VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25376 CVEsRSS

CVE-2026-67827Critical· 9.8PoC
1w ago

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffm…

Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote Code Execution (RCE) via unauthenticated access to the setServerConfig API endpoint, which permits overwriting the ffm…

▾ AbyssalEPSS 0.75%via NVD
CVE-2026-61647High· 7.1
1w ago

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories

NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content to local vault directories. Versions 1.6.0 through 2.0.2 contain a path traversal vulnerability in the `POST /batch-t…

▾ Twilightroomi-fields · notebooklm-mcpEPSS 0.32%via NVD
CVE-2026-59816Medium· 4.3PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7, the GET /api/transcribe/:id and POST /api/transcribe/:id handlers in packages/server/src/routes/api/transcribe.ts o…

▾ Twilightlaurent22 · joplinEPSS 0.36%via NVD
CVE-2026-55179Medium· 6.5PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /items/:id/content route in packages/server/src/routes/index/items.ts loads item content from a…

▾ Twilightlaurent22 · joplinEPSS 0.26%via NVD
CVE-2026-55105High· 7.7PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, packages/renderer/MdToHtml/rules/fountain.ts passes HTML generated by the vendored fountain.js renderer …

▾ Midnightlaurent22 · joplinEPSS 0.50%via NVD
CVE-2026-49453High· 7.0PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.15 and 3.7.2, Joplin accepts synchronized resource metadata whose id or file_extension contains parent-directory or pa…

▾ Midnightlaurent22 · joplinEPSS 0.41%via NVD
CVE-2026-49450High· 7.1PoC
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Desktop for Windows omits publisherName from packages/app-desktop/package.json, so the generated app-update.…

▾ Midnightlaurent22 · joplinEPSS 0.18%via NVD
CVE-2026-49449Low· 2.5
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 until 3.7.2, packages/renderer/MdToHtml/rules/katex.ts enables KaTeX's trust option for note content, allowing a note au…

▾ Sunlitlaurent22 · joplinEPSS 0.17%via NVD
CVE-2026-46649Critical· 9.1
1w ago

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2, Joplin Server's GET /api/login_with_code/:id endpoint accepts a nine-digit SSO authentication code with a ten-minut…

▾ Midnightlaurent22 · joplinEPSS 0.56%via NVD
CVE-2026-94572Critical· 9.4PoC
1w ago

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control characters. The value is written verbatim into the HAProxy configuration generated on the amphora, and t…

▾ AbyssalOpenStack · OctaviaEPSS 0.53%via NVD
CVE-2026-94571Critical· 9.4
1w ago

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields

In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirect_prefix fields. The RFC 3986 URL validator percent-encodes control characters before validating, …

▾ MidnightOpenStack · OctaviaEPSS 0.53%via NVD
CVE-2026-79317Medium· 4.8
1w ago

A session invalidation flaw exists in x-ui 0.3.2

A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and authentication only checks that a user object can be retrieved from the cookie without re-validating against the databas…

▾ SunlitEPSS 0.29%via NVD
CVE-2026-88746High· 7.1
1w ago

idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.

idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php.

▾ TwilightEPSS 0.25%via NVD
CVE-2026-73553High· 7.5PoC
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, When ignore_path_parameters_in_path_matching is enabled, Envoy's router strips the semicolon suffix befo…

▾ Midnightenvoyproxy · envoyEPSS 0.52%via NVD
CVE-2026-73551Medium· 5.3
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy's URL normalization does not recognize dot and dotdot path segments when they carry semicolon para…

▾ Sunlitenvoyproxy · envoyEPSS 0.55%via NVD
CVE-2026-77519Medium· 5.4PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path looks up an ApplicationApiKey using only its secret and active status, without enforcing the is_permanent and expire_ti…

▾ Twilight1Panel-dev · MaxKBEPSS 0.24%via NVD
CVE-2026-73511Medium· 5.3
1w ago

Envoy is an open source edge and service proxy designed for cloud-native applications

Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4, and 1.39.1, Envoy normally matches the raw request path, while servlet backends such as Apache Tomcat strip semicolo…

▾ Sunlitenvoyproxy · envoyEPSS 0.55%via NVD
CVE-2026-88467None
1w ago

CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of value, causing errors and leaking sensitive information.

▾ SunlitEPSS 0.20%via NVD
CVE-2026-79316High· 7.6
1w ago

An improper access control vulnerability exists in x-ui 0.3.2

An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configuration template through the settings interface and trigger a panel restart, causing the xray management gRPC service, …

▾ TwilightEPSS 0.32%via NVD
CVE-2026-77520Medium· 5.4
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from the homepage application question-ranking endpoint when the published victi…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.23%via NVD
CVE-2026-58272Medium· 5.3PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1 contain an observable timing discrepancy in the login endpoint because authentication attempts for nonexistent accou…

▾ TwilightSync-in · serverEPSS 0.34%via NVD
CVE-2026-58270Medium· 6.5PoC
1w ago

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing

Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0, the sync diff endpoint compiles a user-supplied string into a `RegExp` with no complexity validation. A catastrophic…

▾ TwilightSync-in · serverEPSS 0.35%via NVD
CVE-2026-88745Medium· 6.1
1w ago

EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.

EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.

▾ SunlitEPSS 0.25%via NVD
CVE-2026-79916Critical· 9.1
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /r…

▾ Midnight1Panel-dev · MaxKBEPSS 0.45%via NVD
CVE-2026-88405Critical· 9.8PoC
1w ago

A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-function.service.ts) of Univer v1.0.0-alpha.2 allows attackers to execute arbitrary code via a crafted payload.

▾ AbyssalEPSS 0.75%via NVD
CVE-2026-77518Medium· 5.0PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because …

▾ Twilight1Panel-dev · MaxKBEPSS 0.27%via NVD
CVE-2026-88403Medium· 6.5PoC
1w ago

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to scan internal resources via a crafted HTTP request.

▾ TwilightEPSS 0.40%via NVD
CVE-2026-77525Medium· 4.2PoC
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id and chat_record_id values without confirming that the c…

▾ Twilight1Panel-dev · MaxKBEPSS 0.19%via NVD
CVE-2026-77523High· 7.4
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads and saves a Model by id alone without including wo…

▾ Twilight1Panel-dev · MaxKBEPSS 0.26%via NVD
CVE-2026-77516Medium· 5.4
1w ago

MaxKB is an open-source AI assistant for enterprise

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can still bind its identifier through tool_ids, skill_tool_i…

▾ Sunlit1Panel-dev · MaxKBEPSS 0.28%via NVD
CVEs tagged “nvd” — page 95 · VulnSea