VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30134 CVEsRSS

CVE-2026-54165Medium· 6.4PoC
3w ago

Dobase is an open-source, self-hosted workspace with installable tools

Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click stored DOM-based cross-site scripting (XSS) vulnerability in the public, unauthenticated shared-folder image gallery. A…

▾ Twilightsmgdkngt · dobaseEPSS 0.55%via NVD
CVE-2026-47773High· 7.2
3w ago

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models

ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missing bounds check in the ATT layer write request handler that allows a remote, unauthenticated BLE client to corrupt mem…

▾ Twilightarduino-libraries · ArduinoBLEEPSS 0.15%via NVD
CVE-2026-90460High· 7.6PoC
3w ago

An issue was discovered in OpenStack Keystone before 29.0.3

An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or d…

▾ MidnightOpenStack · KeystoneEPSS 0.55%via NVD
CVE-2026-54241High· 7.4
3w ago

libde265 is an open source implementation of the h.265 video codec

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and …

▾ Twilightstrukturag · libde265EPSS 0.39%via NVD
CVE-2026-54240High· 7.4
3w ago

libde265 is an open source implementation of the h.265 video codec

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflo…

▾ Twilightstrukturag · libde265EPSS 0.39%via NVD
CVE-2026-45057Medium· 4.9
3w ago

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself i…

▾ Sunlitmatrix-org · matrix-sdk-uiEPSS 0.23%via NVD
CVE-2026-45056Medium· 6.9⚖ disputed
3w ago

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients

matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the…

▾ Sunlitmatrix-org · matrix-rust-sdkEPSS 0.31%via NVD
CVE-2026-44715High· 8.7
3w ago

OpenMRS is an open source electronic medical record system platform

OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, w…

▾ Twilightopenmrs · org.openmrs.module:legacyui-apiEPSS 0.41%via NVD
CVE-2026-54258Medium· 6.5PoC
3w ago

ZoneMinder is a free, open source closed-circuit television software application

ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to …

▾ TwilightZoneMinder · zoneminderEPSS 0.34%via NVD
CVE-2026-54248Medium· 6.5
3w ago

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided …

▾ Sunlitkimdre · doco-cdEPSS 0.40%via NVD
CVE-2026-49846High· 7.5
3w ago

libks provides foundational support for signalwire C products

libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. Th…

▾ Twilightsignalwire · libksEPSS 0.50%via NVD
CVE-2026-90461Medium· 6.3
3w ago

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

▾ SunlitOpenStack · IronicEPSS 0.33%via NVD
CVE-2026-90450Medium· 4.3
3w ago

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny

The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered…

▾ SunlitCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-90449Medium· 6.5
3w ago

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first

When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. A…

▾ SunlitCISA · MalcolmEPSS 0.54%via NVD
CVE-2026-90448Medium· 6.5
3w ago

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed

A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwr…

▾ SunlitCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-90447Medium· 6.5
3w ago

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control

A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user i…

▾ SunlitCISA · MalcolmEPSS 0.47%via NVD
CVE-2026-90446Medium· 4.3
3w ago

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents

An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows …

▾ SunlitCISA · MalcolmEPSS 0.35%via NVD
CVE-2026-79395Critical· 9.8
3w ago

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass …

An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass …

▾ MidnightEPSS 0.77%via NVD
CVE-2026-79035Medium· 6.1
3w ago

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …

A reflected cross-site scripting (XSS) vulnerability in the p.rfihub.com component of Zeta Marketing Platform (ZMP) v1.0 allows attackers to execute arbitrary Javascript in the context of the victim's browser via injecting a crafted URL …

▾ SunlitEPSS 0.26%via NVD
CVE-2026-78807High· 7.1
3w ago

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

▾ TwilightRed Hat · Red Hat Enterprise Linux 6EPSS 0.11%via NVD
CVE-2026-78131Low· 3.7
3w ago

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

▾ Sunlitstrongswan · strongswanEPSS 0.23%via NVD
CVE-2026-72708High· 7.5PoC
3w ago

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the SQL escaping layer that allows unauthenticated attackers to inject arbitrary SQL by supplying a crafted annee parameter value matching a word charact…

▾ MidnightSPIP · SPIPEPSS 0.52%via NVD
CVE-2026-7298Medium· 6.1
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: before 8.4.2.0.

▾ SunlitIdeaSoft Software Industry and Trade Inc. · Smart E-CommerceEPSS 0.25%via NVD
CVE-2026-89245Medium· 6.5PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can cra…

▾ TwilightWWBN · AVideoEPSS 0.17%via NVD
CVE-2026-68497High· 7.5PoC
3w ago

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…

jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLD…

▾ MidnightFasterXML · com.fasterxml.jackson.core:jackson-databindEPSS 0.58%via NVD
CVE-2026-62139Medium· 4.3
3w ago

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

▾ SunlitGoogle · google-site-kitEPSS 0.10%via NVD
CVE-2026-14565Medium· 5.4
3w ago

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated …

The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated …

▾ SunlitEPSS 0.13%via NVD
CVE-2026-80942Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…

In the Linux kernel, the following vulnerability has been resolved: wifi: rtlwifi: rtl8192du: Fix possible memory leak in rtl92du_init_sw_vars() The memory allocated inside rtl92du_init_shared_data() is not freed in any of the subseque…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89454Medium· 4.4
3w ago

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…

In the Linux kernel, the following vulnerability has been resolved: PCI: plda: Fix IRQ domain leaks in the error paths of plda_init_interrupts() plda_init_interrupts() initializes IRQ domains and creates IRQ mapping but does not unwind…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-89453Medium· 5.5
3w ago

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Put PCI device after handling PPR faults iommu_call_iopf_notifier() looks up the requester with pci_get_domain_bus_and_slot(), which returns a PCI device wi…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVEs tagged “nvd” — page 354 · VulnSea