VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29999 CVEsRSS

CVE-2026-85196Medium· 5.3
2w ago

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

▾ Sunlitregularlabs.com · plg_system_articlesanywhereEPSS 0.44%via NVD
CVE-2026-82794High· 8.8
2w ago

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings

SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ TwilightContec Co., Ltd. · SV-CPT-MC310EPSS 1.9%via NVD
CVE-2026-82793High· 7.2
2w ago

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed o…

▾ TwilightContec Co., Ltd. · CAN-2-WFEPSS 0.63%via NVD
CVE-2026-82792Medium· 5.2
2w ago

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · CAN-2-WFEPSS 0.24%via NVD
CVE-2026-90713Low· 3.3PoC
2w ago

A security flaw has been discovered in vllm-project vLLM up to 0.29.0

A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipula…

▾ Twilightvllm-project · vLLMEPSS 0.16%via NVD
CVE-2026-85190High· 7.5
2w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A cr…

▾ Twilightregularlabs.com · plg_system_quickindexEPSS 0.42%via NVD
CVE-2026-82791High· 8.8
2w ago

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may b…

▾ TwilightContec Co., Ltd. · CAN-2-WFEPSS 1.9%via NVD
CVE-2026-90714Medium· 6.3PoC
2w ago

A weakness has been identified in marcobambini Gravity up to 0.9.7

A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruption. The attack is …

▾ Twilightmarcobambini · GravityEPSS 0.47%via NVD
CVE-2026-82790Medium· 5.4
2w ago

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US

Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

▾ SunlitContec Co., Ltd. · PC-HELPER Wireless I/O DIO-0404RY-LWFEPSS 0.24%via NVD
CVE-2026-78336High· 7.5
2w ago

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser

Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains al…

▾ TwilightApache Software Foundation · org.apache.syncope.ext.oidcc4ui:syncope-ext-oidcc4ui-logicEPSS 0.43%via NVD
CVE-2026-78330Critical· 9.8
2w ago

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a succ…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.64%via NVD
CVE-2026-78318Medium· 6.1
2w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HT…

▾ SunlitApache Software Foundation · org.apache.syncope.client.idrepo:syncope-client-idrepo-common-uiEPSS 0.26%via NVD
CVE-2026-77883Medium· 4.9
2w ago

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficien…

▾ SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-apiEPSS 0.39%via NVD
CVE-2026-90715High· 7.3PoC
2w ago

A security vulnerability has been detected in marcobambini Gravity up to 0.9.7

A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The atta…

▾ Midnightmarcobambini · GravityEPSS 0.64%via NVD
CVE-2024-58383High· 7.3PoC
2w ago

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password

Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. O…

▾ Midnightfroxlor · froxlorEPSS 0.10%via NVD
CVE-2026-90937Critical· 9.9
2w ago

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives

froxlor versions before 2.2.5 fail to validate newline characters in subdomain redirect URLs, allowing authenticated customers to inject arbitrary nginx or Apache configuration directives. Attackers can supply URLs containing literal new…

▾ Midnightfroxlor · froxlorEPSS 0.45%via NVD
CVE-2026-90936Medium· 4.3PoC
2w ago

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php

Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authenticated attackers can enumerate global sender alias IDs and read other customers' allowed sender values by supplying a…

▾ Twilightfroxlor · froxlorEPSS 0.31%via NVD
CVE-2026-90934Medium· 4.3
2w ago

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses

EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints that allows authenticated users to read restricted email addresses. Attackers can recover hidden attendee emails by ex…

▾ Sunlitespocrm · espocrmEPSS 0.30%via NVD
CVE-2026-90932High· 7.2PoC
2w ago

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling

LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file…

▾ Midnightlaradashboard · laradashboardEPSS 0.82%via NVD
CVE-2026-90931Medium· 5.4PoC
2w ago

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags

LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated users with only the media.create permission to upload malicious SVG files containing script tags. When any user incl…

▾ Twilightlaradashboard · laradashboardEPSS 0.24%via NVD
CVE-2026-90929High· 8.1
2w ago

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go)

File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a tar…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-90927Medium· 6.5PoC
2w ago

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages

filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages…

▾ Twilightfilebrowser · filebrowserEPSS 0.44%via NVD
CVE-2026-90716Medium· 5.5PoC
2w ago

A vulnerability was detected in marcobambini Gravity up to 0.9.7

A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bou…

▾ Twilightmarcobambini · GravityEPSS 0.36%via NVD
CVE-2026-77181Critical· 9.8
2w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update opera…

▾ MidnightApache Software Foundation · org.apache.syncope.core.am:syncope-core-am-logicEPSS 0.51%via NVD
CVE-2026-77051Critical· 9.8
2w ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-jpaEPSS 0.60%via NVD
CVE-2026-73668Critical· 9.8
2w ago

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idm:syncope-core-idm-logicEPSS 0.51%via NVD
CVE-2026-73579Critical· 9.8
2w ago

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such trans…

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-persistence-commonEPSS 0.51%via NVD
CVE-2026-90955Medium· 4.6
2w ago

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID

Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user across audit logging. The shell is designed to run actions as a supplied MISP user ID. However, the legacy SysLogLoga…

▾ SunlitMISP · MISPEPSS 0.16%via NVD
CVE-2026-78299Critical· 9.1
2w ago

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on …

▾ MidnightEclipse Foundation · Eclipse Embedded CDT (C/C++ Development Tools)EPSS 0.54%via NVD
CVE-2026-75030Critical· 9.8
2w ago

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue…

▾ MidnightApache Software Foundation · org.apache.syncope.core.idrepo:syncope-core-idrepo-logicEPSS 0.62%via NVD
CVEs tagged “nvd” — page 334 · VulnSea