VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25189 CVEsRSS

CVE-2026-12559High· 7.3
4d ago

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized scri…

▾ TwilightOpenText · Vendor Invoice Management for SAP SolutionsEPSS 0.39%via NVD
CVE-2026-97062Medium· 5.4PoC
4d ago

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript

Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with scrip…

▾ TwilightWebkul · Aureus ERPEPSS 0.22%via NVD
CVE-2026-97061Medium· 4.3
4d ago

Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instance

Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authenticated user to enumerate all playlists on the instance. Attackers can query the SearchController or Search::Playlists…

▾ Sunlitblackcandy-org · Black CandyEPSS 0.22%via NVD
CVE-2026-97059High· 8.2
4d ago

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames

DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without validating the PixelData buffer length against the declared NumberOfFrames. Attackers can craft malicious DICOM inst…

▾ TwilightOFFIS · DCMTKEPSS 0.35%via NVD
CVE-2026-97058Medium· 5.3PoC
4d ago

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision value…

▾ Twilightalexei · sprintf-jsEPSS 0.37%via NVD
CVE-2026-97057High· 7.5
4d ago

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length

redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to trigger an uncaught RangeError by supplying an excessively large declared length. A malicious or compromised Redis e…

▾ TwilightNodeRedis · redis-parserEPSS 0.39%via NVD
CVE-2026-88360Medium· 5.5
4d ago

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images

libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header length is not a multiple of four bytes, the mmap-based loader can expose pixel data at an address that is not properly…

▾ SunlitRed HatEPSS 0.14%via NVD
CVE-2026-88359Medium· 6.5PoC
4d ago

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format()

libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted YAML document containing a very large literal or folded block scalar, the function repeatedly grows an internal buffer…

▾ TwilightRed HatEPSS 0.25%via NVD
CVE-2026-77798Medium· 6.5
4d ago

Velociraptor contains a deadlock condition that may be triggered by authenticated users

Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock management bug in the user management module.

▾ SunlitRapid7 · VelociraptorEPSS 0.20%via NVD
CVE-2026-77797Low· 3.6
4d ago

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malformed prefetch files.

▾ SunlitRapid7 · VelociraptorEPSS 0.10%via NVD
CVE-2026-18857Low· 3.4
4d ago

IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface

IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a vulnerability in the BMC firmware management interface. The host system can cause the BMC firmware management service …

▾ SunlitIBM · OPENBMCEPSS 0.11%via NVD
CVE-2026-18104Low· 3.3
4d ago

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of the AES Electronic Codebook (ECB) mode for encryption.

▾ SunlitIBM · Db2 Mirror for iEPSS 0.06%via NVD
CVE-2026-17511Low· 3.4
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition resource dump interface. An attacker with authent…

▾ SunlitIBM · PowerVM HypervisorEPSS 0.13%via NVD
CVE-2026-17504Medium· 5.1
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime. An attacker with root access to…

▾ SunlitIBM · PowerVM HypervisorEPSS 0.10%via NVD
CVE-2026-17503Medium· 5.1
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the partition firmware runtime boot configuration. An attacker …

▾ SunlitIBM · PowerVM HypervisorEPSS 0.10%via NVD
CVE-2026-17413Medium· 5.1
4d ago

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface

IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 through FW950.H3 is affected by a vulnerability in the RTAS firmware-to-OS interface. An attacker with administrat…

▾ SunlitIBM · PowerVM HypervisorEPSS 0.10%via NVD
CVE-2026-91187Critical· 9.3
4d ago

Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token

Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote attacker to authenticate as an arbitrary Cloudflare service token. Applications using the Cloudflare Zero Trust authent…

▾ Midnightdashbit · nimble_ztaEPSS 0.30%via NVD
CVE-2026-97359Critical· 10.0
4d ago

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename

HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attac…

▾ Midnightrejetto · hfs2EPSS 0.78%via NVD
CVE-2026-95521High· 7.8
4d ago

A command injection flaw was found in rpm

A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames contain a %() macro construct causes rpm to execute an attacker-controlled shell command via popen() while relocating th…

▾ TwilightRed Hat · rpmEPSS 0.58%via NVD
CVE-2026-95519High· 7.8
4d ago

A flaw was found in rpm

A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation using `rpm -q -p` or similar manifest-processing flows, leads to arbitrary code execution. This occurs because manifest …

▾ TwilightRed Hat · rpmEPSS 0.14%via NVD
CVE-2026-97360Critical· 10.0PoC
4d ago

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …

HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside …

▾ Abyssalrejetto · hfs2EPSS 0.32%via NVD
CVE-2026-94416Medium· 6.8
4d ago

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not…

▾ SunlitRed Hat · ansible-automation-platform-25/gateway-rhel8EPSS 0.45%via NVD
CVE-2026-88916Medium· 6.8
4d ago

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPDF: through 09092026.

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPDF: through 09092026.

▾ SunlitTÜBİTAK ULAKBİM · UlakPDFEPSS 0.21%via NVD
CVE-2026-88907High· 7.4
4d ago

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakPDF: through 09092026.

Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakPDF: through 09092026.

▾ TwilightTÜBİTAK ULAKBİM · UlakPDFEPSS 0.32%via NVD
CVE-2026-19072Critical· 9.9
4d ago

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt

Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field "compiled_collector_args" is an internal field, Velociraptor allowed the fiel…

▾ MidnightRapid7 · VelociraptorEPSS 0.40%via NVD
CVE-2026-96515High· 8.6PoC
4d ago

This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality

This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation controls in the diagnostic script import functionality. An authenticated attacker could exploit this vulnerability by uplo…

▾ MidnightNetlink ICT Pvt Ltd · Netlink ICT HG323RW RouterEPSS 0.31%via NVD
CVE-2026-97182High· 7.3PoC
4d ago

A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1

A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file application/src/main/java/run/halo/app/content/comment/ReplyNotificationSubscriptionHelper.java of the component…

▾ Midnighthalo-dev · HaloEPSS 0.37%via NVD
CVE-2026-19532Medium· 5.3
4d ago

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS allows Path Traversal. This issue affects Liman MYS: from 2.3.2 before 2.3.4-1124.

▾ SunlitHAVELSAN Inc. · Liman MYSEPSS 0.26%via NVD
CVE-2026-7169High· 7.5
4d ago

a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’…

a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a local attacker without privileges to load a malicious DLL by placing a ‘wtsapi32.dll’ file in the ‘C:\ProgramData\Evope\’…

▾ TwilightEvope Collector · Evope CollectorEPSS 0.14%via NVD
CVE-2026-97311Medium· 4.3
4d ago

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution

A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to retrieve groups associated with a specific role do not properly check for individual group visibility permissions. This…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVEs tagged “nvd” — page 54 · VulnSea