CVE-2026-91081Medium· 5.8
2w ago

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID

Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-tim…

▾ Sunlitsuitenumerique · docsEPSS 0.43%via NVD
CVE-2026-91080High· 7.5PoC
2w ago

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies

webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with inva…

▾ Midnightadnanh · webhookEPSS 0.66%via NVD
CVE-2026-91079High· 8.5
2w ago

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation

Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which …

▾ Twilighthcengineering · platformEPSS 0.37%via NVD
CVE-2026-90946High· 7.5PoC
2w ago

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment

DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary director…

▾ MidnightAsyncFuncAI · deepwiki-openEPSS 0.51%via NVD
CVE-2026-90945Critical· 9.8PoC
2w ago

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables

Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrativ…

▾ Abyssalcrawlab-team · crawlabEPSS 0.77%via NVD
CVE-2026-90944High· 8.2PoC
2w ago

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with fo…

▾ Midnightkrayin · laravel-crmEPSS 0.66%via NVD
CVE-2026-90942Critical· 9.6PoC
2w ago

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it

Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key…

▾ Abyssalcasdoor · casdoorEPSS 0.28%via NVD
CVE-2026-90807Medium· 6.3PoC
2w ago

A vulnerability was found in nanocoai NanoClaw up to 2.1.17

A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link…

▾ Twilightnanocoai · NanoClawEPSS 0.43%via NVD
CVE-2026-90806Medium· 6.3
2w ago

A vulnerability has been found in DjangoCRM django-crm up to 1.2

A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing au…

▾ SunlitDjangoCRM · django-crmEPSS 0.37%via NVD
CVE-2026-86836High· 8.4
2w ago

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration

In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a dir…

▾ TwilightEclipse Foundation · Eclipse AnkaiosEPSS 0.11%via NVD
CVEs tagged “nvd” — page 326 · VulnSea