VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30146 CVEsRSS

CVE-2026-88880High· 8.6
3w ago

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests

Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify…

▾ Twilightrenovatebot · renovateEPSS 0.50%via NVD
CVE-2026-88044Critical· 9.1PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 const…

▾ Abyssalrclone · rcloneEPSS 0.49%via NVD
CVE-2026-88015Medium· 5.3PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.De…

▾ Twilightrclone · rcloneEPSS 0.36%via NVD
CVE-2026-88013Low· 3.7PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backen…

▾ Twilightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-88045High· 7.5PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentL…

▾ Midnightrclone · rcloneEPSS 0.63%via NVD
CVE-2026-89087High· 7.3
3w ago

The cstruct package before 6.3.0 for OCaml mishandles indexes.

The cstruct package before 6.3.0 for OCaml mishandles indexes.

▾ TwilightOCaml · cstructEPSS 0.32%via NVD
CVE-2026-79723Medium· 5.0
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

▾ Sunlitlangflow · langflowEPSS 0.35%via NVD
CVE-2026-81551High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.64%via NVD
CVE-2026-80434High· 7.4
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.31%via NVD
CVE-2026-9327Medium· 6.3
3w ago

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration

IBM WebSphere Application Server 9.0, and 8.5 could allow an authenticated user with a low-privilege administrative role to modify security configuration. This could result in information disclosure or denial of service.

▾ Sunlitibm · websphere_application_serverEPSS 0.37%via NVD
CVE-2026-88059Medium· 4.0
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authentic…

▾ Sunlitangular · angularEPSS 0.34%via NVD
CVE-2026-86087Medium· 4.3
3w ago

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.

▾ Sunlitibm · db2EPSS 0.34%via NVD
CVE-2026-82098High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.79%via NVD
CVE-2026-81554High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.77%via NVD
CVE-2026-45765High· 7.5
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, DNP3 reassembly could buffer data without sufficient parser-level bounds. Crafted D…

▾ Twilightoisf · suricataEPSS 0.62%via NVD
CVE-2026-45752Medium· 5.9
3w ago

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Starting in version 8.0.0 and prior to version 8.0.5, when certain detection transforms are chained, the decompress tra…

▾ Sunlitoisf · suricataEPSS 0.52%via NVD
CVE-2025-57231High· 7.5PoC
3w ago

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

Path Traversal in avatar attachments in Docmost v0.21.0 allows an unauthenticated malicious actor to disclose local files via a POST Request in a public url.

▾ MidnightEPSS 1.8%via NVD
CVE-2026-88890High· 8.5
3w ago

OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses

OpenPanel through 2.3.0 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.39%via NVD
CVE-2026-81793Medium· 6.5
3w ago

Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.8.

Missing Authorization vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Salon booking system: from n/a through 10.31.8.

▾ SunlitDimitri Grassi · salon-booking-systemEPSS 0.33%via NVD
CVE-2026-82099High· 8.8
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

▾ Twilightibm · datastage_on_cloud_pak_for_dataEPSS 0.81%via NVD
CVE-2026-81213High· 8.6
3w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

▾ Twilightlangflow · langflowEPSS 0.49%via NVD
CVE-2026-88036High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identi…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identi…

▾ Twilightmongodb · c_driverEPSS 0.27%via NVD
CVE-2026-79592High· 7.5PoC
3w ago

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

An out-of-bounds read vulnerability exists in the xls_dumpSummary() function of libxls 1.6.3 due to insufficient validation of file-controlled OLE summary offsets.

▾ MidnightEPSS 0.43%via NVD
CVE-2026-88874High· 7.5PoC
3w ago

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin

AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password…

▾ MidnightWWBN · AVideoEPSS 0.55%via NVD
CVE-2026-75880Medium· 6.5
3w ago

An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. …

An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. …

▾ Sunlitapache · artemisEPSS 0.65%via NVD
CVE-2026-75777High· 8.8
3w ago

IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.

IBM Aspera Enterprise WebApps 1.0.0 through 1.0.5 could allow a local attacker to escape container protections due to unrestricted system calls being permitted within the container.

▾ TwilightIBM · Aspera Enterprise WebAppsEPSS 0.15%via NVD
CVE-2026-87962High· 7.5PoC
3w ago

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatche…

▾ Midnighttdunning · t-digestEPSS 0.63%via NVD
CVE-2026-81467Critical· 9.8
3w ago

Dell ThinOS 10, versions prior to 2605_10

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially explo…

▾ Midnightdell · thinosEPSS 3.0%via NVD
CVE-2026-49363High· 7.5⚖ disputed
3w ago

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apa…

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apa…

▾ Twilightapache · artemisEPSS 0.80%via NVD
CVE-2026-89089Medium· 6.5
3w ago

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "…

▾ SunlitThe OpenNMS Group · MeridianEPSS 0.36%via NVD
CVEs tagged “nvd” — page 363 · VulnSea