VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25204 CVEsRSS

CVE-2026-78312Critical· 9.1
4d ago

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Path Traversal in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ MidnightDeltaww · DIAEnergieEPSS 0.34%via NVD
CVE-2026-78311High· 8.8
4d ago

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ TwilightDeltaww · DIAEnergieEPSS 0.24%via NVD
CVE-2026-78310Medium· 4.3
4d ago

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

Authorization Bypass Through User-Controlled Key in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ SunlitDeltaww · DIAEnergieEPSS 0.21%via NVD
CVE-2026-78309High· 8.8
4d ago

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022.

▾ TwilightDeltaww · DIAEnergieEPSS 0.24%via NVD
CVE-2026-78308Critical· 9.8
4d ago

Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.

Improper Authentication vulnerability in DIAEnergie allows Authentication Bypass. This issue affects DIAEnergie: before 1.11.00.022.

▾ MidnightDeltaww · DIAEnergieEPSS 0.35%via NVD
CVE-2026-77193High· 7.5
4d ago

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter

The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.0.3 via the `id2wp_path` parameter. This makes it possible for unauthenticated attackers to read the con…

▾ Twilighteesywp · eesy_ID2WP – Publish InDesign HTML5EPSS 0.36%via NVD
CVE-2026-97181Medium· 5.3
4d ago

GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability

GPM LIGHT developed by ezGlobal has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can directly access system logs.

▾ SunlitezGlobal · GPM LIGHTEPSS 0.26%via NVD
CVE-2026-87739Medium· 6.9
4d ago

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation

An improper authentication vulnerability in PaperCut MF/NG allows an unauthenticated, remote attacker to trigger report generation. By submitting report generation requests without valid credentials, an attacker can generate reports and …

▾ SunlitPaperCut · PaperCut NG/MFEPSS 0.38%via NVD
CVE-2026-82077High· 7.3
4d ago

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlyi…

An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax component of PaperCut NG and PaperCut MF allows an authenticated administrator to execute arbitrary commands on the underlyi…

▾ TwilightPaperCut · PaperCut NG/MFEPSS 0.74%via NVD
CVE-2026-81645Medium· 5.9
4d ago

Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.

Out-of-bounds read vulnerability in the graphics module. Successful exploitation of this vulnerability may affect availability.

▾ SunlitHuawei · HarmonyOSEPSS 0.09%via NVD
CVE-2026-11744Low· 3.8
4d ago

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices

An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card reading process before passing it to the application's we…

▾ SunlitPaperCut · PaperCut HiveEPSS 0.17%via NVD
CVE-2026-97177Medium· 6.6
4d ago

A flaw was found in the user update mechanism of the Keycloak Admin REST API

A flaw was found in the user update mechanism of the Keycloak Admin REST API. When Fine-Grained Admin Permissions are enabled, the system fails to check for specific password reset authorizations during a general user profile update. Thi…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.24%via NVD
CVE-2026-97176Medium· 4.2
4d ago

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution

A flaw was found in the Level of Authentication enforcement mechanism of Keycloak, an identity and access management solution. The issue occurs when a client specifically requires a higher security level for a user who already has an act…

▾ SunlitRed Hat · keycloak-servicesEPSS 0.17%via NVD
CVE-2026-97168None
4d ago

Rejected reason: it is a suggestion

Rejected reason: it is a suggestion

▾ Sunlitvia NVD
CVE-2026-93662Medium· 4.3
4d ago

The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending o…

The Events Manager WordPress plugin before 7.4.5 does not force the scope of its logged-in event and location search when a caller supplies their own owner value, letting a low-privileged user read other accounts' unpublished, pending o…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-93661Low· 2.7
4d ago

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any …

The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers of the ticket it was authorized against, letting a user who can manage one event's tickets overwrite and reassign any …

▾ SunlitEPSS 0.17%via NVD
CVE-2026-89005Medium· 6.8
4d ago

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stor…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitise and escape one of its campaign configuration fields when a certain feature is enabled, which allows users with the Contributor role and above to perform Stor…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-89004Low· 2.7
4d ago

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the c…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returning a campaign's stored configuration and run log, allowing users with contributor-level access and above to read the c…

▾ SunlitEPSS 0.22%via NVD
CVE-2026-89002Medium· 6.8
4d ago

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Sc…

The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not sanitize and escape content it retrieves from a user-supplied source before rendering it, which could allow users such as contributors to perform Stored Cross-Site Sc…

▾ SunlitEPSS 0.24%via NVD
CVE-2026-88847Medium· 4.3
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create cou…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not verify that a user is enrolled in a course before recording lesson completions against it, allowing any authenticated user, such as a subscriber, to create cou…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-88846Medium· 5.3
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated use…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not check whether user registration is enabled on the site before creating an account through one of its front-end registration flows, allowing unauthenticated use…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-88845Medium· 4.3
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any capability or nonce checks on an administrative maintenance action, allowing any authenticated user, such as a subscriber, to trigger it and create…

▾ SunlitEPSS 0.15%via NVD
CVE-2026-88843High· 7.2
4d ago

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute …

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings before using it to build a template path, allowing users with the Contributor role and above to include and execute …

▾ TwilightEPSS 0.36%via NVD
CVE-2026-84151Low· 3.5
4d ago

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input e…

The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own markup and applies it site-wide, allowing users with the Contributor role and above to store iframe, style and input e…

▾ SunlitEPSS 0.14%via NVD
CVE-2026-82850Medium· 4.3
4d ago

The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses the…

The Masteriyo LMS WordPress plugin before 3.4.2 does not restrict access to quiz answer keys, allowing any authenticated user, such as a student, to retrieve the correct answers for any quiz on the site, including quizzes in courses the…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-82849Medium· 4.3
4d ago

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another use…

The Masteriyo LMS WordPress plugin before 3.4.2 does not verify that the user making the request owns the course-progress records being returned, allowing any authenticated user, such as a self-registered subscriber, to read another use…

▾ SunlitEPSS 0.16%via NVD
CVE-2026-82195Medium· 6.5
4d ago

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete …

The 10Web Booster WordPress plugin before 2.34.0 does not restrict access to the routine which issues the shared secret that authenticates its cloud connection, disclosing that secret to unauthenticated visitors and letting them delete …

▾ SunlitEPSS 0.23%via NVD
CVE-2026-80513High· 7.5
4d ago

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a …

The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes a user-supplied profile field value, allowing authenticated users with Subscriber-level access and above to inject a …

▾ TwilightEPSS 0.31%via NVD
CVE-2026-80338Medium· 6.8
4d ago

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break co…

▾ SunlitEPSS 0.18%via NVD
CVE-2026-74991Medium· 6.8
4d ago

The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate …

The WPForms WordPress plugin before 2.0.2 does not verify that a Stripe payment object supplied during a public form submission belongs to it before acting on it, allowing unauthenticated users to trigger a full refund and an immediate …

▾ SunlitEPSS 0.18%via NVD
CVEs tagged “nvd” — page 56 · VulnSea