VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30156 CVEsRSS

CVE-2026-21088High· 7.8
3w ago

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

Improper input validation in loading a subtitle frame in libsubextractor.so prior to SMR Sep-2026 Release 1 allows local attackers to write out-of-bounds memory.

▾ Twilightsamsung · androidEPSS 0.11%via NVD
CVE-2023-54355High· 7.5
3w ago

PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve

PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types…

▾ Twilightpmmp · PocketMine-MPEPSS 0.22%via NVD
CVE-2023-54394Medium· 4.3
3w ago

PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization

PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the s…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.38%via NVD
CVE-2026-79942Low· 3.4
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. A high privileged attacker with local access could potentiall…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.15%via NVD
CVE-2026-61910Low· 3.5
3w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annot…

▾ Sunlitcyrus · imapEPSS 0.19%via NVD
CVE-2026-21104Medium· 6.7
3w ago

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.

▾ Sunlitsamsung · androidEPSS 0.10%via NVD
CVE-2026-80122High· 7.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ Twilightdell · secure_connect_gatewayEPSS 0.22%via NVD
CVE-2026-87822High· 7.5
3w ago

t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to inject NaN values that bypass validation checks

t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to inject NaN values that bypass validation checks. Attackers can craft malicious serialized digests …

▾ Twilighttdunning · t-digestEPSS 0.67%via NVD
CVE-2026-86757Medium· 6.5
3w ago

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements

Snipe-IT before 8.7.0 fails to properly gate access to encrypted custom-field values in asset form templates for listbox, textarea, markdown-textarea, and date/datetime picker elements. Authenticated users with assets.edit, assets.checki…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.37%via NVD
CVE-2026-70425Medium· 6.7
3w ago

Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability

Dell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain a command injection vulnerability. An admin privileged local attacker could potentially exploit t…

▾ Sunlitdell · powerscale_onefsEPSS 0.53%via NVD
CVE-2026-79947Medium· 5.5
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low pr…

▾ Sunlitdell · secure_connect_gatewayEPSS 1.8%via NVD
CVE-2026-87853High· 7.5
3w ago

A flaw was found in SSSD's IdP authentication provider

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of …

▾ TwilightRed Hat · sssdEPSS 0.48%via NVD
CVE-2026-15667High· 7.5PoC
3w ago

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 4.1.22 via the 'event_layout' parameter parameter. This mak…

▾ Midnightarraytics · Eventin – Event Calendar, Tickets, Registration, Booking & WooCommerceEPSS 0.80%via NVD
CVE-2026-86743Medium· 5.0PoC
3w ago

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies

Snipe-IT versions before 8.7.0 fail to properly scope asset acceptance report queries by company, allowing authenticated reports.view users to read pending acceptances across all companies. Attackers can access the unaccepted_assets repo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.29%via NVD
CVE-2026-78483Medium· 5.9
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially ex…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.20%via NVD
CVE-2026-21085Medium· 6.7
3w ago

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

Out-of-bounds write in Keymaster trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to write out-of-bounds memory.

▾ Sunlitsamsung · androidEPSS 0.11%via NVD
CVE-2026-79950High· 7.5
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially expl…

▾ Twilightdell · secure_connect_gatewayEPSS 0.41%via NVD
CVE-2026-86768Medium· 5.4PoC
3w ago

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets

Snipe-IT before 8.7.0 fails to validate soft-deleted state in API checkout endpoints, allowing authenticated users with checkout permissions to bind live inventory to trashed targets. Attackers can submit POST requests to hardware, compo…

▾ Twilightsnipeitapp · snipe-itEPSS 0.35%via NVD
CVE-2026-88002Medium· 6.5
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but tra…

▾ Sunlitopenwebui · open_webuiEPSS 0.58%via NVD
CVE-2026-87015Medium· 6.8PoC
3w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/open_webui/utils/tools.py captured a cookie jar from the enclosing connection loop instead of binding it to each exte…

▾ Twilightopenwebui · open_webuiEPSS 0.48%via NVD
CVE-2026-86747Medium· 5.4
3w ago

Snipe-IT is an open source IT asset management system

Snipe-IT is an open source IT asset management system. In versions up to and including 8.6.3, the report acceptance endpoints POST /reports/unaccepted_assets/sent_reminder (ReportsController::sentAssetAcceptanceReminder) and DELETE /repo…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-86739Low· 3.1
3w ago

Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store()

Snipe-IT 8.6.3 and earlier do not check the return value of Storage::put() when writing the signature PNG and the generated acceptance PDF in Account\AcceptanceController::store(). On filesystem drivers that return false instead of throw…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.36%via NVD
CVE-2026-86742Medium· 6.5
3w ago

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export

Snipe-IT through 8.6.3 does not neutralize formula elements in the "unaccepted assets" acceptance report CSV export. ReportsController::postAssetAcceptanceReport builds the CSV by hand (stripping commas and joining rows manually) and, un…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.41%via NVD
CVE-2026-87735Medium· 4.3
3w ago

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml

An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml. There is an undocumented exception for a small message during RSA decryption or encryption.

▾ SunlitOCaml · mirage-crypto-pkEPSS 0.23%via NVD
CVE-2026-16272Critical· 9.1
3w ago

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc

Use of less trusted source vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API WHMCS Module allows Exploitation of Trusted Identifiers. This issue affects PayTR Virtual Pos iFrame API WHMCS …

▾ MidnightPayTR Payment and Electronic Money Institution Inc. · PayTR Virtual Pos iFrame API WHMCS ModuleEPSS 0.14%via NVD
CVE-2026-18147High· 8.1
3w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and comple…

▾ TwilightRed Hat · ipaEPSS 0.34%via NVD
CVE-2026-86767Medium· 5.0
3w ago

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset re…

Snipe-IT versions before 8.7.0 fail to apply company scope filtering to the GET /hardware/requested endpoint when Full Multiple Company Support is enabled, allowing authenticated users with assets.view permission to read pending asset re…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-86771High· 7.6PoC
3w ago

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function

Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a maliciou…

▾ Midnightsnipeitapp · snipe-itEPSS 0.32%via NVD
CVE-2026-86756Medium· 6.1
3w ago

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs)

Snipe-IT 8.5.0 through 8.6.3 contains an open redirect vulnerability in its SAML assertion-consumer endpoint (SamlController::acs, POST /saml/acs). The endpoint wrote the RelayState POST parameter directly into Laravel's url.intended ses…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.33%via NVD
CVE-2026-79961Medium· 5.3
3w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could po…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.40%via NVD
CVEs tagged “nvd” — page 375 · VulnSea