VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25321 CVEsRSS

CVE-2026-88345High· 7.5PoC
6d ago

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema ends with an unterminated quotation mark, the C-string scanning logic in lex() dereferences the input pointer afte…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-88344High· 7.5
6d ago

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e

An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers schema buffer ends with a digit, the integer digit-scan loop in lex() advances past the end of the input buffer and deref…

▾ TwilightEPSS 0.40%via NVD
CVE-2026-88340High· 7.6
6d ago

An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files

An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_…

▾ TwilightEPSS 0.25%via NVD
CVE-2026-88419High· 8.8PoC
6d ago

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execut…

An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=thumbUpload) of WuzhiCMS 5.0.0 allows an authenticated low-privileged member to upload a crafted .php file and execut…

▾ MidnightEPSS 0.48%via NVD
CVE-2026-88341Medium· 5.5PoC
6d ago

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files

A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.17%via NVD
CVE-2026-63104High· 8.1PoC
6d ago

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk…

Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace members with viewer or member roles to delete and modify tasks beyond their assigned permissions by exploiting the bulk…

▾ Midnightusekaneo · kaneoEPSS 0.49%via NVD
CVE-2026-88350None
6d ago

An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().

An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc().

▾ SunlitEPSS 0.15%via NVD
CVE-2026-83805Medium· 6.4
6d ago

Nautobot is a Network Source of Truth and Network Automation Platform

Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkflowStageResponse create endpoint does not enforce approver-group membership, change permission on the object under re…

▾ Sunlitnautobot · nautobotEPSS 0.22%via NVD
CVE-2026-83801Medium· 5.4
6d ago

Nautobot is a Network Source of Truth and Network Automation Platform

Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add_relationship or extras.change_relationship permission can store HTML or JavaScript in a Relationship description, an…

▾ Sunlitnautobot · nautobotEPSS 0.22%via NVD
CVE-2026-87121Critical· 9.8
6d ago

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution on the device.

▾ MidnightlwIP · TCP/IP Stack MQTTEPSS 0.53%via NVD
CVE-2026-79767Medium· 5.5
6d ago

Gardener implements the automated management and operation of Kubernetes clusters as a service

Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.3, 1.144.2, and 1.145.0, the customverbauthorizer admission plugin's mustCheckProjectMembers manage-members check com…

▾ Sunlitgardener · gardenerEPSS 0.39%via NVD
CVE-2026-77322High· 7.5PoC
6d ago

SIPGO is a library for writing SIP services in the GO language

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go creates a wsutil.Reader without setting MaxFrameSize, allowing NextFrame to accept a client-controlled header.Length…

▾ Midnightemiago · sipgoEPSS 0.52%via NVD
CVE-2026-76717Medium· 5.3
6d ago

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information

A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive information. An unauthenticated remote attacker could exploit this vulnerability by providing specially crafted input to…

▾ Sunlitarubanetworks · analytics_and_location_engineEPSS 0.42%via NVD
CVE-2026-65829Medium· 5.3
6d ago

MPXJ is an open source library to read and write project plans from a variety of file formats and databases

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbit…

▾ Sunlitjoniles · mpxjEPSS 0.34%via NVD
CVE-2026-61570High· 7.5
6d ago

MPXJ is an open source library to read and write project plans from a variety of file formats and databases

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 until 16.4.1, MerlinReader creates a DocumentBuilder with default settings while parsing XML from the ZTIMEINTERVALS …

▾ Twilightsf · net.sf.mpxj:mpxjEPSS 0.35%via NVD
CVE-2026-59991High· 7.5PoC
6d ago

psd-tools is a Python package for working with Adobe Photoshop PSD files

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDImage.numpy() allocated output buffers from attacker-controlled PSD header geometry, including width, height, channels…

▾ Midnightpsd-tools · psd-toolsEPSS 0.52%via NVD
CVE-2026-62985High· 7.5PoC
6d ago

request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses

request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior to 3.2.1, RequestFilteringHttpAgent and RequestFilteringHttpsAgent synchronously threw from createConnection when rej…

▾ Midnightazu · request-filtering-agentEPSS 0.46%via NVD
CVE-2026-58268High· 7.5
6d ago

SIPGO is a library for writing SIP services in the GO language

SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_stream.go allocates a SIP body buffer from the client-controlled Content-Length header before ParseMaxMessageLength is…

▾ Twilightemiago · sipgoEPSS 0.61%via NVD
CVE-2026-91130Critical· 9.3PoC
6d ago

Home Assistant is open source home automation software focused on local control and privacy

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Statistics Graph card in src/components/chart/statistics-chart.ts passed entity names through getStatisticLabel and compu…

▾ Abyssalhomeassistant · homeassistantEPSS 0.39%via NVD
CVE-2026-91129Medium· 5.4PoC
6d ago

Home Assistant is open source home automation software focused on local control and privacy

Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP integration automatically processed unauthenticated _ipp._tcp.local mDNS announcements in homeassistant/components/ip…

▾ Twilighthome-assistant · coreEPSS 0.20%via NVD
CVE-2026-84395High· 7.1
6d ago

Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access

Premiere Pro is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation potentially resulting in unauthorized write access. Exploitation of this issue does not require user interaction. Sc…

▾ TwilightAdobe · PremiereEPSS 0.25%via NVD
CVE-2026-77399Medium· 6.5
6d ago

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python

icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.from_ical accepts an attacker-controlled VALARM REPEAT value and applications that request alarm times can eagerly expan…

▾ Sunlitcollective · icalendarEPSS 0.31%via NVD
CVE-2026-63386Medium· 5.3PoC
6d ago

js-toml is a TOML parser for JavaScript

js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does not bound nesting or dotted-key depth in the recursive parser at src/load/parser.ts or the interpreter at src/load/interpreter.ts, so deeply nested arrays, deeply neste…

▾ Twilightsunnyadn · js-tomlEPSS 0.36%via NVD
CVE-2026-57149Critical· 9.9
6d ago

plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone

plone.app.portlets.portlets provides a Plone-specific user interface for plone.portlets, as well as a standard set of portlets that ship with Plone. Starting in version 5.0.0 and prior to versions 5.0.8, 6.0.4, and 7.0.2, the Classic por…

▾ Midnightplone · plone.app.portletsEPSS 0.64%via NVD
CVE-2026-77257High· 8.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, HTTP-exposed Jira and Confluence upload tools pass a caller-provided file_path to local file operations without restric…

▾ Twilightsooperset · mcp-atlassianEPSS 0.40%via NVD
CVE-2026-77254Critical· 9.1PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, requests to the HTTP MCP endpoint without a per-user identity are allowed to reach tool handlers, which then use global…

▾ Abyssalmcp-atlassian · mcp_atlassianEPSS 0.61%via NVD
CVE-2026-77262High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment accepts an attacker-controlled file_path and does not apply the path restriction added for…

▾ Midnightsooperset · mcp-atlassianEPSS 0.54%via NVD
CVE-2026-95831High· 7.8
6d ago

Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file

Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts t…

▾ TwilightEPSS 0.12%via NVD
CVE-2026-77255High· 8.6PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira update_issue attachments argument is converted into local paths and routed to the attachment upload implementa…

▾ Midnightsooperset · mcp-atlassianEPSS 0.40%via NVD
CVE-2026-77269Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the remediation for CVE-2026-27825 protects download destinations but does not constrain source paths used by attachmen…

▾ Twilightsooperset · mcp-atlassianEPSS 0.38%via NVD
CVEs tagged “nvd” — page 80 · VulnSea