VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30161 CVEsRSS

CVE-2026-19651High· 7.4
3w ago

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

▾ TwilightIBM · Enterprise Build of QuarkusEPSS 0.26%via NVD
CVE-2026-85983High· 7.8
3w ago

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configur…

▾ TwilightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.20%via NVD
CVE-2026-85982Critical· 9.0
3w ago

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to …

▾ MidnightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.40%via NVD
CVE-2026-85981Medium· 6.7
3w ago

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to acce…

▾ SunlitAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.18%via NVD
CVE-2026-84685Medium· 6.5
3w ago

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. U…

▾ SunlitAuth0 · react-native-auth0EPSS 0.28%via NVD
CVE-2026-81192High· 7.0
3w ago

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute dete…

▾ Twilightopen-telemetry · opentelemetry-dotnet-contribEPSS 0.18%via NVD
CVE-2026-78622Medium· 6.0
3w ago

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recurs…

▾ SunlitOkta · Okta Verify for WindowsEPSS 0.13%via NVD
CVE-2026-19625Medium· 5.3⚖ disputed
3w ago

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

▾ SunlitIBM · Enterprise Build of QuarkusEPSS 0.23%via NVD
CVE-2026-86819High· 7.1
3w ago

Waves Central for macOS contains a local privilege escalation in the privileged helper service

Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than …

▾ TwilightWaves Audio Ltd. · Waves CentralEPSS 0.10%via NVD
CVE-2026-77827High· 7.1PoC
3w ago

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

▾ MidnightMaono · Maono LinkEPSS 0.16%via NVD
CVE-2026-81975High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-79908High· 7.8
3w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-30754High· 8.8
3w ago

A memory corruption vulnerability exists in FFmpeg before 8.1

A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC str…

▾ TwilightRed Hat · Red Hat Enterprise Linux AI (RHEL AI) 3EPSS 0.51%via NVD
CVE-2026-82001Medium· 5.5
3w ago

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application deni…

▾ Sunlitadobe · acrobatEPSS 0.23%via NVD
CVE-2026-81997Medium· 6.3
3w ago

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploita…

▾ Sunlitadobe · acrobatEPSS 0.24%via NVD
CVE-2026-81996High· 8.8
3w ago

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not req…

▾ Twilightadobe · acrobatEPSS 0.24%via NVD
CVE-2026-81994High· 8.2
3w ago

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to acces…

▾ Twilightadobe · acrobatEPSS 0.60%via NVD
CVE-2026-81993Medium· 5.5
3w ago

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requi…

▾ Sunlitadobe · acrobatEPSS 0.30%via NVD
CVE-2026-81992High· 7.8
3w ago

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a …

▾ Twilightadobe · acrobatEPSS 0.34%via NVD
CVE-2026-81990High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-81989High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-81988High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-81987High· 7.8
3w ago

Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op…

▾ Twilightadobe · acrobatEPSS 0.31%via NVD
CVE-2026-81986High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-81985High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-81984Medium· 5.5
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user int…

▾ Sunlitadobe · acrobatEPSS 0.33%via NVD
CVE-2026-81983High· 7.8
3w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81982Medium· 5.5
3w ago

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires use…

▾ Sunlitadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81981High· 7.8
3w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81980High· 7.8
3w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVEs tagged “nvd” — page 393 · VulnSea