VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30134 CVEsRSS

CVE-2026-89009Critical· 9.1PoC
3w ago

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to th…

WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to th…

▾ AbyssalWAVLINK Technology · WN535M1EPSS 1.0%via NVD
CVE-2026-87988Critical· 10.0
3w ago

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed

An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside…

▾ Midnightmistralai · mistral-vibeEPSS 0.43%via NVD
CVE-2026-87987Critical· 10.0
3w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabl…

▾ Midnightmistralai · mistral-vibeEPSS 0.56%via NVD
CVE-2026-87986Critical· 10.0
3w ago

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret

An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded comman…

▾ Midnightmistralai · mistral-vibeEPSS 0.56%via NVD
CVE-2026-87984Critical· 9.3
3w ago

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval

An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permi…

▾ Midnightmistralai · mistral-vibeEPSS 0.50%via NVD
CVE-2026-87122None
3w ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-85984. Reason: This candidate is a reservation duplicate of CVE-2026-85984. Notes: All CVE users should reference CVE-2026-85984 instead of this candida…

▾ Sunlitvia NVD
CVE-2026-8303High· 7.8
3w ago

Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus-softwareEPSS 0.14%via NVD
CVE-2026-8301High· 7.8
3w ago

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardu…

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardu…

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus Boot RepairEPSS 0.84%via NVD
CVE-2026-7863High· 8.4
3w ago

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus S…

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus S…

▾ TwilightTUBITAK BILGEM Software Technologies Research Institute · Pardus SoftwareEPSS 0.95%via NVD
CVE-2026-89258Medium· 6.3
3w ago

Hugo is a static site generator

Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who…

▾ Sunlitgohugoio · hugoEPSS 0.47%via NVD
CVE-2026-89255High· 8.7PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated att…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89253High· 8.7PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() val…

▾ MidnightWWBN · AVideoEPSS 0.37%via NVD
CVE-2026-89248Medium· 5.3PoC
3w ago

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebR…

▾ TwilightWWBN · AVideoEPSS 0.50%via NVD
CVE-2026-89247Medium· 6.1PoC
3w ago

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script e…

▾ TwilightWWBN · AVideoEPSS 0.36%via NVD
CVE-2026-89212High· 8.6
3w ago

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing

A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1…

▾ TwilightPerforce · AkanaEPSS 0.44%via NVD
CVE-2026-87020High· 8.1
3w ago

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

▾ TwilightOrthanc · DICOM ServerEPSS 0.56%via NVD
CVE-2026-82583High· 8.3
3w ago

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary fil…

NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary fil…

▾ TwilightNextGen Healthcare · Mirth ConnectEPSS 0.45%via NVD
CVE-2026-82578High· 7.5
3w ago

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

▾ TwilightNextGen Healthcare · Mirth ConnectEPSS 0.41%via NVD
CVE-2026-78224High· 8.2
3w ago

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

▾ TwilightNextGen Healthcare · Mirth ConnectEPSS 0.44%via NVD
CVE-2026-71644Critical· 9.8
3w ago

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops p…

An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops p…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-71641High· 7.5
3w ago

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergen…

An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergen…

▾ TwilightEPSS 0.61%via NVD
CVE-2026-15710Medium· 6.8
3w ago

An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141

An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the…

▾ SunlitNetskope · Endpoint DLPEPSS 0.10%via NVD
CVE-2026-89242High· 7.2PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated …

▾ MidnightWWBN · AVideoEPSS 0.28%via NVD
CVE-2026-89179Medium· 4.3
3w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, there…

▾ SunlitHowyar · WeenyGeniusEPSS 0.16%via NVD
CVE-2026-89178High· 8.8
3w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing stude…

▾ TwilightHowyar · WeenyGeniusEPSS 0.36%via NVD
CVE-2026-89177High· 8.8
3w ago

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability

WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmit…

▾ TwilightHowyar · WeenyGeniusEPSS 0.36%via NVD
CVE-2026-89176High· 8.8
3w ago

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability

WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a stud…

▾ TwilightHowyar · WeenyGeniusEPSS 0.40%via NVD
CVE-2026-89175Medium· 5.3
3w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system confi…

▾ SunlitKingdom Communication Associated · EH3040EPSS 0.54%via NVD
CVE-2026-89174High· 7.5
3w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

▾ TwilightKingdom Communication Associated · EH3040EPSS 0.51%via NVD
CVE-2026-89173Medium· 5.3
3w ago

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability

Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.

▾ SunlitKingdom Communication Associated · EH3040EPSS 0.44%via NVD
CVEs tagged “nvd” — page 358 · VulnSea