VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25164 CVEsRSS

CVE-2026-87722High· 8.7
4d ago

Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling predicates) and REST regex filter endpoints (RegexListSearcher /pr…

Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, RegexRefPredicate, RegexPathPredicate, and sibling predicates) and REST regex filter endpoints (RegexListSearcher /pr…

▾ TwilightGerrit · GerritEPSS 0.32%via NVD
CVE-2026-87721High· 8.7
4d ago

Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthentic…

Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerrit Code Review versions 2.0.19 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through 3.14.2 allows an unauthentic…

▾ TwilightGerrit · GerritEPSS 0.32%via NVD
CVE-2026-87720High· 7.6PoC
4d ago

Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 throu…

Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 throu…

▾ MidnightGerrit · GerritEPSS 0.25%via NVD
CVE-2026-85491High· 8.8
4d ago

Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal replaces the dispatcher's prepare_acti…

Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorization check via a dispatch memo keyed on the request path alone. Catalyst::Seal replaces the dispatcher's prepare_acti…

▾ TwilightEPSS 0.36%via NVD
CVE-2026-14441Medium· 6.9
4d ago

A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures

A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when processing specific user account structures. The issue has been remediated by updating the internal comparison routines …

▾ SunlitBrocade · SANnavEPSS 0.36%via NVD
CVE-2026-84403Medium· 6.2
4d ago

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics

The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access to Bluetooth Low Energy communications and GATT characteristics. An unauthenticated attacker within Bluetooth range …

▾ SunlitBotslab · G980HEPSS 0.12%via NVD
CVE-2026-82716Medium· 4.6
4d ago

The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process

The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diagnostic logs generated during the support process. These logs remain accessible on removable storage after the support…

▾ SunlitBotslab · G980HEPSS 0.17%via NVD
CVE-2026-14443High· 8.4
4d ago

Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs

Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extension switch pre-shared keys to be written to system logs. Individuals with read access to container logs or support arch…

▾ TwilightBrocade · SANnavEPSS 0.11%via NVD
CVE-2026-81630High· 8.1
4d ago

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates

The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update process retrieves firmware through an unprotected connection and relies on an integrity value supplied with the firmware i…

▾ TwilightBotslab · G980HEPSS 0.19%via NVD
CVE-2026-75558Medium· 5.3
4d ago

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device

The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi credentials communicated by the device. An attacker who obtains the protected credential and extracts the cryptographic …

▾ SunlitBotslab · G980HEPSS 0.16%via NVD
CVE-2026-97366Medium· 6.3PoC
4d ago

A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0

A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function openDevTools of the file electron/window.js of the component Open in Editor Handler. The manipulation of the argumen…

▾ Twilightjhen0409 · react-native-debuggerEPSS 1.2%via NVD
CVE-2026-87118Medium· 5.7
4d ago

The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality

The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functionality. An authenticated attacker with adjacent network access could submit crafted command data that corrupts memory, …

▾ SunlitBotslab · G980HEPSS 0.24%via NVD
CVE-2026-82708Medium· 6.5
4d ago

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server

The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with access to the device's WiFi network could submit a crafted request to access files within the device's removable storage …

▾ SunlitBotslab · G980HEPSS 0.21%via NVD
CVE-2026-79959Medium· 6.8
4d ago

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user

The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. An attacker who obtains the firmware or has physical access to the device could recover the credential and use it to o…

▾ SunlitBotslab · G980HEPSS 0.17%via NVD
CVE-2026-97368Medium· 6.3PoC
4d ago

A weakness has been identified in chillzhuang SpringBlade up to 5.0.2

A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInfo of the file blade-service/blade-system/src/main/java/org/springblade/system/service/impl/UserServiceImpl.java of th…

▾ Twilightchillzhuang · SpringBladeEPSS 0.23%via NVD
CVE-2026-93353Medium· 5.3PoC
4d ago

copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that…

copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users to create, remove, and truncate arbitrary paths outside permitted volume boundaries by exploiting three handlers that…

▾ Twilight9001 · copypartyEPSS 0.32%via NVD
CVE-2026-82585Medium· 6.5
4d ago

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections

The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An attacker capable of intercepting communications on the device's WiFi network could obtain stored recordings, live video…

▾ SunlitBotslab · G980HEPSS 0.13%via NVD
CVE-2026-88387Medium· 5.5
4d ago

LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType)

LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF tag 0x00fe (NewSubfileType). A specially crafted RAW, TIFF, or DNG file can supply an attacker-controlled NewSubfileTyp…

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-95699Critical· 9.6
4d ago

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' dev…

Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' dev…

▾ MidnightMrSteam · iSteamX applicationEPSS 0.30%via NVD
CVE-2026-88388High· 7.5
4d ago

Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds

Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace handling path on 64-bit builds. A remote attacker can supply JavaScript input that triggers an exception and reaches …

▾ TwilightEPSS 0.32%via NVD
CVE-2026-88386Medium· 5.5PoC
4d ago

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform …

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.10%via NVD
CVE-2026-14442Medium· 6.9
4d ago

An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text

An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be written to application logs in plain text. When scheduled support save jobs or related operational tasks are executed, sen…

▾ SunlitBrocade · SANnavEPSS 0.16%via NVD
CVE-2026-97365Medium· 6.3
4d ago

A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2

A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file crates/littrs/src/lib.rs. Executing a manipulation of the argument relative can lead to path traversal. The attack may …

▾ Sunlitchonkie-inc · littrsEPSS 0.35%via NVD
CVE-2026-97326High· 7.3PoC
4d ago

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d

A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of…

▾ Midnightsongxinjianqwe · ChatEPSS 0.28%via NVD
CVE-2026-93354High· 8.1
4d ago

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registratio…

Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registratio…

▾ TwilightGimanh · taskview-communityEPSS 0.27%via NVD
CVE-2026-88956Medium· 6.8
4d ago

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface

The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the device's UART interface. The affected account does not require a password before granting access to a privileged syst…

▾ SunlitBotslab · G980HEPSS 0.22%via NVD
CVE-2026-88761Medium· 5.3
4d ago

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product

The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portions of which are advertised by the product. An unauthenticated attacker within WiFi range could potentially determine t…

▾ SunlitBotslab · G980HEPSS 0.17%via NVD
CVE-2026-85496High· 8.8
4d ago

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active …

▾ TwilightBotslab · G980HEPSS 0.25%via NVD
CVE-2026-77967High· 8.1
4d ago

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a …

▾ TwilightBotslab · G980HEPSS 0.24%via NVD
CVE-2026-97324High· 7.3
4d ago

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderCon…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.28%via NVD
CVEs tagged “nvd” — page 38 · VulnSea