VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30152 CVEsRSS

CVE-2026-87962High· 7.5PoC
3w ago

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data

t-digest versions 3.1 through 3.3 contain a denial of service vulnerability in MergingDigest.fromBytes that fails to validate length and capacity fields from serialized data. Attackers can supply crafted serialized digests with mismatche…

▾ Midnighttdunning · t-digestEPSS 0.63%via NVD
CVE-2026-81467Critical· 9.8
3w ago

Dell ThinOS 10, versions prior to 2605_10

Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially explo…

▾ Midnightdell · thinosEPSS 3.0%via NVD
CVE-2026-49363High· 7.5⚖ disputed
3w ago

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apa…

An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apa…

▾ Twilightapache · artemisEPSS 0.80%via NVD
CVE-2026-89089Medium· 6.5
3w ago

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon

A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user (ROLE_USER) can run the shipped, default-enabled online reports "…

▾ SunlitThe OpenNMS Group · MeridianEPSS 0.36%via NVD
CVE-2026-88024High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · rust_driverEPSS 0.48%via NVD
CVE-2026-89094Critical· 9.9
3w ago

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

▾ MidnightForgejo · ForgejoEPSS 0.85%via NVD
CVE-2026-0310High· 7.2
3w ago

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service …

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service …

▾ TwilightPalo Alto Networks · Cloud NGFWEPSS 0.37%via NVD
CVE-2026-87993High· 7.7
3w ago

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task event…

▾ TwilightHashiCorp · ToolingEPSS 0.38%via NVD
CVE-2026-88790Medium· 4.8PoC
3w ago

A security vulnerability has been detected in proma-ai Proma up to 0.19.37

A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath of the file apps/electron/src/main/lib/file-preview-service.ts of the component File Preview Service. Such manipulatio…

▾ Twilightproma-ai · PromaEPSS 0.17%via NVD
CVE-2026-88035Medium· 4.7
3w ago

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer

A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection setting…

▾ Sunlitmongodb · c_driverEPSS 0.10%via NVD
CVE-2026-19584High· 7.7
3w ago

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature

Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a mali…

▾ TwilightRapid7 · VelociraptorEPSS 0.19%via NVD
CVE-2026-88264Medium· 5.6
3w ago

A flaw was found in crun

A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected …

▾ Sunlitcontainers · crunEPSS 0.12%via NVD
CVE-2026-88056Critical· 9.1PoC
3w ago

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processe…

▾ Abyssalangular · angularEPSS 0.54%via NVD
CVE-2026-88884Medium· 5.8
3w ago

Renovate is a dependency update automation tool

Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0, mend-renovate-ce Helm chart before 15.4.0, mend-renovate-enterprise-edition Helm chart before 10.4.0), digest updat…

▾ Sunlitrenovatebot · renovateEPSS 0.30%via NVD
CVE-2026-79987High· 8.8
3w ago

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

▾ Twilightcraftcms · craftcms/cmsEPSS 0.65%via NVD
CVE-2026-76653Medium· 5.3
3w ago

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and mod…

A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 & v5) and TL-MR6400 v8 due to improper access control; a remote unauthenticated attacker may be able to access and mod…

▾ SunlitTP-Link Systems Inc. · TL-MR6400 v8EPSS 0.47%via NVD
CVE-2026-9768None
3w ago

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

▾ Sunlitvia NVD
CVE-2026-88877Critical· 9.8PoC
3w ago

Traefik is a HTTP reverse proxy and load balancer

Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-…

▾ Abyssaltraefik · traefikEPSS 0.65%via NVD
CVE-2026-88027High· 7.1
3w ago

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query conditi…

▾ Twilightmongodb · laravel_mongodbEPSS 0.27%via NVD
CVE-2026-88030High· 8.3
3w ago

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal ide…

▾ Twilightmongodb · ruby_driverEPSS 0.48%via NVD
CVE-2026-88051High· 7.8PoC
3w ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a c…

▾ Midnighttesseract-ocr · tesseract_ocrEPSS 0.17%via NVD
CVE-2026-88893High· 7.5
3w ago

OpenPanel through 2.3.0 share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers

OpenPanel through 2.3.0 share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes an…

▾ TwilightOpenpanel-dev · openpanelEPSS 0.43%via NVD
CVE-2026-88891High· 8.3PoC
3w ago

OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data

OpenPanel through 2.3.0 fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports…

▾ MidnightOpenpanel-dev · openpanelEPSS 0.37%via NVD
CVE-2026-88915High· 7.1
3w ago

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id

Affected versions of MISP do not consistently enforce the acting user's authorization when instantiating event templates. For templates using distribution = 4, the template can specify a sharing_group_id. The instantiation path passed …

▾ TwilightMISP · MISPEPSS 0.35%via NVD
CVE-2026-88272High· 7.2
3w ago

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

GeoVision GV-LPC2211 V1.13 allows an administrator-controlled username containing shell metacharacters to be executed as arbitrary root commands when the stored username is later deleted.

▾ TwilightGeoVision Inc. · GV-LPC2011/LPC2211EPSS 0.54%via NVD
CVE-2026-88885High· 7.0
3w ago

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode

Renovate before 44.14.7 contains a command injection vulnerability in the gomod manager when processing unescaped depName parameters in import-path update commands with binarySource=docker mode. Attackers can inject shell metacharacters …

▾ Twilightrenovatebot · renovateEPSS 0.89%via NVD
CVE-2026-88016High· 7.1PoC
3w ago

rclone is a command-line program to sync files and directories to and from different cloud storage providers

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and l…

▾ Midnightrclone · rcloneEPSS 0.19%via NVD
CVE-2026-82100Critical· 9.6
3w ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

▾ Midnightibm · datastage_on_cloud_pak_for_dataEPSS 0.61%via NVD
CVE-2026-81046Critical· 9.4
3w ago

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability

Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within…

▾ Midnightdell · thinosEPSS 0.55%via NVD
CVE-2026-88028Medium· 6.5
3w ago

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather tha…

▾ Sunlitmongodb · laravel_mongodbEPSS 0.42%via NVD
CVEs tagged “nvd” — page 364 · VulnSea