VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25321 CVEsRSS

CVE-2026-88020Medium· 6.1
6d ago

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding.

▾ SunlitAutonomy Logic · OpenPLC RuntimeEPSS 0.27%via NVD
CVE-2026-77912High· 7.4
6d ago

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…

A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticated attacker to inject arbitrary HTML attributes into rendered Markdown because the Markdown rendering pipeline rewrot…

▾ TwilightGitHub · Enterprise ServerEPSS 0.45%via NVD
CVE-2026-96269High· 7.5
6d ago

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions

GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no particular user s…

▾ TwilightGNU · EmacsEPSS 0.15%via NVD
CVE-2026-62364Low· 2.3
6d ago

wlc is a Weblate command-line client using Weblate's REST API

wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration from .weblate, .weblate.ini, or weblate.ini can select the API URL while an unscoped API token is supplied through WLC_…

▾ SunlitWeblateOrg · wlcEPSS 0.08%via NVD
CVE-2026-76910Medium· 5.3PoC
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:projectId/features/:featureName/clone authorize creation in the destination project but do not verify access to the s…

▾ TwilightUnleash · unleashEPSS 0.30%via NVD
CVE-2026-76909Low· 2.1
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src/mailtemplates/requested-cr-approval/requested-cr-approval.html.mustache renders the user-controlled changeRequestTit…

▾ SunlitUnleash · unleashEPSS 0.27%via NVD
CVE-2026-77426High· 7.1
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization vulnerabilities. POST /api/admin/segments/strategies assigns the Promise returned by hasPermission without awaiting …

▾ TwilightUnleash · unleashEPSS 0.48%via NVD
CVE-2026-77425Medium· 4.3PoC
6d ago

Unleash is an open-source feature management platform

Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:featureName/environments/:environment/strategies/set-sort-order passes attacker-controlled strategy IDs to unprotectedUp…

▾ TwilightUnleash · unleashEPSS 0.23%via NVD
CVE-2026-63627Medium· 6.9
6d ago

mppx is a TypeScript interface for machine payments protocol

mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-payer.ts used decodeFunctionData to validate fee-sponsored calldata but did not reject trailing bytes. A client could …

▾ Sunlitwevm · mppxEPSS 0.38%via NVD
CVE-2026-76710High· 7.5
6d ago

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information

A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by sending specially c…

▾ Twilightarubanetworks · analytics_and_location_engineEPSS 0.54%via NVD
CVE-2026-76708Critical· 9.8
6d ago

A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts

A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system use default, hard-coded credentials for several administrative and system accounts. An unauthenticated remote attacke…

▾ Midnightarubanetworks · analytics_and_location_engineEPSS 0.59%via NVD
CVE-2026-63628Medium· 6.9PoC
6d ago

mppx is a TypeScript interface for machine payments protocol

mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/internal/fee-payer.ts copied a client-supplied access_list from a 0x78 FeePayerEnvelope without validating its length…

▾ Twilightwevm · mppxEPSS 0.38%via NVD
CVE-2026-76711High· 7.5
6d ago

A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections

A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly processes incoming socket connections. An unauthenticated remote attacker could exploit this vulnerability by providing spec…

▾ Twilightarubanetworks · analytics_and_location_engineEPSS 0.46%via NVD
CVE-2026-76709Critical· 9.8
6d ago

A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE)

A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to gain unauthorized write access to the…

▾ Midnightarubanetworks · analytics_and_location_engineEPSS 0.59%via NVD
CVE-2026-76713High· 7.2
6d ago

A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE)

A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful exploitation of this vulnerability could allow an authenticated remote attacker to gain unauthorized access to the file sy…

▾ Twilightarubanetworks · analytics_and_location_engineEPSS 0.55%via NVD
CVE-2026-76712High· 7.3
6d ago

A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service

A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending spe…

▾ Twilightarubanetworks · analytics_and_location_engineEPSS 0.43%via NVD
CVE-2026-89282Critical· 9.1
6d ago

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.

The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissions vulnerability through its default install directory on C:\, which inherits write access for Authenticated Users.

▾ MidnightApache HTTP Server Project · Apache Lounge WindowsEPSS 0.27%via NVD
CVE-2026-76716Medium· 5.3
6d ago

Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service

Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or denial of service. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted in…

▾ Sunlitarubanetworks · analytics_and_location_engineEPSS 0.51%via NVD
CVE-2026-76714High· 7.2
6d ago

Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host

Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on …

▾ Twilightarubanetworks · analytics_and_location_engineEPSS 0.84%via NVD
CVE-2026-94574High· 7.8
6d ago

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execut…

A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a hardcoded configuration file path (C:\msys64) that is writable by unprivileged users, allowing for arbitrary code execut…

▾ TwilightGNU Wget (Windows Builds) · WgetEPSS 0.12%via NVD
CVE-2026-89281High· 8.4
6d ago

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability within openssl.cnf path that can allow local code execution.

▾ TwilightApache HTTP Server Project · Apache Lounge WindowsEPSS 0.13%via NVD
CVE-2026-47116Critical· 9.8PoC
6d ago

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools

LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stored in /etc/shadow as weak hashes recoverable with dictionary-based cracking tools. The recovered credentials authenti…

▾ AbyssalLTSecurity · LTK3500SFEPSS 0.51%via NVD
CVE-2026-88418High· 8.8PoC
6d ago

CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms

CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-changing admin request, and it does not send the csrf_token hidden field in admin forms. Because administrator authent…

▾ MidnightEPSS 0.25%via NVD
CVE-2026-88416None
6d ago

MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.

MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature.

▾ SunlitEPSS 0.19%via NVD
CVE-2026-28325High· 8.8
6d ago

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability stemming from deserialization of untrusted data when the application is configured to use a specific communication mode.

▾ TwilightSolarWinds · Observability Self-HostedEPSS 1.5%via NVD
CVE-2026-88624Critical· 9.1
6d ago

Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.

Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recursive directory deletion via a crafted payload.

▾ MidnightEPSS 0.34%via NVD
CVE-2026-88339Medium· 5.5PoC
6d ago

A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV)

A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provid…

▾ TwilightEPSS 0.17%via NVD
CVE-2026-28324Critical· 9.8
6d ago

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks

SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure configuration are …

▾ MidnightSolarWinds · Observability Self-HostedEPSS 0.65%via NVD
CVE-2026-76715High· 7.1
6d ago

A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack

A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-middle (MitM) attack. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to exe…

▾ Twilightarubanetworks · analytics_and_location_engineEPSS 0.26%via NVD
CVE-2026-75432Medium· 6.5
6d ago

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::PopIndent(), and Scanner::PushIndentTo() components

▾ SunlitRed HatEPSS 0.22%via NVD
CVEs tagged “nvd” — page 79 · VulnSea