VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25163 CVEsRSS

CVE-2026-85496High· 8.8
4d ago

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source

The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a suitably unpredictable source. An unauthenticated attacker with adjacent network access and knowledge that an active …

▾ TwilightBotslab · G980HEPSS 0.25%via NVD
CVE-2026-77967High· 8.1
4d ago

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client

The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshness or association with the requesting client. An unauthenticated attacker with adjacent network access who captures a …

▾ TwilightBotslab · G980HEPSS 0.24%via NVD
CVE-2026-97324High· 7.3
4d ago

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderCon…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.28%via NVD
CVE-2026-96883High· 8.8
4d ago

pgcollection is an open source extension to PostgreSQL

pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user to execute arbitrary code as the postgres operating system user via crafted S…

▾ TwilightAWS · pgcollectionEPSS 0.65%via NVD
CVE-2026-82372High· 8.5
4d ago

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs

Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.1a results in pre-shared keys being recorded in application logs. Individuals with read access to system log files or…

▾ TwilightBrocade · SANnavEPSS 0.17%via NVD
CVE-2026-48542Medium· 5.4
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

▾ Sunlitkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-97325Medium· 4.3PoC
4d ago

A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability is the function validOAuthClientFromCache of the file yudao-module-system/src/main/java/cn/iocoder/yudao/module/syste…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.26%via NVD
CVE-2026-82164High· 7.1
4d ago

Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability

Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to…

▾ TwilightDell · Trusted Device Client,EPSS 0.09%via NVD
CVE-2026-93291Critical· 9.4
4d ago

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.

▾ MidnightEufy · Omni C20EPSS 0.24%via NVD
CVE-2026-48543Medium· 5.4PoC
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

▾ Twilightkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-48541Medium· 5.4
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

▾ Sunlitkrayin · laravel-crmEPSS 0.14%via NVD
CVE-2026-93290Medium· 5.5
4d ago

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access information like mapping data.

▾ SunlitEufy · Omni C20EPSS 0.11%via NVD
CVE-2026-84399High· 8.8
4d ago

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality

The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionality. The product does not sufficiently associate an authenticated session with the client connection that established i…

▾ TwilightBotslab · G980HEPSS 0.19%via NVD
CVE-2026-48540Medium· 5.4PoC
4d ago

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

▾ Twilightkrayin · laravel-crmEPSS 0.17%via NVD
CVE-2026-93289High· 7.5
4d ago

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute system commands during the pairing process.

▾ TwilightEufy · Omni C20EPSS 0.68%via NVD
CVE-2026-82566High· 8.8
4d ago

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced

The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions…

▾ TwilightBotslab · G980HEPSS 0.28%via NVD
CVE-2026-97323Medium· 6.3PoC
4d ago

A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOriginalFilename of the file yudao-module-mp/src/main/java/cn/iocoder/yudao/module/mp/service/material/MpMaterialServiceImpl…

▾ TwilightYunaiV · ruoyi-vue-proEPSS 0.40%via NVD
CVE-2026-97322Medium· 4.3
4d ago

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the file yudao-module-infra/src/main/java/cn/iocoder/yudao/module/infra/controller/admin/file/FileController.java of the c…

▾ SunlitYunaiV · ruoyi-vue-proEPSS 0.26%via NVD
CVE-2026-89325High· 7.8
4d ago

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Asse…

An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, low-privileged user to execute arbitrary code as SYSTEM via a planted executable resolved from the machine PATH. Asse…

▾ TwilightRapid7 · Insight AgentEPSS 0.13%via NVD
CVE-2026-86860Critical· 9.3
4d ago

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform

ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to extract instance data beyond what wa…

▾ MidnightServiceNow · ServiceNow AI PlatformEPSS 0.30%via NVD
CVE-2026-86859High· 8.7
4d ago

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform

ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This security issue, if exploited, could enable an unauthenticated user to access data within the ServiceNow AI Platform …

▾ TwilightServiceNow · ServiceNow AI PlatformEPSS 0.29%via NVD
CVE-2026-86858High· 8.7
4d ago

ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform

ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. This security issue could enable an unauthenticated user, in certain circumstances, to create, modify, or delete insta…

▾ TwilightServiceNow · ServiceNow AI PlatformEPSS 0.27%via NVD
CVE-2026-82157High· 8.3
4d ago

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading t…

▾ TwilightDell · ThinOS 10EPSS 0.12%via NVD
CVE-2026-81473High· 8.1
4d ago

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

▾ TwilightDell · Rugged Control Center (RCC)EPSS 0.09%via NVD
CVE-2026-81455High· 8.6
4d ago

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability

Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading …

▾ TwilightDell · ThinOS 10EPSS 0.26%via NVD
CVE-2026-57440High· 7.5
4d ago

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services

The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with $wgEmbedVideoRequireConsent disabled (n…

▾ TwilightStarCitizenWiki · mediawiki-extensions-EmbedVideoEPSS 0.26%via NVD
CVE-2026-56792Medium· 4.4
4d ago

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability

Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

▾ SunlitDell · Rugged Control Center (RCC)EPSS 0.09%via NVD
CVE-2026-13016Critical· 9.3
4d ago

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform

ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the…

▾ MidnightServiceNow · ServiceNow AI PlatformEPSS 0.27%via NVD
CVE-2026-77293High· 7.1PoC
4d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId endpoint authorizes an authenticated user against the attacker-controlled tripId but deleteNoteFile in server/src/se…

▾ Midnightmauriceboe · TREKEPSS 0.38%via NVD
CVE-2026-85738Medium· 6.3
4d ago

TREK is a collaborative travel planner

TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not recognize NAT64, 6to4, or Teredo IPv6 transition addresses that encode an IPv4 destination. An authenticated user who c…

▾ Sunlitliketrek · TREKEPSS 0.30%via NVD
CVEs tagged “nvd” — page 39 · VulnSea