VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25245 CVEsRSS

CVE-2026-66069Low· 2.3⚖ disputed
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_authorized_monitor for all methods. DELETE resets rabbit_core_metrics:reset_auth_attempt_metrics(). Impact is cosmetic (cou…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.40%via NVD
CVE-2026-66067Medium· 6.0
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only check_vhost_access; it omits the node/vhost/user connection-limit checks that rabbit_reader performs for AMQP. A develope…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.35%via NVD
CVE-2026-96556High· 7.3
5d ago

A flaw has been found in Neethuharii CafeManagement

A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authoriza…

▾ TwilightNeethuharii · CafeManagementEPSS 0.28%via NVD
CVE-2026-67224Low· 2.1⚖ disputed
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The trace consumer constructs the output path as filename:join(TraceDir, Name ++ ".log") where Name comes from PUT /api/traces/:vh…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.38%via NVD
CVE-2026-66077High· 7.3
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI uses EJS 1.0 in which <%= ... %> does NOT HTML-escape. connection.ejs:135 renders <%= connection.ssl_details.peer_cert_…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.30%via NVD
CVE-2026-67240Low· 2.3PoC⚖ disputed
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ -> ., then compiles ^...$ with only [unicode]; re:run is called with only [{capture, none}] - no explicit match_limit. …

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.26%via NVD
CVE-2026-67220Medium· 6.0
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, 4.3.0, When a binding is created on an x-jms-topic exchange, add_binding/3 reads the rjms_erlang_selector argument and passes it through erl_…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.29%via NVD
CVE-2026-66080Medium· 5.9
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only checks that the requested partition count is at least 1, with no upper bound. A large count such as lists:seq(0, 500000000…

▾ Sunlitrabbitmq · rabbitmq-serverEPSS 0.28%via NVD
CVE-2026-96889High· 7.8PoC
5d ago

A flaw was found in librsvg

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly fre…

▾ MidnightRed Hat · glycin-loadersEPSS 0.13%via NVD
CVE-2026-96826High· 7.6
5d ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection. This issue affects W4 Post List: from n/a through 3.0.6.

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Injection. This issue affects W4 Post List: from n/a through 3.0.6.

▾ TwilightShazzad Hossain Khan · w4-post-listEPSS 0.23%via NVD
CVE-2026-67404Critical· 9.2
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bundle is available, ssl_options/1 falls back to [{verify, verify_none}] with no warning. An attacker in a man-in-the-m…

▾ Midnightrabbitmq · rabbitmq-serverEPSS 0.24%via NVD
CVE-2026-96552Low· 3.1PoC
5d ago

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function MD5.getMD5 of the file ssm_pro/src/main/java/cn/sfturing/utils/MD5.java of the component User Pass…

▾ Twilightsfturing · hosp_orderEPSS 0.15%via NVD
CVE-2026-96551Medium· 4.3PoC
5d ago

A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java. Executing a manipulation c…

▾ Twilightsfturing · hosp_orderEPSS 0.16%via NVD
CVE-2026-96550Low· 3.7
5d ago

A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the function getProperties of the file ssm_pro/src/main/java/cn/sfturing/utils/MailUtil.java. Performing a manipulation r…

▾ Sunlitsfturing · hosp_orderEPSS 0.21%via NVD
CVE-2026-87900Critical· 9.4
5d ago

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.

Argument injection in WP Toolkit for cPanel 6.11.2-10794 and earlier allows remote authenticated users to read arbitrary files and execute arbitrary code across customer accounts.

▾ MidnightWebPros · WP Toolkit for cPanelEPSS 0.57%via NVD
CVE-2026-87899Critical· 9.4
5d ago

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

Execution with unnecessary privileges in cPanel allows remote authenticated users to execute arbitrary code with root privileges.

▾ MidnightWebPros · cPanelEPSS 0.53%via NVD
CVE-2026-87898Critical· 9.4
5d ago

OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.

OS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.

▾ MidnightWebPros · Plesk extension "Site Import"EPSS 0.95%via NVD
CVE-2026-85475High· 7.2
5d ago

A flaw was found in the Ansible Automation Platform automation controller

A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by interpolating user-controlled settings — LOG_AGGREGATOR_HOST, LOG_AGGREGATOR_MAX_DISK_USAGE_PATH and …

▾ TwilightRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.43%via NVD
CVE-2026-84724Medium· 6.6
5d ago

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem

An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation def…

▾ SunlitRed Hat · automation-controllerEPSS 0.29%via NVD
CVE-2026-84721Medium· 6.4
5d ago

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend

A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the …

▾ SunlitRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.17%via NVD
CVE-2026-84720Medium· 6.5
5d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in preve…

▾ SunlitRed Hat · automation-controllerEPSS 0.27%via NVD
CVE-2026-84719Critical· 9.9
5d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node a…

▾ MidnightRed Hat · automation-controllerEPSS 0.43%via NVD
CVE-2026-84718Medium· 4.3
5d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it ori…

▾ SunlitRed Hat · automation-controllerEPSS 0.14%via NVD
CVE-2026-84717Medium· 5.3
5d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target…

▾ SunlitRed Hat · automation-controllerEPSS 0.34%via NVD
CVE-2026-84716Medium· 6.6
5d ago

A flaw was found in the automation-controller instance install-bundle endpoint

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X…

▾ SunlitRed Hat · automation-controllerEPSS 0.18%via NVD
CVE-2026-84714High· 7.1
5d ago

A flaw was found in the automation-controller input-validation guard sanitize_jinja()

A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop a…

▾ TwilightRed Hat · automation-controllerEPSS 0.29%via NVD
CVE-2026-84713Medium· 6.5
5d ago

A flaw was found in the automation-controller notification subsystem

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is…

▾ SunlitRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.31%via NVD
CVE-2026-84712Medium· 5.3
5d ago

A flaw was found in the automation-controller API

A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data in…

▾ SunlitRed Hat · automation-controllerEPSS 0.34%via NVD
CVE-2026-84706High· 7.6
5d ago

A flaw was found in Ansible Automation Platform's automation-controller

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that om…

▾ TwilightRed Hat · automation-controllerEPSS 0.31%via NVD
CVE-2026-75884Critical· 9.1
5d ago

A flaw was found in AWX

A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service…

▾ MidnightRed Hat · automation-controllerEPSS 0.41%via NVD
CVEs tagged “nvd” — page 61 · VulnSea