VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25164 CVEsRSS

CVE-2026-93399Critical· 9.1PoC
3d ago

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX ac…

▾ Abyssalladela · Online Scheduling and Appointment Booking System – BooklyEPSS 0.37%via NVD
CVE-2026-96039High· 7.2
3d ago

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping

The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it poss…

▾ Twilightbookingalgorithms · BA Book EverythingEPSS 0.24%via NVD
CVE-2026-92746Medium· 6.4
3d ago

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, and including, 4.0.8 due to insufficient…

The Gutenverse – WordPress Blocks, Page Builder & Site Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Comment Block 'suffixMain' Attribute in all versions up to, and including, 4.0.8 due to insufficient…

▾ Sunlitjegstudio · Gutenverse – WordPress Blocks, Page Builder & Site EditorEPSS 0.19%via NVD
CVE-2026-97721Low· 2.7
3d ago

A weakness has been identified in Sanluan PublicCMS up to 6.202506.e

A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContentAdminController of the file publiccms-parent/publiccms-core/src/main/java/com/publiccms/controller/admin/sys/SysUserA…

▾ SunlitSanluan · PublicCMSEPSS 0.24%via NVD
CVE-2026-97764Low· 3.7
3d ago

django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.

django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configurations, an attacker can leverage the handling of diacritics (e.g., accents) for a higher effective limit.

▾ Sunlitallauth · django-allauthEPSS 0.23%via NVD
CVE-2026-97737High· 7.4
3d ago

In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.

In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.

▾ Twilightmuety · WakapiEPSS 0.27%via NVD
CVE-2026-97818High· 8.6
3d ago

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php.

▾ Twilightphpipam · phpIPAMEPSS 0.32%via NVD
CVE-2026-97736Medium· 5.4
3d ago

tinyauth before 5.1.3 allows rule bypass by appending an allowed route string

tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular expression.

▾ Sunlittinyauth · github.com/tinyauthapp/tinyauthEPSS 0.21%via NVD
CVE-2026-97732Medium· 5.1
3d ago

IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root…

IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for expected publisher and root-certificate strings in WIN_CERTIFICATE data ("IRONMACE Co., Ltd." and "DigiCert Trusted Root…

▾ SunlitIRONMACE · IronshieldEPSS 0.06%via NVD
CVE-2025-14814Medium· 6.4
3d ago

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping o…

The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's cjtoolbox shortcode in all versions up to, and including, 12.0.6 due to insufficient input sanitization and output escaping o…

▾ Sunlitwipeoutmedia · CSS & JavaScript ToolboxEPSS 0.16%via NVD
CVE-2026-97735High· 8.0
3d ago

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.

▾ TwilightITFlow · ITFlowEPSS 0.25%via NVD
CVE-2026-97731High· 7.1
3d ago

MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list

MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and nev…

▾ TwilightMinIO · MinIOEPSS 0.15%via NVD
CVE-2026-97650Medium· 4.3
3d ago

A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function echo of the file admin/fun/addLog.php. The manipulation of the argument reason/…

▾ Sunlitningzichun · student-management-systemEPSS 0.27%via NVD
CVE-2026-97730High· 8.5
3d ago

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To ex…

▾ TwilightNetgate · pfSense PlusEPSS 1.0%via NVD
CVE-2026-97724Medium· 4.3PoC
3d ago

A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePl…

A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlled object containing a __proto__ property to modify the prototype of an object created during serialization in clonePl…

▾ Twilightswmansion · React Native ReanimatedEPSS 0.25%via NVD
CVE-2026-97723Medium· 5.4
3d ago

madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality

madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering functionality. User-controlled URLs in chat messages were insufficiently neutralized before being converted into HTML l…

▾ Sunlitmadpsy · ka9q_ubersdrEPSS 0.21%via NVD
CVE-2026-97648Medium· 4.3PoC
3d ago

A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function. Performing a manipulation results in cross-site request forgery. It is possible to init…

▾ Twilightningzichun · student-management-systemEPSS 0.16%via NVD
CVE-2026-97647Medium· 5.3
3d ago

A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This impacts an unknown function of the file user/editLog.php. Such manipulation of the argument sid/addti…

▾ Sunlitningzichun · student-management-systemEPSS 0.31%via NVD
CVE-2026-95811Medium· 6.5PoC
3d ago

Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost…

Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow an equivalent spelling of a path to bypass the locationRules that restrict it. The handler matches each vhost…

▾ TwilightRed Hat · Lemonldap-NG-HandlerEPSS 0.40%via NVD
CVE-2026-97649Medium· 4.7PoC
3d ago

A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this vulnerability is an unknown functionality of the file example_lite.sql. Executing a manipulation can lead to u…

▾ Twilightningzichun · student-management-systemEPSS 0.23%via NVD
CVE-2026-85417Medium· 6.4
3d ago

Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions

Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be recorded in application logs under specific configuration conditions. Individuals with read access to system logs or supp…

▾ SunlitBrocade · SANnavEPSS 0.19%via NVD
CVE-2026-53493Medium· 6.9
3d ago

containerd is an open-source container runtime

containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCr…

▾ Sunlitcontainerd · containerdEPSS 0.36%via NVD
CVE-2026-97646High· 7.3PoC
3d ago

A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes au…

▾ Midnightningzichun · student-management-systemEPSS 0.30%via NVD
CVE-2026-92289Critical· 9.1PoC⚖ disputed
3d ago

Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaD…

Lemonldap::NG::Portal versions from 2.23.0 before 2.23.4 for Perl allow a PKCE bypass for public Relying Parties in "PKCE or secret" mode because checkEndPointAuthenticationCredentials does not verify the client secret. With oidcRPMetaD…

▾ AbyssalRed Hat · Lemonldap-NG-PortalEPSS 0.22%via NVD
CVE-2026-92288Critical· 9.1PoC⚖ disputed
3d ago

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Re…

Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl allow unauthenticated OAuth2 token introspection because checkEndPointAuthenticationCredentials does not verify the client secret of a public Re…

▾ AbyssalRed Hat · Lemonldap-NG-PortalEPSS 0.37%via NVD
CVE-2026-85082High· 8.5PoC
3d ago

Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.

Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely separating the filename from the command.

▾ MidnightMaple Media · Root Browser ClassicEPSS 0.13%via NVD
CVE-2026-84283Medium· 6.8PoC
3d ago

Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree

Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-storage tree. A local application or file manager that has access to the relevant shared-storage path can enumerate, copy…

▾ TwilightFluteCode · Secure FolderEPSS 0.11%via NVD
CVE-2026-97387None
4d ago

Rejected reason: This CVE is a duplicate of another CVE.

Rejected reason: This CVE is a duplicate of another CVE.

▾ Sunlitvia NVD
CVE-2026-97230Critical· 9.8
4d ago

IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file

IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrie…

▾ MidnightEPSS 0.24%via NVD
CVE-2026-97636Medium· 6.5
4d ago

Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key

Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-controlled key. In a multi-team deployment, a Dag author scoped to one team can supply a Variable key containing a path…

▾ SunlitApache Software Foundation · apache-airflow-providers-hashicorpEPSS 0.37%via NVD
CVEs tagged “nvd” — page 37 · VulnSea