VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

29999 CVEsRSS

CVE-2026-75015Medium· 4.9
2w ago

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators…

Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators…

▾ SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.39%via NVD
CVE-2026-73470Critical· 9.8
2w ago

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. …

▾ MidnightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.51%via NVD
CVE-2026-90792Medium· 4.3PoC
2w ago

A flaw has been found in GPAC up to f1219cde

A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereferen…

▾ TwilightEPSS 0.69%via NVD
CVE-2026-90681Low· 3.3PoC
2w ago

A weakness has been identified in Matthias-Wandel jhead up to 3.3

A weakness has been identified in Matthias-Wandel jhead up to 3.3. This affects the function Get16u of the file exif.c of the component EXIF Parsing. This manipulation causes out-of-bounds read. The attack requires local access. The expl…

▾ TwilightMatthias-Wandel · jheadEPSS 0.16%via NVD
CVE-2026-90620High· 7.3PoC
2w ago

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04

A vulnerability was determined in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The impacted element is an unknown function of the file hexstrike_server.py of the component API Command Endpoint. This manipulation cau…

▾ Midnight0x4m4 · HexStrike AIEPSS 0.65%via NVD
CVE-2026-90614Medium· 6.3
2w ago

A weakness has been identified in FedML-AI FedML up to 0.9.6

A weakness has been identified in FedML-AI FedML up to 0.9.6. Affected by this issue is the function S3Storage.read_model of the file fedml/core/distributed/communication/s3/remote_storage.py of the component MQTT+S3 Communication Backen…

▾ SunlitFedML-AI · FedMLEPSS 0.43%via NVD
CVE-2026-90609Low· 3.3PoC
2w ago

A vulnerability has been found in GPAC up to f1219cde

A vulnerability has been found in GPAC up to f1219cde. The impacted element is an unknown function of the file scenegraph/vrml_tools.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be p…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-73178High· 7.5
2w ago

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. Thes…

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. Thes…

▾ TwilightApache Software Foundation · org.apache.syncope.core:syncope-core-provisioning-javaEPSS 0.43%via NVD
CVE-2023-50462Medium· 5.3
2w ago

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3

An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to…

▾ SunlitTYPO3 · content_consentEPSS 0.27%via NVD
CVE-2023-40772Medium· 4.3PoC
2w ago

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

A directory Traversal vulnerability in DataEase before 1.18.10 allows a remote attacker to obtain sensitive information via a a crafted request to the StaticResourceController.java component.

▾ TwilightDataEase · DataEaseEPSS 1.1%via NVD
CVE-2023-37253Low· 3.1PoC
2w ago

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3

An issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the API and config variables.

▾ TwilightMediaWiki · ProofreadPageEPSS 0.24%via NVD
CVE-2023-29377Medium· 6.60day
2w ago

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22

An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA …

▾ MidnightSofting · Secure Integration ServerEPSS 0.48%via NVD
CVE-2026-33968Low· 2.8
2w ago

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680

An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. In the camera driver, a Time-of-Check Time-of-Use (TOCTOU) race condition leads to out-of-bounds access.

▾ SunlitSamsung · Exynos 1330 firmwareEPSS 0.12%via NVD
CVE-2026-33962Low· 2.8
2w ago

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930

An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 850, 1280, 1330, 1380, 1480, 2400, W920, and W930. A malformed Netlink command can trigger an out-of-bounds read, potentially leading to information leakage.

▾ SunlitSamsung · Exynos 850 firmwareEPSS 0.13%via NVD
CVE-2026-23793Low· 3.5
2w ago

An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400

An issue was discovered in Samsung Mobile Processor Exynos 1330, 1380, 1480, and 2400. An out-of-bounds memory access vulnerability in the camera GDC driver may lead to kernel memory corruption under certain conditions.

▾ SunlitSamsung · Exynos 1330 firmwareEPSS 0.20%via NVD
CVE-2026-23788Medium· 4.2
2w ago

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380

An issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, and 1380. A heap overflow in the Exynos DRM HDR driver (due to improper buffer size validation) leads to kernel memory corruption and a system crash.

▾ SunlitSamsung · Exynos 1280 firmwareEPSS 0.10%via NVD
CVE-2023-32803High· 7.5
2w ago

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store

The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23…

▾ TwilightAmazon · ca-certificatesEPSS 0.18%via NVD
CVE-2023-24288Low· 2.9
2w ago

An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.

An issue in Portable Puzzle Collection before 20230116.5782e29 allows attackers to cause a Denial of Service (DoS) via creating an excessive amount of save states.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.11%via NVD
CVE-2023-24286Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.10%via NVD
CVE-2023-24283Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.11%via NVD
CVE-2026-90791Medium· 6.3PoC
2w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack can …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-90790Medium· 6.3
2w ago

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender…

▾ Sunlita2aproject · a2a-pythonEPSS 0.37%via NVD
CVE-2026-90789High· 7.3PoC
2w ago

A weakness has been identified in itsourcecode Leave Management System 1.0

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The a…

▾ Midnightitsourcecode · Leave Management SystemEPSS 0.43%via NVD
CVE-2026-82438High· 8.1
2w ago

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

▾ TwilightApache Software Foundation · org.apache.storm:storm-webappEPSS 0.21%via NVD
CVE-2026-82437Medium· 4.3
2w ago

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "this is a daemon log" flag with the au…

▾ SunlitApache Software Foundation · org.apache.storm:storm-webappEPSS 0.28%via NVD
CVE-2026-82435Critical· 9.8
2w ago

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried i…

▾ MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.65%via NVD
CVE-2026-82434Medium· 6.5⚖ disputed
2w ago

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any ca…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.50%via NVD
CVE-2026-82433Medium· 6.5
2w ago

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and t…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.34%via NVD
CVE-2026-82432High· 8.1
2w ago

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validat…

▾ TwilightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.37%via NVD
CVE-2026-82431Critical· 9.8
2w ago

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.us…

▾ MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.39%via NVD
CVEs tagged “nvd” — page 335 · VulnSea