VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25245 CVEsRSS

CVE-2026-68492High· 8.7
5d ago

An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.

An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote authenticated users to execute arbitrary code as root via the "Plesk RESTful API" extension from 2.4.2 before 2.4.7.

▾ TwilightWebPros · PleskEPSS 0.35%via NVD
CVE-2026-68490High· 8.2
5d ago

Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.

Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other accounts.

▾ TwilightWebPros · cPanelEPSS 0.13%via NVD
CVE-2026-67238High· 7.1
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/1 parses a caller-supplied ETF-encoded binary and calls binary_to_atom(Node, utf8) on the node-name field. It is reac…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.33%via NVD
CVE-2026-66079High· 8.2
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitive/2 for constructor 0x45 (list0) returns an element with byte-width B = 0. The enclosing array32 parser at line 148 r…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.32%via NVD
CVE-2026-66076Low· 2.3PoC⚖ disputed
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized/2 calls rabbit_mgmt_util:is_authorized/2, which checks only the management tag, instead of is_authorized_vhost/2. Th…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.27%via NVD
CVE-2026-66070High· 7.6
5d ago

RabbitMQ is a messaging and streaming broker

RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 returned the bare reflected Origin and allowed credentials even when the wildcard "" was configured, so the response echoe…

▾ Twilightrabbitmq · rabbitmq-serverEPSS 0.41%via NVD
CVE-2026-84691High· 8.7
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a li…

▾ TwilightRed Hat · automation-controllerEPSS 0.20%via NVD
CVE-2026-94183High· 7.4
5d ago

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background

Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to…

▾ TwilightThe Browser Company of New York · Arc SearchEPSS 0.20%via NVD
CVE-2026-84683High· 8.7
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal es…

▾ TwilightRed Hat · automation-controllerEPSS 0.26%via NVD
CVE-2026-82406High· 7.1PoC
5d ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function core/kapp/market/market.go Buy does not check IsClaimed before accepting a bid. A seller can use the Claim seller-acce…

▾ Midnightklever-io · klever-goEPSS 0.34%via NVD
CVE-2026-82407High· 7.0PoC
5d ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.go Register and the runtime validator update path accept a submitted BLSPublicKey without curve, prime-order subgroup,…

▾ Midnightklever-io · klever-goEPSS 0.43%via NVD
CVE-2026-82409High· 8.4PoC
5d ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataForUpdateAccounts places the attacker-controlled acc.Name value into an Elasticsearch _bulk JSON and NDJSON request wi…

▾ Midnightklever-io · klever-goEPSS 0.27%via NVD
CVE-2026-86065High· 7.5
5d ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe endpoint in network/api/websocket/routes.go accepts unauthenticated WebSocket clients with permissive origin handling,…

▾ Twilightklever-io · github.com/klever-io/klever-goEPSS 0.35%via NVD
CVE-2026-86064High· 8.6PoC
5d ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSocket route configured in config/node/api.yaml and registered by network/api/api.go does not require authentication. The…

▾ Midnightklever-io · klever-goEPSS 0.40%via NVD
CVE-2026-82405High· 8.7
5d ago

Klever-Go is the Go implementation of the Klever blockchain protocol

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission built-in authorizes replacement of a target account's permissions by checking attacker-controlled vmInput.RecipientA…

▾ Twilightklever-io · github.com/klever-io/klever-goEPSS 0.26%via NVD
CVE-2026-96872Low· 2.9
5d ago

Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This is…

Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Windows allows Accessing Functionality Not Properly Constrained by ACLs. This is…

▾ SunlitThe Wikimedia Foundation · Mediawiki - WikiLambda ExtensionEPSS 0.23%via NVD
CVE-2026-96770Critical· 9.3
5d ago

All published s2s-proxy versions through 0.2.2 are affected

All published s2s-proxy versions through 0.2.2 are affected. In versions 0.1.16 through 0.2.2, TLS server listeners use Go's RequireAnyClientCert mode when skipCAVerification is false. This mode checks that the client holds the certifica…

▾ MidnightTemporal Technologies, Inc. · github.com/temporalio/s2s-proxyEPSS 0.25%via NVD
CVE-2026-96549Low· 3.3PoC
5d ago

A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability affects unknown code of the file ssm_pro/src/main/java/cn/sfturing/service/impl/CommonUserServiceImpl.java. Such man…

▾ Twilightsfturing · hosp_orderEPSS 0.08%via NVD
CVE-2026-96548Medium· 5.6PoC
5d ago

A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8

A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is poss…

▾ Twilightsfturing · hosp_orderEPSS 0.26%via NVD
CVE-2026-96546Low· 2.5PoC
5d ago

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. …

▾ TwilightRed Hat · gimpEPSS 0.11%via NVD
CVE-2026-96545Medium· 4.4PoC
5d ago

An out-of-bounds heap read flaw was found in GIMP's TIM image loader

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the l…

▾ TwilightRed Hat · gimpEPSS 0.18%via NVD
CVE-2026-94181High· 7.4
5d ago

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.

An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a <select> element that triggers requestFullscreen without displaying the fullscreen notification.

▾ TwilightThe Browser Company of New York · ArcEPSS 0.26%via NVD
CVE-2026-93421Medium· 5.3
5d ago

Mesop is a Python-based UI framework that allows users to build web applications

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report…

▾ Sunlitmesop-dev · mesopEPSS 0.40%via NVD
CVE-2026-90905High· 7.2
5d ago

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated c…

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated c…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.26%via NVD
CVE-2026-90904High· 8.6
5d ago

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-l…

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-l…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.31%via NVD
CVE-2026-90903High· 7.2
5d ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. Al…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.17%via NVD
CVE-2026-90902High· 8.6
5d ago

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdat…

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdat…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.28%via NVD
CVE-2026-90901High· 8.6
5d ago

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) …

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) …

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.28%via NVD
CVE-2026-90900Medium· 5.3
5d ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addRevi…

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addRevi…

▾ Sunlitjoomshaper.com · Easy Store extension for JoomlaEPSS 0.17%via NVD
CVE-2026-90899High· 8.2
5d ago

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.33%via NVD
CVEs tagged “nvd” — page 62 · VulnSea