VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30158 CVEsRSS

CVE-2026-79967Medium· 5.6
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.15%via NVD
CVE-2024-58380Medium· 6.5
3w ago

PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided

PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an inven…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2026-81644Medium· 4.3
3w ago

DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

DoS vulnerability in the preview service module. Impact: Successful exploitation of this vulnerability may affect availability.

▾ SunlitHuawei · HarmonyOSEPSS 0.23%via NVD
CVE-2026-79966Low· 3.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

▾ Sunlitdell · secure_connect_gatewayEPSS 0.14%via NVD
CVE-2026-87807High· 7.5
3w ago

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter

siyuan versions before v3.8.2 contain an authenticated SQL injection vulnerability in the fullTextSearchBlock endpoint's method=1 query parameter. Attackers can inject UNION SELECT statements to read the entire blocks table, bypassing pu…

▾ Twilightsiyuan-note · siyuanEPSS 0.45%via NVD
CVE-2026-79617High· 7.1PoC
3w ago

Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

Incorrect Permission Assignment for Critical Resource vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Pardus LightDM Greeter allows Exploiting Incorrectly Configured Access Control Security Levels. This issue af…

▾ MidnightTÜBİTAK BİLGEM Software Technologies Research Institute · Pardus LightDM GreeterEPSS 0.14%via NVD
CVE-2026-86198Medium· 4.2
3w ago

PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling

PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedl…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2026-21090High· 7.8⚖ disputed
3w ago

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in libsaviextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21113Medium· 5.5
3w ago

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

Improper export of android application components in Visual Voicemail prior to version 20.1.00.05 allows local attackers to initiate call without proper permission.

▾ Sunlitsamsung · visual_voicemailEPSS 0.08%via NVD
CVE-2026-40635Medium· 5.4
3w ago

Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability

Dell PowerScale OneFS versions 9.12.0.0 through 9.13.1.0 contain an Insecure Temporary File vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to denial of service and information tamper…

▾ Sunlitdell · powerscale_onefsEPSS 0.39%via NVD
CVE-2026-86200Medium· 5.3
3w ago

PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT

PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.64%via NVD
CVE-2026-79963High· 7.4
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with remote access could potent…

▾ Twilightdell · secure_connect_gatewayEPSS 0.27%via NVD
CVE-2026-79970Medium· 5.6
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Verification of Cryptographic Signature vulnerability. An unauthenticated attacker with remote access cou…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.17%via NVD
CVE-2026-80171Medium· 4.7
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Entropy in PRNG vulnerability. A low privileged attacker with local access could potentially exploit …

▾ Sunlitdell · secure_connect_gatewayEPSS 0.12%via NVD
CVE-2026-87811High· 7.3PoC
3w ago

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding

SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScrip…

▾ Midnightsiyuan-note · siyuanEPSS 0.37%via NVD
CVE-2026-87813High· 7.3PoC
3w ago

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping

SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing ma…

▾ Midnightsiyuan-note · siyuanEPSS 0.37%via NVD
CVE-2026-21112Medium· 5.5
3w ago

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege

Improper input validation in Samsung Tips prior to Android 17 allows local attackers to launch arbitrary activity with Samsung Tips privilege. User interaction is required for triggering this vulnerability.

▾ Sunlitsamsung · androidEPSS 0.09%via NVD
CVE-2026-57825Medium· 5.7
3w ago

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

▾ SunlitOCaml · opamEPSS 0.47%via NVD
CVE-2026-87035Medium· 4.3
3w ago

Tanium addressed an information disclosure vulnerability in Comply.

Tanium addressed an information disclosure vulnerability in Comply.

▾ Sunlittanium · complyEPSS 0.30%via NVD
CVE-2026-87823High· 8.2PoC
3w ago

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near…

▾ Midnightluben · zstd-jniEPSS 0.43%via NVD
CVE-2026-61915Medium· 4.2
3w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two o…

▾ Sunlitcyrus · imapEPSS 0.26%via NVD
CVE-2026-88001Medium· 5.0PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when A…

▾ Twilightopenwebui · open_webuiEPSS 0.38%via NVD
CVE-2026-79974Medium· 6.4
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.30%via NVD
CVE-2025-71417Medium· 6.5
3w ago

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple co…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.31%via NVD
CVE-2026-78485High· 7.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated a…

▾ Twilightdell · secure_connect_gatewayEPSS 0.37%via NVD
CVE-2026-82563High· 7.6
3w ago

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position

An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of fir…

▾ TwilightSoftish · EarVision Android applicationEPSS 0.24%via NVD
CVE-2026-21091High· 7.8⚖ disputed
3w ago

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in libcodec2secevrcdec.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.10%via NVD
CVE-2026-21102Medium· 6.7⚖ disputed
3w ago

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

Use after free in DualDAR prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code with root privilege.

▾ Sunlitsamsung · androidEPSS 0.12%via NVD
CVE-2026-86773Medium· 5.4PoC
3w ago

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits

Snipe-IT through version 8.6.3 fails to perform object-level authorization in the updateLicense, updateConsumable, updateAccessory, and updateModel endpoints and in the storeModel endpoint for Predefined Kits. The existing check authoriz…

▾ Twilightsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-21106Medium· 5.1
3w ago

Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.

Improper verification of intent by broadcast receiver in Samsung Cloud Assistant prior to version 9.0.5 allows local attackers to disable enhanced data protection settings.

▾ SunlitSamsung Mobile · Samsung Cloud AssistantEPSS 0.10%via NVD
CVEs tagged “nvd” — page 373 · VulnSea