VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25299 CVEsRSS

CVE-2026-92928Medium· 6.5
5d ago

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated

OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains a hardcoded, undocumented recovery account with a shared credential that cannot be changed, disabled, or rotated. An unauthenticated remote attacker can use the accoun…

▾ SunlitOpenEye · Apex Network Video Recorder (NVR)EPSS 0.21%via NVD
CVE-2026-95868Medium· 6.3PoC
5d ago

A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c

A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. Affected by this issue is the function mysqli_query of the file admin/display_menu.php of the component Search …

▾ TwilightAdithyaYelloju · Restaurant-Management-SystemEPSS 0.24%via NVD
CVE-2026-95833Medium· 6.3PoC
5d ago

A weakness has been identified in itsourcecode Leave Management System 1.0

A weakness has been identified in itsourcecode Leave Management System 1.0. Impacted is an unknown function of the file /module/leavetype/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated r…

▾ Twilightitsourcecode · Leave Management SystemEPSS 0.20%via NVD
CVE-2026-77285Low· 2.4⚖ disputed
5d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode could write secrets from env_template to standard output when command/agent/exec/exec.go re-created the template runn…

▾ Sunlitopenbao · openbaoEPSS 0.13%via NVD
CVE-2026-63132Critical· 9.2
5d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path in http/logical.go compared the highly privileged recovery token with ordinary string equality. A remote unauthentic…

▾ Midnightopenbao · openbaoEPSS 0.50%via NVD
CVE-2026-63131Medium· 6.0
5d ago

OpenBao is an open source identity-based secrets management system

OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could evaluate a broader wildcard ACL grant before more-specific trailing-wildcard ACL paths with capabilities = ["deny"] f…

▾ Sunlitopenbao · openbaoEPSS 0.35%via NVD
CVE-2026-57168Critical· 9.6
5d ago

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-56120. Reason: This candidate is a duplicate of CVE-2026-56120. Notes: All CVE users should reference CVE-2026-56120 instead of this candidate.

▾ Midnightopenremote · io.openremote:openremote-managervia NVD
CVE-2026-61685High· 7.5
6d ago

ReactPress is a publishing system for React developers

ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `articl…

▾ Twilightfecommunity · reactpressEPSS 0.53%via NVD
CVE-2026-57576Medium· 6.5
6d ago

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types

plone.app.dexterity is a content-type system for the Plone content management system, and plone.app.contenttypes provides Plone’s Dexterity-based content types. Plone.app.dexterity versions through 3.2.2, 4.0.0 through 4.1.2, and 5.0.0, …

▾ Sunlitplone · plone.app.dexterityEPSS 0.76%via NVD
CVE-2026-18163Critical· 9.8
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.

▾ MidnightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.51%via NVD
CVE-2026-18170Medium· 6.5
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to allocation of resources without limits or throttling.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.19%via NVD
CVE-2026-18162Critical· 9.8
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.

▾ MidnightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.48%via NVD
CVE-2026-18176High· 7.4
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.13%via NVD
CVE-2026-18172High· 7.4
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper restriction of XML external entity references.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.20%via NVD
CVE-2026-18173Low· 3.7
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to improper enforcement of mutual TLS authentication.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.24%via NVD
CVE-2026-18169Critical· 9.9
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.

▾ MidnightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.53%via NVD
CVE-2026-95820Medium· 6.3PoC
6d ago

A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6

A vulnerability was found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this issue is some unknown functionality of the file /dashboard/userprofile.php?section=admin1. Performing a man…

▾ Twilightanirbandutta9 · College-Notes-GalleryEPSS 0.35%via NVD
CVE-2026-95828Medium· 4.3PoC
6d ago

A vulnerability was determined in Mstfakts College-Management-System

A vulnerability was determined in Mstfakts College-Management-System. This affects the function session_start of the file Front-end/server.php of the component Authentication. Executing a manipulation can lead to session fixiation. It is…

▾ TwilightMstfakts · College-Management-SystemEPSS 0.49%via NVD
CVE-2026-95819High· 7.3PoC
6d ago

A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6

A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument use…

▾ Midnightanirbandutta9 · College-Notes-GalleryEPSS 0.41%via NVD
CVE-2026-18161Medium· 4.3
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to falsify transaction audit logs due to improper validation of a client-supplied HTTP header.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.20%via NVD
CVE-2026-18156Medium· 6.5
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to bypass security controls by forging user identities due to improper authorization.

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.24%via NVD
CVE-2026-18154High· 8.0
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to the use of a hard-coded or predictable cryptographic key.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.17%via NVD
CVE-2026-18153Medium· 5.4
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vec…

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information and forge authentication tags due to the use of hard-coded cryptographic keys and initialization vec…

▾ SunlitIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.14%via NVD
CVE-2026-18152High· 7.4
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to forge validly-signed messages due to improper verification of cryptographic signatures.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.12%via NVD
CVE-2026-18137High· 8.1
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary ESQL commands due to improper neutralization of special elements used in an ESQL command.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.30%via NVD
CVE-2026-18134High· 7.5
6d ago

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive information due to cleartext transmission of sensitive information.

▾ TwilightIBM · Financial Transaction Manager (FTM) for RedHat OpenShiftEPSS 0.13%via NVD
CVE-2026-16346Critical· 9.9
6d ago

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ MidnightIBM · DataStage on Cloud Pak for DataEPSS 0.45%via NVD
CVE-2026-15915Medium· 6.2
6d ago

IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.

▾ SunlitIBM · ConcertEPSS 0.12%via NVD
CVE-2025-36084Medium· 5.9
6d ago

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

IBM Concert 1.0.0 through 3.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information.

▾ SunlitIBM · ConcertEPSS 0.16%via NVD
CVE-2025-12767Medium· 5.3
6d ago

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resource consumption.

▾ SunlitIBM · ConcertEPSS 0.36%via NVD
CVEs tagged “nvd” — page 76 · VulnSea