VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30148 CVEsRSS

CVE-2026-88033High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · java_driverEPSS 0.46%via NVD
CVE-2026-12683Medium· 5.4
3w ago

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation and Technology Inc. LIBRID/LIBREF allows Stored XSS. This issue affects LIBRID/LIBREF: from 2.01.0.2183 before 18.9…

▾ SunlitAnkaref Innovation and Technology Inc. · LIBRID/LIBREFEPSS 0.16%via NVD
CVE-2026-89011High· 7.1
3w ago

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path …

isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path …

▾ Twilightisomorphic-git · isomorphic-gitEPSS 0.44%via NVD
CVE-2026-88062Critical· 9.5PoC
3w ago

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers

OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand v…

▾ Abyssaldiegosouzapw · OmniRouteEPSS 1.4%via NVD
CVE-2026-88057Medium· 6.1
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compi…

▾ Sunlitangular · angularEPSS 0.26%via NVD
CVE-2026-88047High· 7.8
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whit…

▾ Twilighttesseract-ocr · tesseract_ocrEPSS 0.11%via NVD
CVE-2026-88017High· 7.3
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the se…

▾ Twilightrclone · rcloneEPSS 0.23%via NVD
CVE-2026-88012Medium· 5.3
3w ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connectio…

▾ Sunlittraefik · traefikEPSS 0.52%via NVD
CVE-2026-45768High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, LDAP transaction state could store an unbounded number of respons…

▾ Twilightoisf · suricataEPSS 0.70%via NVD
CVE-2026-45762High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's IP defragmentation tracker lookup did not verify that an existing tracke…

▾ Twilightoisf · suricataEPSS 0.61%via NVD
CVE-2026-88924High· 7.0PoC
3w ago

A flaw was found in the admin backend of gvfs

A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory…

▾ MidnightGNOME · gvfsEPSS 0.17%via NVD
CVE-2026-80378High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.38%via NVD
CVE-2026-80380High· 7.1
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.20%via NVD
CVE-2026-80436High· 8.5
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.38%via NVD
CVE-2026-88273High· 7.2
3w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled PPPoE username to escape a sourced shell configuration assignment and execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via NVD
CVE-2026-88032Medium· 5.9
3w ago

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled

A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able t…

▾ Sunlitmongodb · java_driverEPSS 0.26%via NVD
CVE-2026-84939Critical· 9.1
3w ago

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

▾ Midnightapache · freemarkerEPSS 0.85%via NVD
CVE-2026-88061Medium· 5.8
3w ago

career-ops is an open-source AI-assisted job search and application management tool

career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or …

▾ Sunlitsantifer · career-opsEPSS 0.38%via NVD
CVE-2026-88271High· 8.8
3w ago

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

GeoVision GV-LPC2211 V1.13 allows a Guest user to overwrite device configuration and replace the administrator password through SSVR.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.42%via NVD
CVE-2026-79725Medium· 6.5
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

▾ Sunlitlangflow · langflowEPSS 0.41%via NVD
CVE-2026-88871Medium· 4.3PoC
3w ago

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script …

▾ TwilightWWBN · AVideoEPSS 0.18%via NVD
CVE-2026-87931Critical· 9.6
3w ago

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707

A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation lead…

▾ MidnightBehavioral Technology Group · Pavlok Behavioral Conditioning WearableEPSS 0.60%via NVD
CVE-2026-87913Medium· 5.9
3w ago

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state…

A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state…

▾ SunlitAWS · AWS Security Agent MCP serverEPSS 0.44%via NVD
CVE-2026-88274High· 7.2
3w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled wireless SSID containing shell syntax to execute arbitrary commands as root.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.70%via NVD
CVE-2026-81210High· 7.7
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal

IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained t…

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.34%via NVD
CVE-2026-88283Medium· 4.9
3w ago

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticated administrator to overwrite stack control state and crash the ONVIF worker.

▾ SunlitGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.44%via NVD
CVE-2026-85544Medium· 6.1
3w ago

Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…

Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physical interaction with the device within their main card, which may allow attackers to forge a legitimate main card, th…

▾ SunlitHikvision · DS-KV9503EPSS 0.41%via NVD
CVE-2026-67593Critical· 9.1
3w ago

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects …

▾ Midnightapache · artemisEPSS 0.86%via NVD
CVE-2026-49362High· 7.5
3w ago

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…

An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56…

▾ Twilightapache · artemisEPSS 0.82%via NVD
CVE-2026-81796High· 7.3
3w ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

Authentication Bypass Using an Alternate Path or Channel vulnerability in WEN Solutions WP Travel wp-travel allows Password Recovery Exploitation.This issue affects WP Travel: from n/a through 12.0.3.

▾ TwilightWEN Solutions · wp-travelEPSS 0.40%via NVD
CVEs tagged “nvd” — page 362 · VulnSea