VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25359 CVEsRSS

CVE-2026-25255High· 8.8
6d ago

Exposed dangerous function lead to privilege escalation via gRPC server.

Exposed dangerous function lead to privilege escalation via gRPC server.

▾ TwilightQualcomm, Inc. · SnapdragonEPSS 0.12%via NVD
CVE-2026-25254Critical· 9.8
6d ago

Improper authorization leads to Remote Code Execution via SocketIO interface.

Improper authorization leads to Remote Code Execution via SocketIO interface.

▾ Midnightqualcomm · software_centerEPSS 0.32%via NVD
CVE-2026-25265High· 8.8
6d ago

Privilege escalation due to weak configuration while temporary file handling.

Privilege escalation due to weak configuration while temporary file handling.

▾ Twilightqualcomm · software_centerEPSS 0.07%via NVD
CVE-2026-25264High· 8.8
6d ago

Privilege escalation due to weak configuration during package extraction process.

Privilege escalation due to weak configuration during package extraction process.

▾ Twilightqualcomm · software_centerEPSS 0.07%via NVD
CVE-2026-93556Critical· 9.3
6d ago

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed

The ‘/password/guardarClau/recover’ endpoint accepts the ‘usuariId’ parameter, which specifies the account whose password is to be changed. The JWT token for the recovery process is not validated against the user specified in that parame…

▾ MidnightKompini · Tankuam PlacesEPSS 0.30%via NVD
CVE-2026-95508High· 7.4
6d ago

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp

A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply bu…

▾ TwilightRed Hat · libslirpEPSS 0.57%via NVD
CVE-2026-15095Medium· 4.9
6d ago

The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter

The Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping & Social Channels plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.6.43 via the 'provider' parameter. This makes…

▾ Sunlitwahid0003 · Product Feed Manager for WooCommerce – CTX Feed – Support 220+ Shopping, AI & Social ChannelsEPSS 1.1%via NVD
CVE-2026-95511High· 8.2PoC
6d ago

Rejected reason: Not a vulnerability

Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.

▾ MidnightRed Hat · cups-filtersEPSS 0.12%via NVD
CVE-2026-68956High· 7.1
6d ago

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The "session" …

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The "session" …

▾ TwilightErlang · otpEPSS 0.66%via NVD
CVE-2026-65634High· 8.2
6d ago

Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder asn1rtt_ber:d…

Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of service by sending a crafted OID during the TLS handshake. The BER OID decoder asn1rtt_ber:d…

▾ TwilightErlang · otpEPSS 0.42%via NVD
CVE-2026-93928High· 7.3
6d ago

Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc

Authentication Bypass Using an Alternate Path or Channel vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Authentication Bypass. This issue affects Taxi Booking Manager for WooCommerce: from n/a before 2.0.8.

▾ TwilightMagepeople inc. · ecab-taxi-booking-managerEPSS 0.40%via NVD
CVE-2026-89422Critical· 9.3
6d ago

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server

Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the intended server. A pre_shared_key extension in the ServerHello that the client never off…

▾ MidnightErlang · otpEPSS 0.64%via NVD
CVE-2026-9231High· 7.5
6d ago

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.8.0 via the wte_get_template function. This makes it possible for auth…

▾ Twilightwptravelengine · WP Travel Engine – Tour Booking Plugin – Tour Operator SoftwareEPSS 0.58%via NVD
CVE-2026-74765Medium· 6.5
6d ago

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a signed in…

Net::IDN::Punycode versions before 2.590 for Perl allow an out-of-bounds read via integer overflow of the delta accumulator in encode_punycode. The XS backend keeps the punycode delta, and the digit index derived from it, in a signed in…

▾ SunlitEPSS 0.52%via NVD
CVE-2026-74766High· 8.4
6d ago

Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buff…

Net::IDN::Punycode versions from 2.301 before 2.590 for Perl allow a heap use-after-free via a decoded code point that reallocates the output buffer in decode_punycode. The XS backend inserts each decoded code point into the string buff…

▾ TwilightEPSS 0.19%via NVD
CVE-2016-15059Critical· 9.8
6d ago

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized …

Net::IDN::Punycode versions before 2.301 for Perl allow a heap buffer overflow via unchecked writes past the output buffer in encode_punycode. The XS backend builds the encoded label in the string buffer of the scalar it returns, sized …

▾ MidnightRed Hat · Net-IDN-EncodeEPSS 0.42%via NVD
CVE-2026-87079High· 7.5
6d ago

Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertio…

Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in decode_punycode. The XS backend inserts each decoded code point into a UTF-8 buffer and finds the insertio…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-87078Critical· 9.1
6d ago

Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the…

Net::IDN::Punycode versions from 2.302 before 2.590 for Perl leak the output buffer on every rejected label in decode_punycode. The XS backend allocates the scalar it returns before it validates the input, sizing the buffer at twice the…

▾ MidnightEPSS 0.65%via NVD
CVE-2026-87081High· 7.5
6d ago

Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte DNS lim…

Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length check in to_ascii. to_ascii punycode encodes each label and only then applies the 63-byte DNS lim…

▾ TwilightEPSS 0.63%via NVD
CVE-2026-87080Critical· 9.1
6d ago

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the…

Net::IDN::Punycode::PP versions before 2.590 for Perl decode a truncated label to a name containing a character it never encoded in decode_punycode. The pure-Perl decoder reads one digit at a time with four-argument substr and tests the…

▾ MidnightEPSS 0.63%via NVD
CVE-2026-93952Critical· 10.0CISA KEV0dayPoC
6d ago

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integ…

▾ Hadalarista · velocloud_orchestratorEPSS 1.1%via NVD
CVE-2026-87082High· 7.5
6d ago

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set ov…

Net::IDN::Punycode versions before 2.590 for Perl hang, crash or return a wrong label via unvalidated malformed UTF-8 in encode_punycode. Neither backend checks that its input is well-formed UTF-8, so a string with the UTF-8 flag set ov…

▾ TwilightEPSS 0.68%via NVD
CVE-2026-16778Medium· 6.4
6d ago

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient in…

The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_module_downloads_output' Shortcode Content in all versions up to, and including, 2.1.21 due to insufficient in…

▾ Sunlitlivecomposer · Live Composer – Free WordPress Website BuilderEPSS 0.22%via NVD
CVE-2026-12995Medium· 4.3
6d ago

The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key

The Custom Field Template plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.7.8 via the edit_meta_value due to missing validation on a user controlled key. This makes it possib…

▾ Sunlithiroaki-miyashita · Custom Field TemplateEPSS 0.21%via NVD
CVE-2026-92969High· 8.1
6d ago

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 via the 'shortcode' parameter parameter

The HUSKY – Products Filter for WooCommerce Professional plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.4 via the 'shortcode' parameter parameter. This makes it possible for unauthent…

▾ Twilightrealmag777 · HUSKY – Products Filter for WooCommerce ProfessionalEPSS 0.65%via NVD
CVE-2025-14486Medium· 5.3
6d ago

The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2

The PixelPlay plugin for WordPress is vulnerable to unauthorized API key deletion due to missing authorization checks in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to delete arbitrary A…

▾ Sunlitkamleshyadav · PixelPlayEPSS 0.23%via NVD
CVE-2026-18439Medium· 4.3
6d ago

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation tha…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 4.0.7 via the tutor_quiz_builder_save AJAX action due to missing validation tha…

▾ Sunlitthemeum · Tutor LMS – eLearning and online course solutionEPSS 0.25%via NVD
CVE-2025-14484Medium· 5.3
6d ago

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3

The Image Buzz plugin for WordPress is vulnerable to unauthorized API key modification due to missing authorization checks in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to modify arbitr…

▾ Sunlitkamleshyadav · Image BuzzEPSS 0.23%via NVD
CVE-2026-91092Medium· 4.3
6d ago

The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5

The wpForo Forum plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possi…

▾ Sunlittomdever · wpForo ForumEPSS 0.39%via NVD
CVE-2026-18345Medium· 4.3
6d ago

The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18

The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is registered on the…

▾ Sunlitwpusermanager · WP User Manager – User Profile Builder & MembershipEPSS 0.20%via NVD
CVEs tagged “nvd” — page 91 · VulnSea