VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25167 CVEsRSS

CVE-2026-57175Medium· 6.4
4d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted SAML responses on the Assertion Consumer Service endpoint without verifying that they matched a previously issued `Au…

▾ Sunlitpython-social-auth · social-coreEPSS 0.23%via NVD
CVE-2026-95985High· 8.8
4d ago

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context

The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspac…

▾ TwilightAmazon · Kiro IDEEPSS 0.14%via NVD
CVE-2026-57178High· 7.4
4d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accepted VK application callback data without verifying the callback signature when the `auth_key` parameter was omitted. …

▾ Twilightpython-social-auth · social-coreEPSS 0.16%via NVD
CVE-2026-57176Medium· 6.8
4d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend used only the numeric Vend user_id as the social-auth UID. When multiple Vend shops authenticate through the same appli…

▾ Sunlitpython-social-auth · social-coreEPSS 0.22%via NVD
CVE-2026-91120Medium· 5.4
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlled video titles in lazy video embeds could be reparsed as HTML when Discourse generated notification emails or chat su…

▾ Sunlitdiscourse · discourseEPSS 0.20%via NVD
CVE-2026-85057High· 8.7
4d ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables the goja Node-compatible require() registry without restricting its filesystem source loader. An organization Action a…

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.39%via NVD
CVE-2026-57177Medium· 4.3
4d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend did not validate OAuth state during the authentication flow. Applications using this backend were vulnerable to login C…

▾ Sunlitpython-social-auth · social-coreEPSS 0.11%via NVD
CVE-2026-85056High· 8.2
4d ago

ZITADEL is an open source identity management platform

ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser session after password verification and can reuse that session for a later authentication request without verifying a use…

▾ Twilightzitadel · github.com/zitadel/zitadelEPSS 0.29%via NVD
CVE-2026-61782High· 7.5
4d ago

Rsdoctor is a build analyzer tailored for projects built with Rspack

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /a…

▾ Twilightweb-infra-dev · rsdoctorEPSS 0.36%via NVD
CVE-2026-61784Medium· 6.1
4d ago

xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML

xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Versions prior to 0.4.3 do not HTML-entity-encode attribute values when serializing its sanitized output. In attributeS…

▾ Sunlitxhtml-purifier · xhtml-purifierEPSS 0.17%via NVD
CVE-2026-57179Medium· 4.2
4d ago

Python Social Auth is a social authentication/registration mechanism

Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resume mechanism accepted `partial_token` as a bearer credential without binding it to the browser session that created it…

▾ Sunlitpython-social-auth · social-coreEPSS 0.16%via NVD
CVE-2026-97232Medium· 6.3PoC
4d ago

A vulnerability was determined in volotat Anagnorisis up to 0.4.2

A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_file_content/save_file_content/move_files/start_streaming of the file page.html. This manipulation causes path traversa…

▾ Twilightvolotat · AnagnorisisEPSS 0.34%via NVD
CVE-2026-91121Medium· 5.0
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlled upload filenames used in chat message excerpts were rendered as unescaped HTML. A user able to upload a file and se…

▾ Sunlitdiscourse · discourseEPSS 0.26%via NVD
CVE-2026-61788High· 7.4
4d ago

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, setting `readonly = true` on the `execute_sql` tool does not make the connection read-only. The connectors are written to s…

▾ Twilightbytebase · dbhubEPSS 0.30%via NVD
CVE-2026-63645High· 7.5
4d ago

OpenObserve is a cloud-native observability platform

OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoint without authentication and serializes the complete server configuration after applying the hide_sensitive_fields ke…

▾ Twilightopenobserve · openobserveEPSS 0.33%via NVD
CVE-2026-61742Critical· 9.3PoC
4d ago

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite

DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose an unauthenticated HTTP MCP endpoint when started with the documented HTTP transport mode, for example `--transport …

▾ Abyssalbytebase · dbhubEPSS 0.20%via NVD
CVE-2026-54461Medium· 6.5
4d ago

Habitica is a habit tracker application that treats goals like a role-playing game

Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query parameter on Habitica's /api/v3/groups/:groupId/members route is not sanitized before being interpreted as a regular e…

▾ SunlitHabitRPG · habiticaEPSS 0.29%via NVD
CVE-2026-97233Low· 3.5
4d ago

A vulnerability was identified in volotat Anagnorisis up to 0.4.11

A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the file PlaylistManager.js of the component Media Filename Handler. Such manipulation of the argument file_path leads to …

▾ Sunlitvolotat · AnagnorisisEPSS 0.19%via NVD
CVE-2026-61732Critical· 10.0PoC
4d ago

Decepticon is an autonomous hacking agent for red teams

Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of agent reconnaissance against target services — into LLM messages without neutralizing ChatML special-token literals.…

▾ Abyssaldecepticon-core · decepticon-coreEPSS 1.2%via NVD
CVE-2026-94604None
4d ago

Rejected reason: This CVE is a duplicate of another CVE.

Rejected reason: This CVE is a duplicate of another CVE.

▾ Sunlitvia NVD
CVE-2026-91161Medium· 6.4
4d ago

OpenWA is a free, open source, self-hosted WhatsApp API gateway

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/groups/{groupId}/invite-code endpoint and the GroupGetInviteCode MCP tool have no OPERATOR role requirement, allowing a v…

▾ Sunlitrmyndharis · OpenWAEPSS 0.18%via NVD
CVE-2026-91134Medium· 5.4
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post sanitizer allowed a stored cross-origin iframe to bypass the allowed_iframes prefix policy when the iframe src conta…

▾ Sunlitdiscourse · discourseEPSS 0.22%via NVD
CVE-2026-91133Medium· 6.5
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated users could supply unescaped SQL LIKE metacharacters to upload-resolution patterns, causing wildcard input to select unre…

▾ Sunlitdiscourse · discourseEPSS 0.29%via NVD
CVE-2026-91132Medium· 4.3
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildcard patterns in the allowed_iframes setting could accept a crafted iframe URL whose allowlisted suffix appeared after …

▾ Sunlitdiscourse · discourseEPSS 0.14%via NVD
CVE-2026-91123High· 7.2
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded dot segments. A crafted source could …

▾ Twilightdiscourse · discourseEPSS 0.29%via NVD
CVE-2026-91122High· 8.7
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placeholder component allowed crafted HTML to cause an attribute breakout and inject an attacker-controlled event handler. An…

▾ Twilightdiscourse · discourseEPSS 0.26%via NVD
CVE-2026-84302Medium· 4.2
4d ago

Discourse is an open-source discussion platform

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI reviewables associated with private messages could appear in the moderator review queue of a moderator who was not a parti…

▾ Sunlitdiscourse · discourseEPSS 0.24%via NVD
CVE-2026-56744High· 8.7
4d ago

`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet stor…

`@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@bsv/wallet-toolbox-mobile` provide client-focused distributions for standard and mobile applications using wallet stor…

▾ Twilightbsv-blockchain · @bsv/wallet-toolboxEPSS 0.30%via NVD
CVE-2026-26054Medium· 6.8
4d ago

SumatraPDF is a multi-format reader for Windows

SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a decoder sized for kMobiHeaderLen without …

▾ Sunlitsumatrapdfreader · sumatrapdfEPSS 0.14%via NVD
CVE-2026-79766Critical· 9.1
4d ago

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1 until 2.5.1, an authenticated Termix administrator can store attacker-controlled domain and email values through PAT…

▾ MidnightTermix-SSH · TermixEPSS 0.39%via NVD
CVEs tagged “nvd” — page 41 · VulnSea