VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30012 CVEsRSS

CVE-2026-81564High· 7.0
2w ago

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks use…

Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks use…

▾ Twilightjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.47%via NVD
CVE-2026-79701Medium· 6.9
2w ago

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the resul…

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the resul…

▾ Sunlitjoomshaper.com · SP Page Builder (Pro) extension for JoomlaEPSS 0.45%via NVD
CVE-2026-79700Medium· 6.9
2w ago

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag f…

Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag f…

▾ Sunlitjoomshaper.com · SP Page Builder (Pro) extension for JoomlaEPSS 0.45%via NVD
CVE-2026-78375High· 8.6
2w ago

Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id…

Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id…

▾ Twilightjoomshaper.com · SP Page Builder (Free and Pro) extension for JoomlaEPSS 0.37%via NVD
CVE-2026-77147Medium· 6.5
2w ago

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their Co…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their Co…

▾ SunlitApache Software Foundation · org.apache.syncope.core:syncope-core-springEPSS 0.45%via NVD
CVE-2026-21391Critical· 9.5
2w ago

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden

An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication…

▾ MidnightPing Identity · PingAMEPSS 0.45%via NVD
CVE-2026-12258Critical· 9.2
2w ago

Inadequate access control in Hiperdino’s REST v1.0 API

Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, …

▾ MidnightHiperdino · REST APIEPSS 0.40%via NVD
CVE-2026-90686Medium· 5.3PoC
2w ago

A vulnerability was found in GPAC up to f1219cde

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remot…

▾ TwilightEPSS 0.86%via NVD
CVE-2026-85191High· 7.5
2w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected rend…

▾ Twilightregularlabs.com · plg_system_tabsEPSS 0.42%via NVD
CVE-2026-85189High· 7.5
2w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can re…

▾ Twilightregularlabs.com · plg_system_modalsEPSS 0.42%via NVD
CVE-2026-82795Medium· 5.4
2w ago

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting

SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

▾ SunlitContec Co., Ltd. · SV-CPT-MC310EPSS 0.24%via NVD
CVE-2026-82768High· 8.1
2w ago

Path traversal vulnerability exists in SGA1000

Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

▾ TwilightContec Co., Ltd. · SGA1000EPSS 0.49%via NVD
CVE-2026-82765High· 8.1
2w ago

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series

Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

▾ TwilightContec Co., Ltd. · FXA5000EPSS 0.49%via NVD
CVE-2026-71198High· 7.0
2w ago

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image

In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the imp…

▾ TwilightOpenStack · GlanceEPSS 0.45%via NVD
CVE-2023-50459Medium· 5.4
2w ago

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3

An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend user…

▾ SunlitTYPO3 · femanagerEPSS 0.42%via NVD
CVE-2026-55073Medium· 6.2PoC
2w ago

WeasyPrint helps web developers to create PDF documents

WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through t…

▾ TwilightKozea · WeasyPrintEPSS 0.22%via NVD
CVE-2026-54529Medium· 5.3
2w ago

SQLAdmin is a flexible Admin interface for SQLAlchemy models

SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.py accepts the attacker-controlled sortBy list-view query parameter without enforcing the configured column_sortable_l…

▾ Sunlitsmithyhq · sqladminEPSS 0.38%via NVD
CVE-2026-61534Critical· 9.1PoC
2w ago

Yayson is a library for serializing and reading JSON API data in JavaScript

Yayson is a library for serializing and reading JSON API data in JavaScript. Prior to 4.3.0, Store and LegacyStore use attacker-controlled JSON:API type, id, and relationship names as keys in plain-object lookup tables in src/yayson/stor…

▾ Abyssalyayson · yaysonEPSS 0.84%via NVD
CVE-2026-59960High· 7.5
2w ago

Argos JavaScript provides official Argos SDKs for JavaScript

Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseComm…

▾ Twilightargos-ci · argos-javascriptEPSS 0.64%via NVD
CVE-2026-55416High· 8.8
2w ago

Pimcore is an Open Source Data & Experience Management Platform

Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and group…

▾ Twilightpimcore · pimcoreEPSS 0.65%via NVD
CVE-2026-53495Medium· 6.8
2w ago

containerd is an open-source container runtime

containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go …

▾ Sunlitcontainerd · containerdEPSS 0.16%via NVD
CVE-2025-24890Medium· 6.8PoC
2w ago

gitoxide is an implementation of git written in Rust

gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered e…

▾ TwilightGitoxideLabs · gitoxideEPSS 0.19%via NVD
CVE-2026-84445High· 8.7
2w ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host heade…

▾ Twilightgrpc · grpc-goEPSS 0.64%via NVD
CVE-2026-55451High· 8.3PoC
2w ago

gettext-converter provides gettext resource conversion utilities for JavaScript

gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number sign…

▾ Midnightlocize · gettext-converterEPSS 0.57%via NVD
CVE-2026-54150Medium· 6.9
2w ago

next-video is a library for adding video to Next.js applications

next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/…

▾ Sunlitmuxinc · next-videoEPSS 0.42%via NVD
CVE-2026-54155High· 7.7
2w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not ve…

▾ Twilightnode-opcua · node-opcuaEPSS 0.42%via NVD
CVE-2026-54156High· 7.5
2w ago

node-opcua is an OPC UA implementation for TypeScript and Node.js

node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer…

▾ Twilightnode-opcua · node-opcuaEPSS 0.78%via NVD
CVE-2026-54175High· 7.6
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm…

▾ TwilightLaravel-Backpack · CRUDEPSS 0.55%via NVD
CVE-2026-54176Medium· 6.5
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccount…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.65%via NVD
CVE-2026-54177Medium· 6.6
2w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields methods uploadFi…

▾ SunlitLaravel-Backpack · CRUDEPSS 0.93%via NVD
CVEs tagged “nvd” — page 338 · VulnSea