VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30134 CVEsRSS

CVE-2026-90452Medium· 5.3
3w ago

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate

Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the…

▾ SunlitCISA · MalcolmEPSS 0.13%via NVD
CVE-2026-90451Medium· 5.9⚖ disputed
3w ago

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component

An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration w…

▾ SunlitCISA · MalcolmEPSS 0.54%via NVD
CVE-2026-90445Medium· 6.5
3w ago

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attack…

▾ SunlitCISA · MalcolmEPSS 0.52%via NVD
CVE-2026-90444High· 8.8
3w ago

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters

A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, all…

▾ TwilightCISA · MalcolmEPSS 0.40%via NVD
CVE-2026-90443Medium· 5.4
3w ago

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a lin…

▾ SunlitCISA · MalcolmEPSS 0.56%via NVD
CVE-2026-81907High· 7.1
3w ago

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforc…

▾ Twilightconcretecms · concrete_cmsEPSS 0.14%via NVD
CVE-2026-68535Medium· 4.3
3w ago

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the refe…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.21%via NVD
CVE-2026-81918Medium· 4.8
3w ago

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block

Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.25%via NVD
CVE-2026-81917Medium· 5.4
3w ago

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed …

Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81916Medium· 4.3
3w ago

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route

Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the posted form rather than the entity identified by the dashboard route. As a result, a user permitted to add entries to o…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.27%via NVD
CVE-2026-81915Medium· 5.3
3w ago

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated

Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::submit() dashboard controller loaded and saved the Page Type identified by a user-supplied ptID without calling canEdi…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.29%via NVD
CVE-2026-68526Medium· 4.3
3w ago

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

Concrete CMS before 9.5.3 did not validate an anti-CSRF token in the Calendar event duplicate dialog controller (concrete/controllers/dialog/event/duplicate.php) submit() action, which duplicated a calendar event after checking only canA…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.11%via NVD
CVE-2026-18122Medium· 6.0
3w ago

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check

Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.23%via NVD
CVE-2026-81010High· 7.8⚖ disputed
3w ago

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originati…

In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: honor task_work cancellation io_waitid_cb() may run through the fallback task_work path when task_work_add() can no longer queue work to the originati…

▾ TwilightLinux · LinuxEPSS 0.18%via NVD
CVE-2026-80964Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe

In the Linux kernel, the following vulnerability has been resolved: ALSA: virmidi: Check card index validity at probe virmidi driver blindly trusts that the given devptr->id value is within the proper card index range at probe. It's O…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-62105Critical· 9.8
3w ago

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

▾ MidnightThemeRex · ThemeREX AddonsEPSS 0.56%via NVD
CVE-2026-6640Medium· 6.4
3w ago

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping

The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. …

▾ Sunlitdglingren · Media Library AssistantEPSS 0.42%via NVD
CVE-2026-87727Medium· 6.5
3w ago

a-blog cms Ver

a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product.

▾ Sunlitappleple inc. · a-blog cmsEPSS 0.41%via NVD
CVE-2026-89146High· 7.5PoC
3w ago

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow

libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL…

▾ Midnightlibp2p · libp2p-rendezvousEPSS 0.63%via NVD
CVE-2026-89566Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP

In the Linux kernel, the following vulnerability has been resolved: jbd2: check need_resched() when skipping busy checkpoint buffers journal_shrink_one_cp_list() skips busy checkpoint buffers when called with JBD2_SHRINK_BUSY_SKIP. Th…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-86812Medium· 6.5
3w ago

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose …

The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose …

▾ SunlitEPSS 0.27%via NVD
CVE-2026-77490Medium· 6.1
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

▾ Sunlitmicrosoft · edge_chromiumEPSS 0.41%via NVD
CVE-2026-89506Medium· 4.7
3w ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

In the Linux kernel, the following vulnerability has been resolved: RDMA/uverbs: Add UVERBS_ATTR_UHW to UVERBS_METHOD_REG_MR The original commit missed that three drivers (mthca, irdma, siw) have UHW data associated with reg_mr that ca…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-49462Medium· 5.3
3w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. In versions up to and including 3.0.0, deployments using the shipped defau…

▾ Sunlitnl-portal · nl.nl-portal:appEPSS 0.40%via NVD
CVE-2026-89715Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing …

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: fix ref leak on nfs_uuid_add_file failure When nfs_uuid_add_file() races with nfs_uuid_put() tearing down uuid->net, it returns -ENXIO without publishing …

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-27378Medium· 5.3
3w ago

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

▾ Sunlitmagepeopleteam · advanced-partial-payment-or-deposit-for-woocommerceEPSS 0.29%via NVD
CVE-2026-89151Low· 3.5
3w ago

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

▾ SunlitForgejo · ForgejoEPSS 0.23%via NVD
CVE-2026-78130High· 7.5
3w ago

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

▾ Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-87983Critical· 9.2
3w ago

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands

An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during…

▾ Midnightmistralai · mistral-vibeEPSS 0.62%via NVD
CVE-2026-89447Medium· 4.4
3w ago

In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invo…

In the Linux kernel, the following vulnerability has been resolved: iommufd: Avoid locking internal accesses during unmap iommufd_access_notify_unmap() skips internal accesses because they do not have an external unmap callback to invo…

▾ SunlitLinux · LinuxEPSS 0.22%via NVD
CVEs tagged “nvd” — page 352 · VulnSea