VulnSea

Tagged “score-dispute”

CVEs tagged score-dispute, newest first.

501 CVEsRSS

CVE-2026-15801High· 8.0⚖ disputed
yesterday

A vulnerability was found in CRI-O related to the container checkpoint and restore feature

A vulnerability was found in CRI-O related to the container checkpoint and restore feature. When CRI-O is configured to restore containers from checkpoint archives, insufficient validation of restore metadata may allow a user with suffic…

TwilightRed Hat · cri-oEPSS 0.31%via NVD
CVE-2026-86089High· 7.1⚖ disputed
6d ago

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests

Apache NiFi 2.11.0 supports migrating the contents of a version-controlled Process Group into a Connector using REST API methods that list eligible migration sources and submit migration requests. The framework authorized both methods ag…

Twilightapache · nifiEPSS 0.29%via NVD
CVE-2026-81866Medium· 4.3⚖ disputed
6d ago

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration

Apache NiFi 2.9.0 through 2.11.0 provide Connector configuration update and verification REST API methods that do not enforce authorization checking on Assets and Secrets referenced in proposed configuration. Updating or verifying a Conn…

Sunlitapache · nifiEPSS 0.40%via NVD
CVE-2026-91097Critical· 9.8PoC⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Abyssalhp · linux_imaging_and_printingEPSS 0.67%via NVD
CVE-2026-91099Critical· 9.8⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.33%via NVD
CVE-2026-91100Critical· 9.8⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.25%via NVD
CVE-2026-91101Critical· 9.8⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.29%via NVD
CVE-2026-91102Critical· 9.8⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.25%via NVD
CVE-2026-91103Critical· 9.8⚖ disputed
6d ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

Midnighthp · linux_imaging_and_printingEPSS 0.29%via NVD
CVE-2026-85387High· 7.1⚖ disputed
6d ago

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to

Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-check the state of the account the token had been issued to. The resource server's authorization validator confirmed only that a t…

Twilightconcretecms · concrete_cmsEPSS 0.21%via NVD
CVE-2026-92365Medium· 4.3⚖ disputed
6d ago

A vulnerability was found in vllm-project vllm up to 0.29.0

A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the file vllm/v1/sample/thinking_budget_state.py. The manipulation results in inefficient algorithmic complexity. It is …

Sunlitvllm-project · vllmEPSS 0.39%via NVD
CVE-2026-92220Medium· 5.3⚖ disputed
6d ago

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0

A vulnerability was found in vllm-project vLLM 0.26.0/0.27.0. Affected is the function MoRIIOConnectorScheduler.request_finished/MoRIIOConnectorWorker.get_finished/MoRIIOWrapper._handle_release_message of the file vllm/distributed/kv_tra…

Sunlitvllm-project · vLLMEPSS 0.52%via NVD
CVE-2026-91747Low· 3.1⚖ disputed
1w ago

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page

Use after free in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-91746Medium· 4.3⚖ disputed
1w ago

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Integer overflow in Compositing in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91740Medium· 4.3⚖ disputed
1w ago

Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page

Uninitialized resource in Skia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.25%via NVD
CVE-2026-91732High· 8.1⚖ disputed
1w ago

Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page

Missing authorization in AppManifest in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromi…

Twilightgoogle · chromeEPSS 0.24%via NVD
CVE-2026-91730Low· 3.1⚖ disputed
1w ago

Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page

Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium…

Sunlitgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91726Medium· 4.7⚖ disputed
1w ago

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page

Out of bounds read in WebGL in Google Chrome on on Android prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Sunlitgoogle · chromeEPSS 0.27%via NVD
CVE-2026-91723Low· 3.1⚖ disputed
1w ago

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page

Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Sunlitgoogle · chromeEPSS 0.17%via NVD
CVE-2026-91720Medium· 4.7⚖ disputed
1w ago

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page

Uninitialized resource in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.28%via NVD
CVE-2026-91719High· 8.1⚖ disputed
1w ago

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page

Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

Twilightgoogle · chromeEPSS 0.23%via NVD
CVE-2026-91708Low· 3.1⚖ disputed
1w ago

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page

Race condition in Network in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

Sunlitgoogle · chromeEPSS 0.16%via NVD
CVE-2026-81926Medium· 6.1⚖ disputed
1w ago

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog

Concrete CMS 9.4.0 through 9.5.2 did not escape colliding page paths before rendering them in the location panel's duplicate-path confirmation dialog. The panel's check endpoint returned the submitted path unmodified in its JSON response…

Sunlitconcretecms · concrete_cmsEPSS 0.35%via NVD
CVE-2026-18426Medium· 6.5⚖ disputed
1w ago

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation

Concrete CMS 9.0.0 through 9.5.2 did not enforce a block-level edit-permission check on the Express Form block's control-management actions, which relied solely on CSRF token validation. Because the token is bound to the user and action …

Sunlitconcretecms · concrete_cmsEPSS 0.26%via NVD
CVE-2026-81927Medium· 5.4⚖ disputed
1w ago

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling

Concrete CMS before 9.5.3 contained a stored cross-site scripting vulnerability in SVG file handling. When SVG processing was set to the non-default "Reject files containing potentially harmful elements" mode (concrete.file_manager.image…

Sunlitconcretecms · concrete_cmsEPSS 0.17%via NVD
CVE-2026-81925Medium· 6.1⚖ disputed
1w ago

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting

Concrete CMS before 9.5.3 improperly neutralized a user-supplied custom date format when rendering conversation messages, resulting in reflected cross-site scripting. An attacker could execute arbitrary JavaScript in the browser of a use…

Sunlitconcretecms · concrete_cmsEPSS 0.41%via NVD
CVE-2026-18424High· 7.1⚖ disputed
1w ago

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin

Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retain…

Twilightconcretecms · concrete_cmsEPSS 0.33%via NVD
CVE-2026-18422Medium· 6.5⚖ disputed
1w ago

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign)

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user…

Sunlitconcretecms · concrete_cmsEPSS 0.42%via NVD
CVE-2026-18423High· 7.1⚖ disputed
1w ago

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could t…

Twilightconcretecms · concrete_cmsEPSS 0.32%via NVD
CVE-2026-81924Medium· 6.5⚖ disputed
1w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-suppl…

Sunlitconcretecms · concrete_cmsEPSS 0.20%via NVD
CVEs tagged “score-dispute” · VulnSea