VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30012 CVEsRSS

CVE-2023-24286Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow via the game description parameter.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.10%via NVD
CVE-2023-24283Low· 2.9
2w ago

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.

Portable Puzzle Collection before 20230116.5782e29 was discovered to contain a buffer overflow which allows attackers to cause a Denial of Service (DoS) via a crafted save file.

▾ SunlitSimon Tatham · Portable Puzzle CollectionEPSS 0.11%via NVD
CVE-2026-90791Medium· 6.3PoC
2w ago

A vulnerability was detected in GPAC up to f1219cde

A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack can …

▾ TwilightEPSS 0.51%via NVD
CVE-2026-90790Medium· 6.3
2w ago

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3

A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender…

▾ Sunlita2aproject · a2a-pythonEPSS 0.37%via NVD
CVE-2026-90789High· 7.3PoC
2w ago

A weakness has been identified in itsourcecode Leave Management System 1.0

A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. Executing a manipulation of the argument user_email can lead to sql injection. The a…

▾ Midnightitsourcecode · Leave Management SystemEPSS 0.43%via NVD
CVE-2026-82438High· 8.1
2w ago

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP components served to an authenticated user. The Logviewer reflected the request's `Origin` header back in `Access-Contr…

▾ TwilightApache Software Foundation · org.apache.storm:storm-webappEPSS 0.21%via NVD
CVE-2026-82437Medium· 4.3
2w ago

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content

Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For daemon logs those settings were not applied: the access decision combined the "this is a daemon log" flag with the au…

▾ SunlitApache Software Foundation · org.apache.storm:storm-webappEPSS 0.28%via NVD
CVE-2026-82435Critical· 9.8
2w ago

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place

Description The worker's Netty message decoder is installed ahead of the SASL authentication handlers in the pipeline and acts on frames before any authentication has taken place. It allocated buffers sized from a length field carried i…

▾ MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.65%via NVD
CVE-2026-82434Medium· 6.5⚖ disputed
2w ago

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it

Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any ca…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.50%via NVD
CVE-2026-82433Medium· 6.5
2w ago

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check

Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level authorization check. Where the cluster is configured with them, that response includes `storm.zookeeper.auth.payload` and t…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.34%via NVD
CVE-2026-82432High· 8.1
2w ago

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only

Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalance operation accepts configuration overrides and stripped a small set of keys from them, but never re-ran that validat…

▾ TwilightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.37%via NVD
CVE-2026-82431Critical· 9.8
2w ago

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered

Description `SimpleACLAuthorizer` evaluated the user-level command set by returning early when `nimbus.users` was empty, before `nimbus.groups` was considered. An operator who restricted cluster access by group alone, leaving `nimbus.us…

▾ MidnightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.39%via NVD
CVE-2026-82430High· 7.8
2w ago

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the …

Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the …

▾ TwilightApache Software Foundation · org.apache.storm:storm-coreEPSS 0.14%via NVD
CVE-2026-82429High· 7.8
2w ago

Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid…

Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid…

▾ TwilightApache Software Foundation · org.apache.storm:storm-coreEPSS 0.13%via NVD
CVE-2026-82428High· 8.8
2w ago

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`

Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from the Maven coordinate, for example `dep---.jar`. The key was therefore identical for every user of the cluster and pred…

▾ TwilightApache Software Foundation · org.apache.storm:storm-clientEPSS 0.69%via NVD
CVE-2026-82427High· 7.8
2w ago

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises

Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in bo…

▾ TwilightApache Software Foundation · org.apache.storm:storm-serverEPSS 0.15%via NVD
CVE-2026-82426Medium· 6.5
2w ago

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded

Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a server-side path and opened it directly, without checking that it referred to a file the caller had actually uploaded. Th…

▾ SunlitApache Software Foundation · org.apache.storm:storm-serverEPSS 0.42%via NVD
CVE-2026-82019Medium· 4.2PoC
2w ago

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage paylo…

TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage paylo…

▾ TwilightTripleLift · video-bundle.jsEPSS 0.29%via NVD
CVE-2026-7848High· 8.6
2w ago

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook methods

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProductUpdateBefore", "hookActionObjectCategoryUpdateBefore", and "hookActionObjectCategoryAddAfter" hook methods. The mod…

▾ TwilightAlior Bank · ratyEPSS 0.38%via NVD
CVE-2026-59570High· 7.5
2w ago

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.

▾ TwilightZscaler · Client ConnectorEPSS 0.13%via NVD
CVE-2026-59569High· 8.1
2w ago

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.

▾ TwilightZscaler · Client ConnectorEPSS 0.18%via NVD
CVE-2026-90961Critical· 9.3
2w ago

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability

The LdapAuth and LinOTPAuth authentication plugins in MISP contain an authentication bypass vulnerability. Both LdapAuthenticate and LinOTPAuthenticate replace CakePHP's FormAuthenticate class but fail to replicate its _checkFields() inp…

▾ MidnightMISP · MISPEPSS 0.64%via NVD
CVE-2026-90949High· 7.8
2w ago

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader

A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. …

▾ TwilightRed Hat · gimpEPSS 0.33%via NVD
CVE-2026-25687High· 8.1
2w ago

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…

A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZC…

▾ TwilightZscaler · Client ConnectorEPSS 0.38%via NVD
CVE-2026-15600High· 8.6
2w ago

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method

Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotionAction method. The module inserts value of the POST parameter "status" into SQL UPDATE queries without any sanitizat…

▾ TwilightAlior Bank · ratyEPSS 0.24%via NVD
CVE-2026-12985Medium· 6.8
2w ago

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Registration redirect URIs by URL component (matching glob patterns against the raw URI string instead) which allows a …

▾ SunlitMattermost · MattermostEPSS 0.28%via NVD
CVE-2026-90957Medium· 5.1
2w ago

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images

Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains that SVG files are XML documents rather than passive bitmap images. While scripts inside SVG do not execute when the …

▾ SunlitMISP · MISPEPSS 0.40%via NVD
CVE-2026-90948High· 7.8
2w ago

A flaw was found in GIMP's ICO file loader

A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocate…

▾ TwilightRed Hat · gimpEPSS 0.22%via NVD
CVE-2026-90941Medium· 4.3PoC
2w ago

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters

novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookI…

▾ Twilight201206030 · novel-plusEPSS 0.41%via NVD
CVE-2026-90940Medium· 5.3PoC
2w ago

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL …

▾ Twilight201206030 · novel-plusEPSS 0.55%via NVD
CVEs tagged “nvd” — page 336 · VulnSea