VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30150 CVEsRSS

CVE-2026-0305Medium· 4.3
3w ago

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and C…

An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and C…

▾ SunlitPalo Alto Networks · Prisma Access AgentEPSS 0.10%via NVD
CVE-2026-76562High· 7.2
3w ago

The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping

The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping. This m…

▾ Twilightotwthemes · Sidebar Manager LightEPSS 0.40%via NVD
CVE-2026-15820Medium· 6.4
3w ago

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping

The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. …

▾ Sunlitbuilderall · Builderall for WordPressEPSS 0.19%via NVD
CVE-2026-15019High· 7.5
3w ago

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function

The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read t…

▾ Twilightkamalyon · Direct Download for WooCommerceEPSS 0.68%via NVD
CVE-2026-18351Critical· 9.8PoC
3w ago

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function

The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type valid…

▾ Abyssaladdonsorg · Drag and Drop File Upload for Elementor FormsEPSS 1.0%via NVD
CVE-2026-87926Medium· 4.3PoC
3w ago

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f

A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the a…

▾ TwilightRizwan17 · inventory-management-systemEPSS 0.47%via NVD
CVE-2026-49836Medium· 4.6PoC
3w ago

psd-tools is a Python package for working with Adobe Photoshop PSD files

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …

▾ Twilightpsd-tools · psd-toolsEPSS 0.19%via NVD
CVE-2026-49837Medium· 5.9
3w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the f…

▾ Sunlitosrg · gobgpEPSS 0.33%via NVD
CVE-2026-49838Medium· 5.9
3w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …

▾ Sunlitosrg · gobgpEPSS 0.41%via NVD
CVE-2026-49313Medium· 5.5
3w ago

Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

Permission control vulnerability in the app lock module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

▾ SunlitHuawei · HarmonyOSEPSS 0.11%via NVD
CVE-2026-71801Critical· 9.8PoC
3w ago

An issue was discovered in s-pms SPMS-Server through v1.0

An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A r…

▾ AbyssalEPSS 0.79%via NVD
CVE-2026-56711High· 7.0
3w ago

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media

VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the pri…

▾ TwilightVideoLAN · VLC media playerEPSS 0.12%via NVD
CVE-2026-87997Medium· 4.3PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /api/chat/completions and POST /api/v1/chat/completions in backend/open_webui/main.py copied a client-supplied folder_id…

▾ Twilightopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-87016High· 8.1PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that…

▾ Midnightopenwebui · open_webuiEPSS 0.60%via NVD
CVE-2026-79515Medium· 4.3PoC
3w ago

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-79514Medium· 6.5PoC
3w ago

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request

An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted HTTP request. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.

▾ Twilightgpac · gpacEPSS 0.54%via NVD
CVE-2026-79513Medium· 6.5PoC
3w ago

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline

A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767…

▾ Twilightgpac · gpacEPSS 0.37%via NVD
CVE-2026-71809High· 8.1PoC
3w ago

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

▾ MidnightEPSS 0.59%via NVD
CVE-2026-87929Critical· 9.8PoC
3w ago

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies

MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can …

▾ AbyssalMaxSite · MaxSite CMSEPSS 0.53%via NVD
CVE-2026-87872Medium· 6.8
3w ago

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re…

▾ SunlitRed Hat · ansible-collection-community-generalEPSS 0.14%via NVD
CVE-2026-87825High· 7.7PoC
3w ago

zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced

zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dic…

▾ Midnightluben · zstd-jniEPSS 0.20%via NVD
CVE-2026-86775High· 8.6
3w ago

knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API

knowns (npm package) versions <= 0.29.1 contain a path traversal vulnerability in the Document API. The HTTP handler in internal/server/routes/docs.go normalizes the user-supplied document path with cleanDocPath(), which strips leading/t…

▾ Twilightknowns-dev · knownsEPSS 0.75%via NVD
CVE-2026-86770High· 8.1PoC
3w ago

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames

Snipe-IT before 8.7.0 fails to validate username case sensitivity during SAML authentication, allowing attackers to authenticate as different users by registering IdP accounts with accent or case variants of victim usernames. Attackers c…

▾ Midnightsnipeitapp · snipe-itEPSS 0.57%via NVD
CVE-2026-86765Medium· 6.5PoC
3w ago

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint

Snipe-IT versions before 8.7.0 fail to enforce checkout authorization when assignment fields are submitted to the asset update endpoint. Authenticated users with edit permission but explicitly denied checkout permission can reassign asse…

▾ Twilightsnipeitapp · snipe-itEPSS 0.40%via NVD
CVE-2026-86760Medium· 5.4PoC
3w ago

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update()

Snipe-IT versions 8.2.0 through 8.6.x (fixed in 8.7.0) contain an incorrect authorization flaw in app/Http/Controllers/Users/UsersController::update(). The single-user edit route assigned the activated field from the request payload befo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.38%via NVD
CVE-2026-86755Medium· 5.4
3w ago

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission ga…

Snipe-IT versions 4.2.0 through 8.6.3 expose Laravel Passport's auto-registered personal-access-token routes (GET, POST, DELETE /oauth/personal-access-tokens*) with only 'web' and 'auth:web' middleware, without the self.api permission ga…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.27%via NVD
CVE-2026-86750High· 7.7
3w ago

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API

Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before persisting user records via the REST API. In Api\UsersController::store() and ::update(), the user record is filled from the request and …

▾ Twilightsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-86745Medium· 6.5
3w ago

Snipe-IT is an IT asset management application

Snipe-IT is an IT asset management application. In Snipe-IT master-branch builds after 8.6.3 (the code was never included in a tagged release), SettingsController::downloadLocationScopingReport streams the FMCS location-scoping mismatch …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.36%via NVD
CVE-2026-86740Low· 3.8
3w ago

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk

Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api\\UploadedFilesController::destroy(), allowing deletion requests to report success while files remain on disk. Admini…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.29%via NVD
CVE-2026-86201High· 7.5PoC
3w ago

PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization

PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send craf…

▾ Midnightpmmp · PocketMine-MPEPSS 0.61%via NVD
CVEs tagged “nvd” — page 371 · VulnSea