VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25342 CVEsRSS

CVE-2026-18458Medium· 6.8
6d ago

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Co…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-18457High· 8.3
6d ago

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers

Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6…

▾ TwilightRTI · connext_professionalEPSS 0.26%via NVD
CVE-2026-43641Critical· 9.8PoC
6d ago

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authent…

▾ AbyssalSoftaculous · VirtualizorEPSS 3.0%via NVD
CVE-2026-18460Medium· 6.9
6d ago

Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers

Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6.

▾ SunlitRTI · connext_professionalEPSS 0.25%via NVD
CVE-2026-18459High· 8.7
6d ago

Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality

Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*,…

▾ TwilightRTI · connext_professionalEPSS 0.25%via NVD
CVE-2026-83597High· 7.0
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-pr…

▾ Twilightnetdata · netdataEPSS 0.14%via NVD
CVE-2026-18462High· 7.3
6d ago

Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation

Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before…

▾ TwilightRTI · connext_professionalEPSS 0.08%via NVD
CVE-2026-43642High· 8.1
6d ago

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserializat…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing module handler that allows unauthenticated remote attackers to supply arbitrary serialized PHP objects for deserializat…

▾ TwilightSoftaculous · VirtualizorEPSS 0.96%via NVD
CVE-2026-18626Medium· 6.8
6d ago

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers

Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 bef…

▾ SunlitRTI · connext_professionalEPSS 0.10%via NVD
CVE-2026-77267High· 8.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and us…

▾ Twilightsooperset · mcp-atlassianEPSS 0.34%via NVD
CVE-2026-77252Medium· 6.5
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, caller-supplied projects_filter and spaces_filter arguments can replace administrator-configured allowlists, and caller…

▾ Sunlitmcp-atlassian · mcp_atlassianEPSS 0.30%via NVD
CVE-2026-77251High· 8.3PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence se…

▾ Midnightsooperset · mcp-atlassianEPSS 0.25%via NVD
CVE-2026-77250Medium· 6.1PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian direc…

▾ Twilightsooperset · mcp-atlassianEPSS 0.12%via NVD
CVE-2026-43643High· 7.5
6d ago

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafte…

Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing module handler that allows unauthenticated remote attackers to modify any tenant's account balance by supplying crafte…

▾ TwilightSoftaculous · VirtualizorEPSS 0.62%via NVD
CVE-2026-83603High· 8.4PoC
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata…

▾ Midnightnetdata · netdataEPSS 0.35%via NVD
CVE-2026-83601Medium· 6.5PoC
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot in src/plugins.d/pluginsd_internals.h witho…

▾ Twilightnetdata · netdataEPSS 0.37%via NVD
CVE-2026-83600Medium· 6.5PoC
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. Th…

▾ Twilightnetdata · netdataEPSS 0.55%via NVD
CVE-2026-83598High· 7.8
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell…

▾ Twilightnetdata · netdataEPSS 0.16%via NVD
CVE-2026-76819High· 8.6
6d ago

Rejected reason: Further research determined the issue results from a dependency.

Rejected reason: Further research determined the issue results from a dependency.

▾ Twilightprojectdiscovery · github.com/projectdiscovery/nuclei/v3via NVD
CVE-2026-86059Critical· 9.6PoC
6d ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Git provider access can retrieve plaintext provider credentials through github.one, gitlab.one, gitea.one, and bitbucke…

▾ AbyssalDokploy · dokployEPSS 0.49%via NVD
CVE-2026-85709Medium· 5.3PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and l…

▾ TwilightHKUDS · LightRAGEPSS 0.39%via NVD
CVE-2026-94456Critical· 9.1
6d ago

Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source

Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The same helper is used for OAuth access tokens, authorization codes, client secrets, organization API keys, and PKCE ver…

▾ MidnightGitroomHQ · postiz-appEPSS 0.52%via NVD
CVE-2026-94455High· 7.1
6d ago

An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session

An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The authentication middleware is bound only to an explicit list of controllers, and the enterprise controller is not on th…

▾ TwilightGitroomHQ · postiz-appEPSS 0.26%via NVD
CVE-2026-85725Medium· 5.9PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after th…

▾ TwilightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-85740High· 7.1
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying…

▾ TwilightHKUDS · LightRAGEPSS 0.22%via NVD
CVE-2026-85734Critical· 9.1
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication atte…

▾ MidnightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-86062Medium· 6.1PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an H…

▾ TwilightHKUDS · LightRAGEPSS 0.25%via NVD
CVE-2026-83803High· 7.7
6d ago

Sentry is an error tracking and performance monitoring tool

Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the relocation feature enabled unsafely deserialize a legacy database field while importing a user-supplied relocation archive.…

▾ Twilightgetsentry · sentryEPSS 0.60%via NVD
CVE-2026-76805Medium· 5.3
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that all…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.41%via NVD
CVE-2026-76804Medium· 5.5
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. …

▾ Sunlitprojectdiscovery · nucleiEPSS 0.17%via NVD
CVEs tagged “nvd” — page 85 · VulnSea