VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

30179 CVEsRSS

CVE-2026-79721High· 8.6
3w ago

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

Code execution can occur in versions of the MLflow platform running version 0.0.1 or newer, enabling a maliciously crafted model artifact to execute arbitrary code on an end user's system when loaded by the project.

▾ Twilightmlflow · mlflowEPSS 0.47%via NVD
CVE-2026-77109High· 8.6
3w ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue d…

▾ Twilightadobe · commerceEPSS 0.69%via NVD
CVE-2026-76202High· 8.2
3w ago

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue …

▾ Twilightadobe · commerceEPSS 0.67%via NVD
CVE-2026-66306Medium· 6.5
3w ago

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.

▾ Sunlitmicrosoft · skype_for_business_serverEPSS 0.92%via NVD
CVE-2026-28656High· 7.3
3w ago

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack

In multiple functions of DeviceAdminAdd.java, there is a possible way to an overlay due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …

▾ Twilightgoogle · androidEPSS 0.09%via NVD
CVE-2026-9216Low· 3.5
3w ago

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI

An insufficient input validation vulnerability in the listed NETGEAR RAX series models allows a network-adjacent attacker having network access (such as WiFi credentials) to crash the router's management UI. There is no confidentiality o…

▾ Sunlitnetgear · rax30_firmwareEPSS 0.36%via NVD
CVE-2026-9215Medium· 6.7
3w ago

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations …

A cross site request forgery (CSRF) vulnerability in the listed NETGEAR models allows an attacker who can leverage social engineering techniques on a router administrator to tamper with router configuration and disrupt router operations …

▾ Sunlitnetgear · xr1000_firmwareEPSS 0.19%via NVD
CVE-2026-86673High· 7.3PoC
3w ago

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connec…

▾ Midnightningzichun · Student Management SystemEPSS 0.47%via NVD
CVE-2026-86672Medium· 5.3PoC
3w ago

A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf

A vulnerability has been found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected is an unknown function of the file example.7z of the component Backup Handler. The manipulation leads to info…

▾ Twilightningzichun · Student Management SystemEPSS 0.48%via NVD
CVE-2026-86670Low· 3.7PoC
3w ago

A flaw has been found in aircheng-org iWebShop-5 up to 5.15

A flaw has been found in aircheng-org iWebShop-5 up to 5.15. This impacts an unknown function of the file controllers/admin.php of the component Authentication Storage. Executing a manipulation of the argument Password can lead to passwo…

▾ Twilightaircheng-org · iWebShop-5EPSS 0.38%via NVD
CVE-2026-86669High· 7.3PoC
3w ago

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15

A vulnerability was detected in aircheng-org iWebShop-5 up to 5.15. This affects the function Login of the file controllers/systemseller.php. Performing a manipulation of the argument Name results in improper authentication. It is possib…

▾ Midnightaircheng-org · iWebShop-5EPSS 0.69%via NVD
CVE-2026-86074High· 7.1
3w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI credential setup flow accepted a credential test or verification URL without checking that it matched the workflow node's origin. Attacker-co…

▾ Twilightn8n · n8nEPSS 0.38%via NVD
CVE-2026-85880High· 7.8CISA KEV0dayPoC
3w ago

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

▾ Abyssalmicrosoft · windows_10_1607EPSS 3.6%via NVD
CVE-2026-85877High· 8.8
3w ago

Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.82%via NVD
CVE-2026-85875Medium· 5.5
3w ago

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

▾ Sunlitmicrosoft · 365_appsEPSS 0.54%via NVD
CVE-2026-85360High· 7.0
3w ago

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.26%via NVD
CVE-2026-84003High· 7.4
3w ago

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

Authentication bypass by capture-replay in Microsoft Authentication Library (MSAL) for Node.js allows an unauthorized attacker to perform spoofing over a network.

▾ Twilightmicrosoft · azure/msal-nodeEPSS 0.60%via NVD
CVE-2026-84001High· 7.5
3w ago

Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.

Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-84000High· 7.8
3w ago

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to execute code locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-83999High· 7.0
3w ago

Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.

Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_24h2EPSS 0.28%via NVD
CVE-2026-83998High· 8.8
3w ago

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-83997High· 8.1
3w ago

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_21h2EPSS 0.71%via NVD
CVE-2026-83996High· 8.8
3w ago

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Error Reporting allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-83995High· 7.8
3w ago

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-83992High· 8.8
3w ago

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.82%via NVD
CVE-2026-83991Medium· 5.5PoC
3w ago

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

Missing authentication for critical function in Windows Cloud Files Mini Filter Driver allows an authorized attacker to perform tampering locally.

▾ Twilightmicrosoft · windows_10_1809EPSS 0.30%via NVD
CVE-2026-83990High· 7.8
3w ago

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

Stack-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_11_23h2EPSS 0.33%via NVD
CVE-2026-83989High· 7.5
3w ago

Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.

Out-of-bounds read in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to deny service over a network.

▾ Twilightmicrosoft · windows_10_1607EPSS 1.2%via NVD
CVE-2026-83988High· 7.8
3w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVE-2026-83987High· 7.8
3w ago

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

▾ Twilightmicrosoft · windows_10_1607EPSS 0.33%via NVD
CVEs tagged “nvd” — page 404 · VulnSea