VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30148 CVEsRSS

CVE-2026-19985Medium· 6.1
3w ago

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters

The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input…

▾ Sunlitcomesio · Relevanssi – A Better SearchEPSS 0.26%via NVD
CVE-2026-18964Medium· 6.1
3w ago

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and in…

The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and in…

▾ Sunlitpremio · Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – ChatyEPSS 0.22%via NVD
CVE-2026-18562Medium· 6.1
3w ago

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3

The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insuffic…

▾ Sunlitrealmag777 · HUSKY – Products Filter for WooCommerce ProfessionalEPSS 0.23%via NVD
CVE-2026-15462High· 7.5
3w ago

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2

The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data(…

▾ Twilightgingerplugins · Sticky Chat Widget – Floating Chat Icons, Contact Form, Call, Click to Chat, Email & Message ButtonsEPSS 0.30%via NVD
CVE-2026-81906Medium· 6.3
3w ago

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session

Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete a…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.62%via NVD
CVE-2026-78126Medium· 5.9
3w ago

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

▾ Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-78123Medium· 5.9
3w ago

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

▾ Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-12215Medium· 5.3
3w ago

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2

The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `pro…

▾ Sunlitxootix · OTP Login & Register WoocommerceEPSS 0.32%via NVD
CVE-2026-11446Medium· 5.3
3w ago

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23

The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() pe…

▾ Sunlitarraytics · Booktics – Appointment Booking Calendar for Service BusinessesEPSS 0.24%via NVD
CVE-2025-15679High· 7.3
3w ago

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

▾ TwilightBull · BullSequana XH3406EPSS 0.11%via NVD
CVE-2025-15695Low· 3.5
3w ago

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScri…

The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScri…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-50013High· 7.5
3w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy…

▾ TwilightSpectoLabs · hoverflyEPSS 0.47%via NVD
CVE-2026-50018Medium· 6.5PoC
3w ago

Hoverfly is an open source API simulation tool

Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP con…

▾ TwilightSpectoLabs · hoverflyEPSS 0.54%via NVD
CVE-2026-49992Medium· 6.3
3w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exp…

▾ Sunlitkimai · kimaiEPSS 0.22%via NVD
CVE-2026-54174High· 8.3
3w ago

melange allows users to build apk packages using declarative pipelines

melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but…

▾ Twilightchainguard-dev · melangeEPSS 0.15%via NVD
CVE-2026-54072Critical· 9.3PoC
3w ago

Authorizer is an open-source, self-hostable authentication and authorization server

Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` …

▾ Abyssalauthorizerdev · authorizerEPSS 0.46%via NVD
CVE-2026-49865Medium· 5.3PoC
3w ago

Kimai is an open-source time tracking application

Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulnerability in their invoice PDF preview and generation workflow. If an attacker can control Markdown content that is lat…

▾ Twilightkimai · kimaiEPSS 0.35%via NVD
CVE-2026-49463Medium· 6.5
3w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:documenten-api` package through version 3.0.0 and the `n…

▾ Sunlitnl-portal · nl.nl-portal:besluitenEPSS 0.34%via NVD
CVE-2026-49464High· 8.1
3w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to …

▾ Twilightnl-portal · nl-portal-backend-librariesEPSS 0.35%via NVD
CVE-2026-49439Medium· 4.3
3w ago

OpenRemote is an open-source internet-of-things platform

OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.

▾ Sunlitopenremote · openremoteEPSS 0.26%via NVD
CVE-2026-48496Medium· 6.2
3w ago

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to o…

▾ Sunlitopen-telemetry · opentelemetry-ebpf-profilerEPSS 0.18%via NVD
CVE-2026-88888High· 7.0
3w ago

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters

Renovate before 44.14.7 contains a command injection vulnerability in the Mix manager when processing private dependencies with unescaped organization parameters. Attackers can inject shell metacharacters through malicious package names …

▾ Twilightrenovatebot · renovateEPSS 0.89%via NVD
CVE-2026-88053High· 7.8PoC
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .trainedda…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.18%via NVD
CVE-2026-86093High· 7.5
3w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that imp…

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that imp…

▾ Twilightibm · db2EPSS 0.45%via NVD
CVE-2026-85025Critical· 9.8
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow …

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow …

▾ Midnightlangflow · langflowEPSS 0.61%via NVD
CVE-2026-81941High· 8.8
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP To…

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP To…

▾ Twilightlangflow · langflowEPSS 0.63%via NVD
CVE-2026-81940High· 8.8
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

▾ Twilightlangflow · langflowEPSS 0.81%via NVD
CVE-2026-81268High· 8.1
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

▾ Twilightlangflow · langflowEPSS 0.43%via NVD
CVE-2026-81211High· 8.8
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

▾ Twilightlangflow · langflowEPSS 0.50%via NVD
CVE-2026-81204Critical· 9.8
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

▾ Midnightlangflow · langflowEPSS 0.86%via NVD
CVEs tagged “nvd” — page 360 · VulnSea