VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25359 CVEsRSS

CVE-2026-12718Critical· 9.8
6d ago

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic Industry and Trade Inc. KarelIPS allows Blind SQL Injection. This issue affects KarelIPS: through 22092026. NOTE: The…

▾ MidnightKarel Electronic Industry and Trade Inc. · KarelIPSEPSS 0.32%via NVD
CVE-2026-95682Medium· 4.8
6d ago

MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen

MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org organization name setting was interpolated directly into a JavaScript string literal using an unescaped PHP echo: var org…

▾ SunlitMISP · MISPEPSS 0.42%via NVD
CVE-2026-95666Medium· 4.3
6d ago

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive dat…

Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length of the post ID array accepted by the bulk reactions endpoint which allows an authenticated user to cause excessive dat…

▾ SunlitMattermost · MattermostEPSS 0.36%via NVD
CVE-2026-93343Medium· 6.5
6d ago

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the comp…

MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_vendors_ajax AJAX action that allows authenticated attackers with subscriber-level access or higher to retrieve the comp…

▾ SunlitWebWizards · MarketKingEPSS 0.40%via NVD
CVE-2026-95271High· 7.3PoC
6d ago

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7

A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation lead…

▾ Midnightdgtlmoon · changedetection.ioEPSS 0.65%via NVD
CVE-2026-95272Low· 3.7PoC
6d ago

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7

A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument fil…

▾ Twilightdgtlmoon · changedetection.ioEPSS 0.67%via NVD
CVE-2026-95658Medium· 6.9
6d ago

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list

MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list. In CakePHP, listing an action in unlockedActions disables both the CSRF token check and the field hash validation fo…

▾ SunlitMISP · MISPEPSS 0.27%via NVD
CVE-2026-95273Medium· 4.3PoC
6d ago

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7

A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argume…

▾ Twilightdgtlmoon · changedetection.ioEPSS 0.52%via NVD
CVE-2026-95659Medium· 4.8
6d ago

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action

MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. The method accepted a parent object type parameter from the URL without validation and passed it to the Overmind-theme…

▾ SunlitMISP · MISPEPSS 0.39%via NVD
CVE-2026-75791High· 8.6
6d ago

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerability in the REST API.

▾ TwilightZohocorp · ManageEngine ADSelfService PlusEPSS 1.7%via NVD
CVE-2026-95661Medium· 5.1
6d ago

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view

MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes variable, which is derived from the URL path segment , was interpolated directly into a JavaScript array literal insid…

▾ SunlitMISP · MISPEPSS 0.44%via NVD
CVE-2026-95619High· 7.7
6d ago

A flaw was found in libstdc++

A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in the C++ library. This vulnerability could lead to an undersized memory allocation, potentially causing memory corrup…

▾ TwilightRed Hat · gcc-mainEPSS 0.36%via NVD
CVE-2026-93616Critical· 9.8CISA KEV0dayPoC
6d ago

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

▾ Hadalcheckpoint · multi-domain_security_managementEPSS 20%via NVD
CVE-2026-63275Medium· 5.4
6d ago

LibreOffice can read CFF fonts, which may be embedded in documents

LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hints of a glyph. The number of hints was checked against the wrong bound, so a glyph declaring more hints than the arra…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63272Medium· 5.4
6d ago

LibreOffice can import WMF graphics, which may be embedded in documents

LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a text record that carries its own character advance widths. The count of advance values and the length of the text we…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-95270Low· 3.7PoC
6d ago

A flaw has been found in dgtlmoon changedetection.io up to 0.60.7

A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Passwor…

▾ Twilightdgtlmoon · changedetection.ioEPSS 0.44%via NVD
CVE-2026-63278Medium· 6.7
6d ago

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links

URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. The check added for CVE-2024-1242…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.15%via NVD
CVE-2026-63276Medium· 5.4
6d ago

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents

LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and CFF fonts may be embedded in documents. A stack buffer overflow existed in that conversion. The converted operators we…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-87119High· 8.2
6d ago

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id…

Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation credential to charge the payer repeatedly. The payer signs a Tempo KeyAuthorization over the chain id, key type, key id…

▾ TwilightZenHive · mppEPSS 0.57%via NVD
CVE-2026-63273Medium· 5.4
6d ago

LibreOffice Draw can import PDF documents

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The length of the decryption key was taken from the document's own encryption dictionary and was used to fill a fixed size ke…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.11%via NVD
CVE-2026-74849Critical· 9.8
6d ago

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.

▾ MidnightZohocorp · ManageEngine ADSelfService PlusEPSS 4.6%via NVD
CVE-2026-63279Medium· 5.4
6d ago

LibreOffice can import PICT images, which may be embedded in documents

LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an image that uses a colour palette. The palette index held in the image data was used without being checked against the…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-63274Medium· 5.4
6d ago

LibreOffice Draw can import PDF documents

LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of the stream was taken from the object's own dictionary and was not checked against the number of bytes actually presen…

▾ SunlitThe Document Foundation · LibreOfficeEPSS 0.17%via NVD
CVE-2026-89420High· 7.1PoC
6d ago

Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats …

Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obtain paid resources without being charged. MPP.Session.Actions.accept_voucher/3 in lib/mpp/session/actions.ex treats …

▾ MidnightZenHive · mppEPSS 0.47%via NVD
CVE-2026-92882Low· 2.3
6d ago

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read store…

Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an authenticated user who may view a host's configuration to read store…

▾ SunlitCheckmk GmbH · CheckmkEPSS 0.35%via NVD
CVE-2026-90990Medium· 5.3
6d ago

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions i…

Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 allows an authenticated user to inject additional Livestatus query headers, bypassing object visibility restrictions i…

▾ SunlitCheckmk GmbH · CheckmkEPSS 0.42%via NVD
CVE-2026-95623Medium· 5.6
6d ago

The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request

The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the initial request. When the remote server responds with an HTTP 3xx redirect, reqwest follows the redirect internally wit…

▾ SunlitTauri · tauri-plugin-httpEPSS 0.24%via NVD
CVE-2026-94117High· 7.6
6d ago

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: fro…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar – WordPress Notification Bar allows Blind SQL Injection. This issue affects HashBar – WordPress Notification Bar: fro…

▾ TwilightDevItems · hashbar-wp-notification-barEPSS 0.38%via NVD
CVE-2026-90882High· 8.7
6d ago

The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints

The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-Control-Allow-Credentials: true on the authenticated /user/ endpoints. A page on any origin could therefore issue cred…

▾ TwilightEclipse Foundation · open-vsx.orgEPSS 0.44%via NVD
CVE-2026-25262Medium· 6.9PoC
6d ago

Memory corruption while processing a crafted ELF file in the Primary Bootloader.

Memory corruption while processing a crafted ELF file in the Primary Bootloader.

▾ TwilightQualcomm, Inc. · SnapdragonEPSS 0.22%via NVD
CVEs tagged “nvd” — page 90 · VulnSea