VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30161 CVEsRSS

CVE-2026-81979High· 7.8
3w ago

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malici…

▾ Twilightadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81978Medium· 5.5
3w ago

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires use…

▾ Sunlitadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81977Medium· 5.5
3w ago

Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of thi…

▾ Sunlitadobe · acrobatEPSS 0.26%via NVD
CVE-2026-81976High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-81973High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-80162Medium· 5.5
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user int…

▾ Sunlitadobe · acrobatEPSS 0.33%via NVD
CVE-2026-80161High· 7.8
3w ago

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability t…

▾ Twilightadobe · acrobatEPSS 0.29%via NVD
CVE-2026-80160Medium· 5.5
3w ago

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires use…

▾ Sunlitadobe · acrobatEPSS 0.26%via NVD
CVE-2026-80159Medium· 4.0
3w ago

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions bey…

▾ Sunlitadobe · acrobatEPSS 0.19%via NVD
CVE-2026-79910Medium· 5.5
3w ago

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires use…

▾ Sunlitadobe · acrobatEPSS 0.26%via NVD
CVE-2026-79909High· 7.8
3w ago

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.38%via NVD
CVE-2026-79907High· 7.8
3w ago

Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user

Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

▾ Twilightadobe · acrobatEPSS 0.29%via NVD
CVE-2026-79588Medium· 4.3PoC
3w ago

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

▾ TwilightEPSS 0.15%via NVD
CVE-2026-81991Medium· 5.5
3w ago

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires use…

▾ Sunlitadobe · acrobatEPSS 0.26%via NVD
CVE-2026-78971Medium· 4.6PoC
3w ago

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

▾ TwilightEPSS 0.24%via NVD
CVE-2026-78742Medium· 6.1PoC
3w ago

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-78741Medium· 6.1PoC
3w ago

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-78738Medium· 6.1PoC
3w ago

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-86810High· 7.3
3w ago

A vulnerability was detected in Open-Web-Analytics up to 1.9.1

A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in imp…

▾ TwilightEPSS 0.84%via NVD
CVE-2026-85630Medium· 6.1
3w ago

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.24%via NVD
CVE-2026-85485Medium· 6.1⚖ disputed
3w ago

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-85484Medium· 6.1
3w ago

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.33%via NVD
CVE-2026-84197Critical· 9.2
3w ago

In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, th…

In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, th…

▾ MidnightEclipse Foundation · @eclipse-ditto/ditto-javascript-client-nodeEPSS 0.34%via NVD
CVE-2026-78834High· 8.8
3w ago

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin

A code execution vulnerability exists in CMSimple 5.22 in the CoAuthors plugin. An authenticated low-privileged user who can modify page content and provide controlled imported content can trigger server-side execution by referencing cra…

▾ TwilightEPSS 0.67%via NVD
CVE-2026-78627High· 7.3
3w ago

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property

The Okta Hyperdrive Integration installer does not mask the OAuth client secret when passed as an MSI property. The credential is recorded in plaintext in the installer log, the Application Event Log, and the process command line, all of…

▾ Twilightokta · hyperdriveEPSS 0.14%via NVD
CVE-2026-78626High· 8.1
3w ago

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protect…

The Okta Access Gateway improperly handles input sanitization and regular expression evaluation within its Protected Rule authorization check, resulting in an authorization bypass when an administrator has explicitly configured a Protect…

▾ Twilightokta · access_gatewayEPSS 0.36%via NVD
CVE-2026-78625Medium· 6.7
3w ago

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files

The Okta Access Gateway does not sanitize dashboard label values before writing them into generated PHP configuration files. The generated file is automatically included during authentication requests, resulting in execution with the pri…

▾ Sunlitokta · access_gatewayEPSS 0.23%via NVD
CVE-2026-78624Medium· 4.9
3w ago

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload

The Okta Access Gateway backup restore function does not validate the filename embedded in an encrypted backup payload. This results in writing file contents to unintended locations on the appliance filesystem.

▾ Sunlitokta · access_gatewayEPSS 0.46%via NVD
CVE-2026-78623High· 7.7
3w ago

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration

The Okta Access Gateway does not sanitize SAML assertion values before interpolating them into database queries in the advanced mode datastore configuration. The unsanitized values are substituted directly into the query string prior to …

▾ Twilightokta · access_gatewayEPSS 0.45%via NVD
CVE-2026-78620Medium· 5.9
3w ago

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents

The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in event payloads before writing file contents. The path from the event payload is used directly as the write destination, resulting in files b…

▾ Sunlitokta · access_gatewayEPSS 0.34%via NVD
CVEs tagged “nvd” — page 394 · VulnSea