VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25278 CVEsRSS

CVE-2026-93421Medium· 5.3
5d ago

Mesop is a Python-based UI framework that allows users to build web applications

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.4, the unauthenticated /__csp__ endpoint passes attacker-controlled document-uri, blocked-uri, and violated-directive values to the csp_report…

▾ Sunlitmesop-dev · mesopEPSS 0.40%via NVD
CVE-2026-90905High· 7.2
5d ago

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated c…

Joomla Extension - joomshaper.com - Missing CSRF and Access Control on Site Configuration Update in Easy Store extension 1.0.0-3.0.0 - The endpoint administrator/index.php?option=com_easystore&task=appconfig.updateConfiguration updated c…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.26%via NVD
CVE-2026-90904High· 8.6
5d ago

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-l…

Joomla Extension - joomshaper.com - Broken Access Control (ACL Bypass) in ApiController Record Editing in Easy Store extension 1.0.0-3.0.0 - The allowEdit() method in ApiController.php hardcoded return true;, bypassing Joomla component-l…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.31%via NVD
CVE-2026-90903High· 7.2
5d ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action

Joomla Extension - joomshaper.com - Missing CSRF Token Verification across Administrator AJAX API Endpoints in Easy Store extension 1.0.0-3.0.0 - The administrator ApiController only validated CSRF tokens inside the products() action. Al…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.17%via NVD
CVE-2026-90902High· 8.6
5d ago

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdat…

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Coupon Bulk Update in Easy Store extension 1.0.0-3.0.0 - The coupon bulk update task (administrator/index.php?option=com_easystore&task=coupon.couponBulkUpdat…

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.28%via NVD
CVE-2026-90901High· 8.6
5d ago

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) …

Joomla Extension - joomshaper.com - Authenticated, Privileged SQL Injection in Media Image Deletion in Easy Store extension 1.0.0-3.0.0 - The media deletion endpoint (administrator/index.php?option=com_easystore&task=media.deleteImage) …

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.28%via NVD
CVE-2026-90900Medium· 5.3
5d ago

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addRevi…

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Store extension 1.0.0-3.0.0 - The product review submission endpoint (index.php?option=com_easystore&task=product.addRevi…

▾ Sunlitjoomshaper.com · Easy Store extension for JoomlaEPSS 0.17%via NVD
CVE-2026-90899High· 8.2
5d ago

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

Joomla Extension - joomshaper.com - Unauthenticated PII Exposure via IDOR in Guest Checkout in Easy Store extension 1.0.0-3.0.0 - The checkout.searchGuestUser endpoint allowed querying guest checkout records solely by supplying an email …

▾ Twilightjoomshaper.com · Easy Store extension for JoomlaEPSS 0.33%via NVD
CVE-2026-84502Critical· 9.9
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the modul…

▾ MidnightRed Hat · automation-controllerEPSS 0.62%via NVD
CVE-2026-84499High· 7.7
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template no…

▾ TwilightRed Hat · automation-controllerEPSS 0.38%via NVD
CVE-2026-84486High· 8.2
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) a…

▾ TwilightRed Hat · automation-controllerEPSS 0.52%via NVD
CVE-2026-84474Critical· 9.9
5d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template …

▾ MidnightRed Hat · automation-controllerEPSS 0.80%via NVD
CVE-2026-82368High· 8.7
5d ago

Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services

Insecure access controls on internal service ports in Brocade SANnav versions before 3.0.1a allow local, non-administrative host users to communicate directly with backend management services. A local attacker can leverage this exposed a…

▾ TwilightBrocade · SANnavEPSS 0.25%via NVD
CVE-2026-82356High· 7.5
5d ago

Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate

Imprivata EAM <=26.2.6 lacks the ability to rotate its RSA key pair after deployment when generating an X.509 certificate. Using an RSA key pair indefinitely for certificate generation is against best practices.

▾ TwilightImprivata · Imprivata Enterprise Access ManagementEPSS 0.11%via NVD
CVE-2026-77602Critical· 9.9
5d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later…

▾ Midnightopenc3 · openc3EPSS 0.57%via NVD
CVE-2026-77601High· 8.8PoC
5d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.12.0 until 7.3.0, an authenticated actor can write the pypi_url setting through set_setting at POST /openc3-ap…

▾ MidnightOpenC3 · cosmosEPSS 0.58%via NVD
CVE-2026-77423High· 7.5PoC
5d ago

JLine is a Java library for handling console input

JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes user-controlled search and display-filter patterns from getPattern(boolean doDisplayPattern) in builtins/src/ma…

▾ Midnightjline · jline3EPSS 0.39%via NVD
CVE-2026-77394High· 7.6PoC
5d ago

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.0.6 until 7.3.0, an authenticated actor with system_set permission can store a shared screen through POST /ope…

▾ MidnightOpenC3 · cosmosEPSS 0.39%via NVD
CVE-2026-76648High· 8.5
5d ago

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'r…

▾ TwilightRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.24%via NVD
CVE-2026-76089High· 7.7
5d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/sent-notifications/get-resend-modal-content control panel action in SentNotificationsController::actionGetResendModalContent accepts a request-s…

▾ Twilightverbb · formieEPSS 0.24%via NVD
CVE-2026-76087High· 8.2
5d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submit action in SubmissionsController::actionSubmit trusts a client-supplied submissionId when loading an incomplete subm…

▾ Twilightverbb · formieEPSS 0.31%via NVD
CVE-2026-76086High· 8.5
5d ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings control panel action in IntegrationsController::actionFormSettings is reachable without the required form integration…

▾ Twilightverbb · verbb/formieEPSS 0.29%via NVD
CVE-2026-71465Low· 3.1
5d ago

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob. A limit beginning with - is parsed as an ansible CLI op…

▾ SunlitRed Hat · automation-controllerEPSS 0.21%via NVD
CVE-2026-71464Low· 3.1
5d ago

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers. Schedule and WFJT Node accept --upload-pack=/bin/id…

▾ SunlitRed Hat · automation-controllerEPSS 0.21%via NVD
CVE-2026-71463Low· 2.7
5d ago

Notification template Jinja AST whitelist only inspects static Getattr nodes

Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the…

▾ SunlitRed Hat · automation-controllerEPSS 0.27%via NVD
CVE-2026-71462Medium· 4.1
5d ago

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenan…

▾ SunlitRed Hat · automation-controllerEPSS 0.26%via NVD
CVE-2026-71461Medium· 4.3
5d ago

HostList.list() catches bare Exception and returns str(e) verbatim

HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including intern…

▾ SunlitRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.21%via NVD
CVE-2026-71460Medium· 4.3
5d ago

/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user

/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuse…

▾ SunlitRed Hat · automation-controllerEPSS 0.22%via NVD
CVE-2026-61814High· 7.5
5d ago

Jawn is an open source JSON parser

Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON token is delivered across many small chunks because each absorb call rescans the incomplete token from the start. A remo…

▾ Twilighttypelevel · jawnEPSS 0.57%via NVD
CVE-2026-61695High· 7.5
5d ago

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMI…

▾ Twilightsquare · github.com/square/wireEPSS 0.58%via NVD
CVEs tagged “nvd” — page 63 · VulnSea