VulnSea

Tagged “score-dispute”

CVEs tagged score-dispute, newest first.

589 CVEsRSS

CVE-2026-18422Medium· 6.5⚖ disputed
1w ago

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign)

Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.44%via NVD
CVE-2026-18423High· 7.1⚖ disputed
1w ago

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs

Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could t…

▾ Twilightconcretecms · concrete_cmsEPSS 0.25%via NVD
CVE-2026-81924Medium· 6.5⚖ disputed
1w ago

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature

Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-suppl…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.21%via NVD
CVE-2026-81921Medium· 5.4⚖ disputed
1w ago

Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status

Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status. …

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81920Medium· 4.3⚖ disputed
1w ago

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page

Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did no…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.18%via NVD
CVE-2026-81919Medium· 4.3⚖ disputed
1w ago

Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks)

Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization but performed no…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.15%via NVD
CVE-2026-81897Medium· 5.4⚖ disputed
1w ago

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token

In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote a…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.17%via NVD
CVE-2026-81896Medium· 5.4⚖ disputed
1w ago

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2026-81894Medium· 5.4⚖ disputed
1w ago

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-pa…

▾ Sunlitconcretecms · concrete_cmsEPSS 0.24%via NVD
CVE-2024-14029High· 7.5PoC⚖ disputed
1w ago

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request

Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deploye…

▾ Midnighttornadoweb · tornadoEPSS 0.35%via NVD
CVE-2026-91963Medium· 6.5PoC⚖ disputed
1w ago

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client…

▾ Twilightfreerdp · freerdpEPSS 0.60%via NVD
CVE-2026-39919Critical· 9.8⚖ disputed
1w ago

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 imag…

Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 imag…

▾ MidnightArtifex Software · GhostscriptEPSS 0.55%via NVD
CVE-2026-92079Critical· 9.1⚖ disputed
1w ago

Mitigation bypass in the Widget: Win32 component

Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.50%via NVD
CVE-2026-92078Medium· 6.5⚖ disputed
1w ago

Denial-of-service in the Security component

Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.42%via NVD
CVE-2026-92077Medium· 6.5⚖ disputed
1w ago

Denial-of-service in the SVG component

Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.42%via NVD
CVE-2026-92076High· 8.8⚖ disputed
1w ago

Incorrect boundary conditions in the Networking component

Incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.16%via NVD
CVE-2026-92075Critical· 9.1⚖ disputed
1w ago

Mitigation bypass in the Networking component

Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.50%via NVD
CVE-2026-92074High· 8.8⚖ disputed
1w ago

Mitigation bypass in the Popup Blocker component

Mitigation bypass in the Popup Blocker component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.17%via NVD
CVE-2026-92005Medium· 5.3⚖ disputed
1w ago

Use-after-free in the Audio/Video: Web Codecs component

Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ SunlitMozilla · FirefoxEPSS 0.38%via NVD
CVE-2026-92018Critical· 9.6⚖ disputed
1w ago

Sandbox escape in the DOM: Core & HTML component

Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.35%via NVD
CVE-2026-92032Critical· 9.6⚖ disputed
1w ago

Sandbox escape due to invalid pointer in the Graphics component

Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.34%via NVD
CVE-2026-92036Critical· 9.8⚖ disputed
1w ago

Incorrect boundary conditions in the Networking: HTTP component

Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

▾ MidnightMozilla · FirefoxEPSS 0.59%via NVD
CVE-2026-92035Critical· 9.6⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Graphics component

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.48%via NVD
CVE-2026-92037Critical· 9.8⚖ disputed
1w ago

Incorrect boundary conditions in the DOM: Animation component

Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

▾ MidnightMozilla · FirefoxEPSS 0.59%via NVD
CVE-2026-92041Critical· 9.1⚖ disputed
1w ago

Mitigation bypass in the DOM: Networking component

Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.50%via NVD
CVE-2026-92040High· 8.8⚖ disputed
1w ago

Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

▾ TwilightMozilla · FirefoxEPSS 0.45%via NVD
CVE-2026-92045Critical· 9.6⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the WebRTC component

Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.48%via NVD
CVE-2026-92043High· 8.8⚖ disputed
1w ago

Privilege escalation due to incorrect boundary conditions in the Audio/Video component

Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.48%via NVD
CVE-2026-92048Critical· 9.0⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ MidnightMozilla · FirefoxEPSS 0.43%via NVD
CVE-2026-92047High· 8.8⚖ disputed
1w ago

Privilege escalation in the Crash Reporting component

Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

▾ TwilightMozilla · FirefoxEPSS 0.44%via NVD
CVEs tagged “score-dispute” — page 3 · VulnSea