VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25179 CVEsRSS

CVE-2026-93545Medium· 6.5
4d ago

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88385High· 7.5
4d ago

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing

Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted XML input can cause text nodes allocated by mxmlNewText() to become unlinked before a parse error transfers control t…

▾ TwilightRed HatEPSS 0.15%via NVD
CVE-2026-88378None
4d ago

QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().

QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag().

▾ SunlitEPSS 0.17%via NVD
CVE-2026-94281Medium· 6.5
4d ago

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X servers to crash an attached X client.

▾ Sunlitx.org · libXiEPSS 0.20%via NVD
CVE-2026-88384Medium· 5.5PoC
4d ago

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.19%via NVD
CVE-2026-91160High· 8.2
4d ago

OpenWA is a free, open source, self-hosted WhatsApp API gateway

OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers the session.qr event to a VIEWER API key that subscribes by event name or through either wildcard subscription form,…

▾ Twilightrmyndharis · OpenWAEPSS 0.25%via NVD
CVE-2026-56738High· 8.5
4d ago

phpMyFAQ is an open source FAQ web application

phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `INSERT` statement using `sprintf()` and inserts the user-supplied stop word value directly into the query string withou…

▾ Twilightthorsten · phpMyFAQEPSS 0.26%via NVD
CVE-2026-88373High· 7.5PoC
4d ago

libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path

libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequentl…

▾ MidnightEPSS 0.34%via NVD
CVE-2026-63498High· 8.7
4d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_type}/{id}/files/{file_id} allows an authenticated user with file-management access to upload XML and XSLT attachments…

▾ Twilightgrokability · snipe-itEPSS 0.24%via NVD
CVE-2026-88377None
4d ago

Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers

Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Cr…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-88376High· 7.5PoC
4d ago

Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create()

Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A specially crafted MP4 file containing an avcC or hvcC atom with a declared size smaller than the atom header size can caus…

▾ MidnightEPSS 0.39%via NVD
CVE-2026-88390High· 7.7PoC
4d ago

An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASS…

An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted JavaScript input containing an overlong token to trigger a one-byte write beyond the JsLex.token buffer in RELEASE/NO_ASS…

▾ MidnightEPSS 0.17%via NVD
CVE-2026-88383Medium· 6.5
4d ago

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind()

libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data containing a parameterized property, the function passes icalparameter_compare_kind_map() to bsearch() through an inco…

▾ SunlitRed Hat · Red Hat Enterprise Linux 7EPSS 0.17%via NVD
CVE-2026-88382High· 7.5PoC
4d ago

hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.

hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate parser.

▾ MidnightEPSS 0.39%via NVD
CVE-2026-97231High· 7.3
4d ago

A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0

A vulnerability was found in volotat Anagnorisis up to 0.3.1/0.4.0. Affected is an unknown function of the file app.py of the component Socket.IO Connect Interface. The manipulation results in missing authentication. It is possible to la…

▾ Twilightvolotat · AnagnorisisEPSS 0.38%via NVD
CVE-2026-62368High· 8.1PoC
4d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can store markup in CustomField.name, and app/Presenters/AssetPresenter.php assigns that value as an unescaped bootstrap-ta…

▾ Midnightsnipe · snipe/snipe-itEPSS 0.30%via NVD
CVE-2026-97226Medium· 6.3
4d ago

A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1

A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the file packages/api/src/controllers/files.js of the component files-style Endpoint. The manipulation of the argument fi…

▾ SunlitEPSS 0.34%via NVD
CVE-2026-63493High· 8.6
4d ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with self.api permission can reach the personal-access-token API flow before completing the account's second-factor challe…

▾ Twilightsnipe · snipe/snipe-itEPSS 0.27%via NVD
CVE-2026-96750High· 7.1
4d ago

MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view

MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell when a user opens the shell from that database's view. A user with privileges to create databases on a server that a Co…

▾ TwilightMongoDB · CompassEPSS 0.19%via NVD
CVE-2026-96746Medium· 6.5
4d ago

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who controls name resolution and the responses of the hosts named in a client's connection string to write beyond the en…

▾ SunlitMongoDB · C DriverEPSS 0.37%via NVD
CVE-2026-96745Medium· 5.6
4d ago

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects

Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embedded in document content to be honored when the driver builds monitoring event objects. When an application registers…

▾ SunlitMongoDB · PHP DriverEPSS 0.30%via NVD
CVE-2026-96744High· 7.1
4d ago

Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than…

Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integration for Laravel can cause a caller-supplied lock owner value to be evaluated as an aggregation expression rather than…

▾ TwilightMongoDB · Laravel MongoDB (PHP)EPSS 0.29%via NVD
CVE-2026-93541Medium· 6.5
4d ago

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a

▾ SunlitX.org · libXiEPSS 0.24%via NVD
CVE-2026-93425Critical· 9.9PoC
4d ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC procedure passes the user-controlled repoPath value from apps/dokploy/server/api/routers/patch.ts into a shell command in…

▾ AbyssalDokploy · dokployEPSS 0.62%via NVD
CVE-2026-93283None
4d ago

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to drop the reference taken by…

In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When device_register() fails in i3c_master_register_new_i3c_devs(), put_device() is called to drop the reference taken by…

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-93282High· 8.1
4d ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL permission check looks for an ACE matching the current user and falls back to the Everyone ACE. It does not consider …

▾ TwilightLinux · LinuxEPSS 0.31%via NVD
CVE-2026-93281None
4d ago

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads extended capability byte 10, but rejects only datalen values bel…

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length check rtw89_mac_check_he_obss_narrow_bw_ru_iter() reads extended capability byte 10, but rejects only datalen values bel…

▾ SunlitLinux · LinuxEPSS 0.19%via NVD
CVE-2026-93280High· 8.8
4d ago

In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() fetches a topology blob of a module-supplied size, and gbaudio_tpl…

In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes against the fetched size gb_audio_gb_get_topology() fetches a topology blob of a module-supplied size, and gbaudio_tpl…

▾ TwilightLinux · LinuxEPSS 0.32%via NVD
CVE-2026-93279None
4d ago

In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet can be scheduled by the watchdog IRQ handler to execute cvm_oct_tx_do_cleanup

In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown The TX cleanup tasklet can be scheduled by the watchdog IRQ handler to execute cvm_oct_tx_do_cleanup. …

▾ SunlitLinux · LinuxEPSS 0.20%via NVD
CVE-2026-93278None
4d ago

In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first

In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oct_rx_shutdown cvm_oct_rx_shutdown calls free_irq and netif_napi_del without disabling the napi instance first. As th…

▾ SunlitLinux · LinuxEPSS 0.19%via NVD
CVEs tagged “nvd” — page 48 · VulnSea