VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25342 CVEsRSS

CVE-2026-76803Medium· 5.3
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN opti…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.40%via NVD
CVE-2026-95818Low· 3.6⚖ disputed
6d ago

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_R…

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_R…

▾ SunlitThe GNU C Library · glibcEPSS 0.13%via NVD
CVE-2026-76802Medium· 4.7⚖ disputed
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzz…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.18%via NVD
CVE-2026-87902High· 8.1CISA KEVPoC
6d ago

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are…

▾ Abyssalwordpress · wordpressEPSS 18%via NVD
CVE-2026-84301Medium· 6.3PoC
6d ago

FastGPT is an open-source LLM platform for building AI applications on a knowledge base

FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios request interceptor in packages/service/common/api/axios.ts validates a hostname with isInternalAddress() before a l…

▾ Twilightlabring · FastGPTEPSS 0.29%via NVD
CVE-2026-83602Medium· 6.5
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled b…

▾ Sunlitnetdata · netdataEPSS 0.51%via NVD
CVE-2026-83599High· 7.5
6d ago

Netdata is an open source observability tool

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompre…

▾ Twilightnetdata · netdataEPSS 0.74%via NVD
CVE-2026-13087High· 8.8PoC
6d ago

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c

A heap out-of-bounds write vulnerability was found in the Linux kernel's RPC-over-RDMA server reply path in net/sunrpc/xprtrdma/svc_rdma_sendto.c. When a crafted RPC-over-RDMA client sends a large NFS READ request with an empty Write lis…

▾ MidnightRed Hat · kernelEPSS 0.47%via NVD
CVE-2026-56682Medium· 5.3PoC
6d ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, …

▾ Twilightdecolua · 9routerEPSS 0.47%via NVD
CVE-2026-81881Low· 3.3
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O Swift field-metadata parser was vulnerable because a relative Swift field pointer could be lower than the field-metadata sect…

▾ Sunlitradare · radare2EPSS 0.13%via NVD
CVE-2026-81878Medium· 5.5PoC
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecode .pyc marshal parser was vulnerable because the CPython marshal readers accepted a 32-bit string length without reje…

▾ Twilightradare · radare2EPSS 0.20%via NVD
CVE-2026-81886Medium· 5.5
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Windows 64-bit crash-dump dmp64 parser was vulnerable because the Windows dmp64 parser used an input-controlled physical-memory-run …

▾ Sunlitradare · radare2EPSS 0.12%via NVD
CVE-2026-81880Medium· 5.5
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Apple Preferred Executable Format loader was vulnerable because the PEF loader accepted relocSecCount values that were not bounded b…

▾ Sunlitradare · radare2EPSS 0.14%via NVD
CVE-2026-81885Medium· 5.5PoC
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's NE relocation fixup-chain parser was vulnerable because the NE relocation parser followed fixup chains without an active iteration l…

▾ Twilightradare · radare2EPSS 0.12%via NVD
CVE-2026-81883Low· 3.3PoC
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecode function parser was vulnerable because the Lua 5.3 bytecode function parser read fixed function-metadata fields imm…

▾ Twilightradare · radare2EPSS 0.18%via NVD
CVE-2026-81882Low· 3.3
6d ago

radare2 is a UNIX-like reverse engineering framework and command-line toolset

radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's binary property-list Unicode parser was vulnerable because the binary-property-list Unicode parser underallocated an uninitialized U…

▾ Sunlitradare · radare2EPSS 0.13%via NVD
CVE-2026-80143Critical· 9.9
6d ago

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute ar…

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute ar…

▾ MidnightLANTRONIX · SLC8000EPSS 1.5%via NVD
CVE-2026-77619High· 8.7
6d ago

Vector is a high-performance observability data pipeline

Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit compressed-frame length from the network and uses it to size an in-memory buffer without an upper bound. An unauthenti…

▾ Twilightvectordotdev · vectorEPSS 0.52%via NVD
CVE-2026-80145Critical· 9.1
6d ago

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the serv…

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the serv…

▾ MidnightLANTRONIX · SLC8000EPSS 1.7%via NVD
CVE-2026-77621Critical· 9.3
6d ago

Vector is a high-performance observability data pipeline

Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated path from event fields and opens the result without confining it to an intended directory. When an untrusted source s…

▾ Midnightvectordotdev · vectorEPSS 1.1%via NVD
CVE-2026-80147Critical· 9.9
6d ago

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to …

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to …

▾ MidnightLANTRONIX · SLC8000EPSS 0.85%via NVD
CVE-2026-80146Critical· 9.9
6d ago

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to …

Lantronix SLC8000/SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a stack-based buffer overflow vulnerability that allows authenticated attackers to …

▾ MidnightLANTRONIX · SLC8000EPSS 0.85%via NVD
CVE-2026-85055High· 7.1
6d ago

Twenty is an open-source CRM (customer relationship management) platform

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.22.0, field-level read permission is enforced on selected output fields but not on GraphQL or REST filter predicates. A workspace member or API key with…

▾ Twilighttwentyhq · twentyEPSS 0.43%via NVD
CVE-2026-80150High· 7.5
6d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

▾ TwilightLANTRONIX · SLC8000EPSS 0.58%via NVD
CVE-2026-80148High· 8.6
6d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882 contain a server-side request forgery vulnerability in the WebSSH/WebTelnet liste…

▾ TwilightLANTRONIX · SLC8000EPSS 0.58%via NVD
CVE-2026-80151Critical· 9.1
6d ago

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticat…

Lantronix SLC8000 before firmware v9.7.0.3, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticat…

▾ MidnightLANTRONIX · SLC8000EPSS 1.7%via NVD
CVE-2026-79311Medium· 6.1
6d ago

webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) via render_jinja.__init__().

▾ SunlitRed HatEPSS 0.15%via NVD
CVE-2026-95653High· 7.5
6d ago

Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable

Concrete CMS Community Store before 2.7.8 derives digital product download tokens from order creation timestamps instead of random values, making tokens predictable. Unauthenticated attackers can enumerate sequential order and file ident…

▾ Twilightconcretecms-community-store · community_storeEPSS 0.57%via NVD
CVE-2026-80156Critical· 9.1
6d ago

Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management port…

Lantronix SLC8000 before firmware v9.7.0.5, SLC9000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a path traversal vulnerability in the web management port…

▾ MidnightLANTRONIX · SLC8000EPSS 0.70%via NVD
CVE-2026-80154Critical· 9.6
6d ago

All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session…

All firmware versions of Lantronix SLC8000, SLC9000, EMG8500, EMG7500, SLB882, SLCx-03, and SLCx-02 contain an authentication bypass vulnerability in the web management portal that allows unauthenticated attackers to derive valid session…

▾ MidnightLANTRONIX · SLC8000EPSS 0.63%via NVD
CVEs tagged “nvd” — page 86 · VulnSea