VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

32038 CVEsRSS

CVE-2024-58382High· 7.5
4w ago

league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service

league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger wo…

▾ Twilightthephpleague · commonmarkEPSS 0.28%via NVD
CVE-2026-86203Low· 3.7
4w ago

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causin…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.35%via NVD
CVE-2026-87928Medium· 5.4
4w ago

MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files

MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uplo…

▾ SunlitMaxSite · MaxSite CMSEPSS 0.30%via NVD
CVE-2026-80915None
4w ago

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix DPT allocation paths. Remove the fallback for VRAM to system memory, I tested it and that doesn't work at all, only a black screen with pipe fault errors w…

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix DPT allocation paths. Remove the fallback for VRAM to system memory, I tested it and that doesn't work at all, only a black screen with pipe fault errors w…

▾ SunlitLinux · LinuxEPSS 0.21%via NVD
CVE-2026-86774Medium· 6.3
4w ago

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset …

Snipe-IT versions before 8.7.0 contain a broken access control vulnerability in AssetModelPolicy where the files() method cascades from assets.files permission, allowing authenticated users to upload and delete file attachments on Asset …

▾ Sunlitsnipeitapp · snipe-itEPSS 0.29%via NVD
CVE-2026-79952Medium· 5.3
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Encoding or Escaping of Output vulnerability. An unauthenticated attacker with remote access could potent…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.34%via NVD
CVE-2026-80169Low· 3.3
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could …

▾ Sunlitdell · secure_connect_gatewayEPSS 0.14%via NVD
CVE-2026-87806High· 7.4
4w ago

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter

Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain an authentication bypass in the built-in LDAP authentication adapter. The adapter forwarded the client-supplied password to the directory without verifying that a pass…

▾ Twilightparse-community · parse-serverEPSS 0.51%via NVD
CVE-2026-86776Low· 3.3PoC
4w ago

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function

KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeaderField function. Attackers can craft a malicious KDBX file declaring excessive header field lengths to trigger allocat…

▾ TwilightKeePass · KeePassEPSS 0.17%via NVD
CVE-2026-87824High· 7.5
4w ago

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory…

▾ Twilightluben · zstd-jniEPSS 0.39%via NVD
CVE-2026-21111Medium· 6.9
4w ago

Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.

Out-of-bounds write in libsthmbc.so prior to One UI 8.5 allows local attackers to write out-of-bounds memory.

▾ SunlitSamsung Mobile · libsthmbcEPSS 0.10%via NVD
CVE-2026-78490High· 7.5
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote a…

▾ Twilightdell · secure_connect_gatewayEPSS 0.50%via NVD
CVE-2026-87930High· 8.1PoC
4w ago

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects

MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to…

▾ MidnightMaxSite · MaxSite CMSEPSS 0.61%via NVD
CVE-2026-87021High· 7.2
4w ago

Tanium addressed an unauthorized code execution vulnerability in Comply.

Tanium addressed an unauthorized code execution vulnerability in Comply.

▾ Twilighttanium · complyEPSS 0.66%via NVD
CVE-2026-21109Low· 2.1
4w ago

Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.

Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information.

▾ SunlitSamsung Mobile · Watch PluginEPSS 0.10%via NVD
CVE-2026-86752Medium· 5.4
4w ago

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks

snipe-it versions before 8.7.0 fail to enforce per-instance FMCS scoping in asset audit endpoints, relying solely on query-layer filtering instead of policy-layer authorization checks. Attackers with valid sessions and assets.audit permi…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.25%via NVD
CVE-2026-87874High· 8.1
4w ago

A flaw was found in the memcached cache plugin of the community.general Ansible collection

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memc…

▾ TwilightRed Hat · ansible-collection-community-generalEPSS 0.72%via NVD
CVE-2026-86762High· 8.1
4w ago

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens

Snipe-IT before 8.7.0 does not apply the CheckUserIsActivated middleware to the `api` middleware group in app/Http/Kernel.php, and deactivating a user does not revoke that user's Passport personal access tokens. As a result, although a d…

▾ Twilightsnipeitapp · snipe-itEPSS 0.47%via NVD
CVE-2026-86764Medium· 6.5
4w ago

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components

Snipe-IT through 8.6.4 (fixed in 8.7.0) does not enforce the components.view permission on the authenticated endpoint GET /api/v1/hardware/<asset-id>/assigned/components. The endpoint authorizes only assets.view on the parent asset befor…

▾ Sunlitsnipeitapp · snipe-itEPSS 0.37%via NVD
CVE-2026-79964Medium· 5.3
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Escape, Meta, or Control Sequences vulnerability. An unauthenticated attacker with remo…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.34%via NVD
CVE-2026-87927High· 8.2PoC
4w ago

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequ…

MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequ…

▾ MidnightMaxSite · MaxSite CMSEPSS 0.59%via NVD
CVE-2026-76009High· 8.1
4w ago

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function

The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 3.9.8 via the `NCWM_Kitconnect::run()` function. This is due to the plugin registering the `/w…

▾ Twilightmartinnguyen1990 · Next-Cart Store to WooCommerce MigrationEPSS 0.90%via NVD
CVE-2026-85978Critical· 9.8
4w ago

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform

An unauthenticated remote code execution vulnerability exists in the Policy Manager console of Akana API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to …

▾ MidnightPerforce · AkanaEPSS 1.4%via NVD
CVE-2026-79727Low· 3.3
4w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A low privileged attack…

▾ Sunlitdell · secure_connect_gatewayEPSS 0.14%via NVD
CVE-2025-71418Medium· 5.3
4w ago

PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources

PocketMine-MP versions before 5.25.2 fail to limit the explode() function in packet parsing, allowing malicious clients to waste server resources. Attackers can send crafted packets with excessive delimiters to consume CPU and memory thr…

▾ Sunlitpmmp · PocketMine-MPEPSS 0.40%via NVD
CVE-2026-86777Medium· 5.3PoC
4w ago

AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes

AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authorize access to the GET /api/nodes endpoint, allowing unauthenticated attackers to retrieve all navigation nodes. Attackers can access the endpoint without authentication…

▾ TwilightAlchemyCMS · alchemy_cmsEPSS 0.56%via NVD
CVE-2026-87766High· 8.8
4w ago

A flaw was found in bubblewrap

A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This …

▾ TwilightRed Hat · bubblewrapEPSS 0.15%via NVD
CVE-2026-87827Critical· 10.0
4w ago

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication

Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without requiring authentication. A remote unauthenticated attacker with network access to the affected service ca…

▾ MidnightKGUARD · KGUARD_firmwareEPSS 1.1%via NVD
CVE-2026-86547Medium· 6.2PoC
4w ago

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode

mrubyc through 4.0.0 contains a null pointer dereference vulnerability in the op_enter() handler in src/vm.c when processing untrusted bytecode. Attackers can craft malicious .mrb bytecode files with OP_ENTER instructions at the top leve…

▾ Twilightmrubyc · mrubycEPSS 0.18%via NVD
CVE-2026-61907Medium· 4.3
4w ago

An issue was discovered in Cyrus IMAP before 3.12.4

An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or…

▾ Sunlitcyrusimap · Cyrus IMAPEPSS 0.21%via NVD
CVEs tagged “nvd” — page 428 · VulnSea