VulnSea

Tagged “nvd”

CVEs tagged nvd, newest first.

25376 CVEsRSS

CVE-2026-61745Medium· 4.3PoC
1w ago

InvenTree is an Open Source Inventory Management System

InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in src/backend/InvenTree/machine/api.py uses IsAuthenticatedOrReadScope without requiring the ADMIN role used by other …

▾ Twilightinventree · InvenTreeEPSS 0.43%via NVD
CVE-2026-55473Medium· 6.0
1w ago

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetadata notifier SSRF protections in backend/internal/sys/validate/notifier_url.go do not inspect IPv4 destinations embedd…

▾ Sunlitsysadminsmedia · homeboxEPSS 0.41%via NVD
CVE-2026-48826High· 8.1
1w ago

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, HandleWipeInventory in backend/app/api/handlers/v1/v1_ctrl_actions.go authorizes POST /v1/actions/wipe-inventory through the global ctx.User.IsOwner value instead of t…

▾ Twilightsysadminsmedia · homeboxEPSS 0.49%via NVD
CVE-2026-62369High· 8.1
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/comm…

▾ Twilightkubeedge · kubeedgeEPSS 0.86%via NVD
CVE-2026-93012Critical· 9.8
1w ago

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipi…

Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipi…

▾ MidnightEPSS 0.60%via NVD
CVE-2026-92382Medium· 4.1
1w ago

An out-of-bounds write flaw was found in usbredir

An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() …

▾ SunlitRed Hat · usbredirEPSS 0.14%via NVD
CVE-2026-94488High· 8.2PoC
1w ago

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. How…

▾ MidnightTelegram · Telegram DesktopEPSS 0.20%via NVD
CVE-2026-61612Medium· 5.7
1w ago

CKAN MCP Server is a tool for querying CKAN open data portals

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerUrl` (added for CVE-2026-33060, extended for CVE-2026-53509) validates only the hostname string and never resolves DNS…

▾ Sunlitondata · ckan-mcp-serverEPSS 0.23%via NVD
CVE-2026-48976High· 8.1
1w ago

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, NotifierRepository.Update in backend/internal/data/repo/repo_notifier.go updates a notifier through UpdateOneID(id) without requiring the record's user ID to match the…

▾ Twilightsysadminsmedia · homeboxEPSS 0.45%via NVD
CVE-2026-62182High· 8.8
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/config…

▾ Twilightkubeedge · kubeedgeEPSS 0.48%via NVD
CVE-2026-48975High· 8.1
1w ago

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, MaintenanceEntryRepository.Update and MaintenanceEntryRepository.Delete in backend/internal/data/repo/repo_maintenance_entry.go use UpdateOneID(id) and DeleteOneID(id)…

▾ Twilightsysadminsmedia · homeboxEPSS 0.49%via NVD
CVE-2026-48974Medium· 5.4
1w ago

HomeBox is a home inventory and organization system

HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberAdd and GroupService.AddMember using a caller-supplied userID without requiring an owner role, an invitation token, ta…

▾ Sunlitsysadminsmedia · homeboxEPSS 0.29%via NVD
CVE-2026-94449High· 7.5
1w ago

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices

A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, …

▾ TwilightRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.49%via NVD
CVE-2026-77561Medium· 5.3PoC
1w ago

Tinyauth is an authentication and authorization server

Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST /api/user/login requests with 257 distinct nonexistent usernames to fill MaxLoginAttemptRecords and activate a globa…

▾ Twilighttinyauthapp · tinyauthEPSS 0.60%via NVD
CVE-2026-63116High· 8.8PoC
1w ago

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale

deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. From 10.1.0 until 10.1.1, src/services/permission/valve/rules-map.ts omits RECORD_ACTION.PATCH_MULTI from RULES_MAP. When…

▾ MidnightdeepstreamIO · deepstream.ioEPSS 0.51%via NVD
CVE-2026-62866Medium· 6.2PoC
1w ago

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.2, selector/lexer/tokenize.go parseCurRune advances the input index across trailing whitespace and then reads the s…

▾ TwilightTomWright · daselEPSS 0.19%via NVD
CVE-2026-62371High· 8.8
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actio…

▾ Twilightkubeedge · kubeedgeEPSS 0.48%via NVD
CVE-2026-62370Medium· 6.5
1w ago

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHea…

▾ Sunlitkubeedge · kubeedgeEPSS 0.50%via NVD
CVE-2026-59168Medium· 6.2
1w ago

Dasel is a command-line tool and library for querying, modifying, and transforming data structures

Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.11.1, parsing/json/json_reader.go decodeValue, decodeObject, and decodeArray, and parsing/xml/reader.go parseElement, …

▾ SunlitTomWright · daselEPSS 0.13%via NVD
CVE-2026-83621High· 8.1
1w ago

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260717, POST /lua/rest/v2/edit/system/edit_blacklist.lua in scripts/lua/rest/v2/edit/system/edit_blacklist.lua lacks an administrator check and calls lists_utils.…

▾ Twilightntop · ntopngEPSS 0.53%via NVD
CVE-2026-84990High· 8.8
1w ago

ntopng is a web-based network traffic monitoring application

ntopng is a web-based network traffic monitoring application. Prior to 6.7.260718, scripts/lua/rest/v2/get/system/configurations/list_available_backups.lua and scripts/lua/rest/v2/get/system/configurations/download_backup.lua allow any a…

▾ Twilightntop · ntopngEPSS 0.46%via NVD
CVE-2026-62987Medium· 5.8PoC
1w ago

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul

Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48865 fix in proxy/http_headers.go uses protectHeaders for a hardcoded set of forwarded headers but omits the operator-…

▾ Twilightfabiolb · fabioEPSS 0.20%via NVD
CVE-2026-61674Critical· 9.2PoC
1w ago

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows

Fluent Bit is a fast and lightweight logs, metrics, and traces processor for Linux, BSD, macOS, and Windows. From 0.11.0 until 5.0.8, plugins/out_forward/forward.c secure_forward_pong copies the server-controlled PONG[2] reason into the …

▾ Abyssalfluent · fluent-bitEPSS 0.85%via NVD
CVE-2026-58504Medium· 6.1
1w ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a crafted .drawio file can execute attacker-controlled JavaScript in the draw.io origin when selected cells are processed …

▾ Sunlitjgraph · drawioEPSS 0.36%via NVD
CVE-2026-63416Low· 3.7PoC
1w ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/online/ExportProxyServlet.java uses request.getPathInfo() to build a proxyPath and appends it directly to EXPORT_URL …

▾ Twilightjgraph · drawioEPSS 0.33%via NVD
CVE-2026-63334Medium· 6.8PoC
1w ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DRAWIO_PROXY=1 are vulnerable to server-side request forgery because src/main/java/com/mxgraph/online/Utils.java perfor…

▾ Twilightjgraph · drawioEPSS 0.32%via NVD
CVE-2026-63373Medium· 4.2PoC
1w ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler in src/main/java/com/mxgraph/online/AbsAuth.java skips comparison of stateToken and cookieToken whenever IS_GAE is f…

▾ Twilightjgraph · drawioEPSS 0.15%via NVD
CVE-2026-76898High· 7.7PoC
1w ago

draw.io is a configurable diagramming and whiteboarding application

draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.3.8, src/main/java/com/mxgraph/online/Utils.java checks IPv6 Unique Local Addresses in Utils.sanitizeUrl() by comparing the text prefixes fc00:: and…

▾ Midnightjgraph · drawioEPSS 0.35%via NVD
CVE-2026-79920Critical· 9.9
1w ago

Ajenti is a Linux & BSD modular server admin panel

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-mana…

▾ Midnightajenti · ajentiEPSS 0.62%via NVD
CVE-2026-17051Medium· 6.0
1w ago

The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose()

The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ipm_event_dispose(). It read the peer-written doorbell register, extracted the payload length with IPC_HEADER_GET_LENGT…

▾ Sunlitzephyrproject · zephyrEPSS 0.11%via NVD
CVEs tagged “nvd” — page 98 · VulnSea