VulnSea

Tagged “vex”

CVEs tagged vex, newest first.

2912 CVEsRSS

CVE-2026-91098Critical· 9.8
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Midnighthp · linux_imaging_and_printingEPSS 1.0%via NVD
CVE-2026-91100Critical· 9.8⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Midnighthp · linux_imaging_and_printingEPSS 0.72%via NVD
CVE-2026-91101Critical· 9.8⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Midnighthp · linux_imaging_and_printingEPSS 0.97%via NVD
CVE-2026-91102Critical· 9.8⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Midnighthp · linux_imaging_and_printingEPSS 0.79%via NVD
CVE-2026-91105Critical· 9.8
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Midnighthp · linux_imaging_and_printingEPSS 1.0%via NVD
CVE-2026-91103Critical· 9.8⚖ disputed
1w ago

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, inf…

▾ Midnighthp · linux_imaging_and_printingEPSS 0.97%via NVD
CVE-2026-92718High· 7.3PoC
1w ago

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums

Nuclei versions before 3.11.1 cache template signature verification based only on file modification time without content checksums. Attackers can replace verified templates with unsigned malicious content and restore the original modific…

▾ Midnightprojectdiscovery · nucleiEPSS 0.12%via NVD
CVE-2026-92413Medium· 4.3PoC
1w ago

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9

A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation ca…

▾ TwilightArtifex · MuPDFEPSS 0.59%via NVD
CVE-2026-69147Medium· 6.5PoC
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards …

▾ Twilightvllm-project · vllmEPSS 0.55%via NVD
CVE-2026-42784High· 7.4
1w ago

A flaw was found in sequoia-openpgp

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an at…

▾ TwilightRed Hat · rust-podman-sequoia-mainEPSS 0.20%via NVD
CVE-2026-59944Medium· 6.1
1w ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and from 2.3.0 until 2.10.3, a malicious or compromised dependency can bypass the earlier CVE-2026-59946 binary-path hardening because Composer validates litera…

▾ Sunlitcomposer · composerEPSS 0.32%via NVD
CVE-2026-85732Medium· 4.7PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, the parseLink function in registry/remote/utils.go accepts an absolute URL from a registry-controlled Link response header without validating its scheme, host, or port. …

▾ Twilightoras-project · oras-goEPSS 0.35%via NVD
CVE-2026-85731High· 8.8PoC
1w ago

oras-go is a Go library for managing OCI artifacts

oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, content/file.Store extraction of OCI layers marked with io.deis.oras.content.unpack=true can write outside the store working directory. The pushDir path through extractT…

▾ Midnightoras-project · oras-goEPSS 0.63%via NVD
CVE-2026-57173Medium· 6.5
1w ago

vLLM is an inference and serving engine for large language models

vLLM is an inference and serving engine for large language models. Prior to 0.24.0, the input_audio handling path for /v1/chat/completions calls AudioMediaIO.load_bytes or AudioMediaIO.load_file without passing VLLM_MAX_AUDIO_DECODE_DURA…

▾ Sunlitvllm-project · vllmEPSS 0.69%via NVD
CVE-2026-92615Medium· 6.6
1w ago

A flaw was found in flightctl

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates)…

▾ SunlitRed Hat · flightctlEPSS 0.15%via NVD
CVE-2026-17526High· 7.2
1w ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-19607Medium· 5.3
1w ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-92627Medium· 4.6
1w ago

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc()…

▾ SunlitThe HDF Group · HDF5EPSS 0.23%via NVD
CVE-2026-80274High· 7.5
1w ago

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an un…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-76163High· 7.5
1w ago

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 ver…

▾ TwilightISC · BIND 9EPSS 0.67%via NVD
CVE-2026-61709Medium· 5.3
1w ago

OpenFGA is an authorization and permission engine built for developers

OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return a user that should have been excluded when an authorization relation used an intersection containing a base but not e…

▾ Sunlitopenfga · openfgaEPSS 0.35%via NVD
CVE-2026-19666High· 7.5
1w ago

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

On a resolver configured to use ``dns64``, if an applicable answer from the authoritative server is malformed in a specific way, the resolver `named` process will exit unexpectedly. This issue affects BIND 9 versions 9.11.0 through 9.18.…

▾ TwilightISC · BIND 9EPSS 0.57%via NVD
CVE-2026-19033Medium· 6.5
1w ago

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives

For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer before the final message with the TSIG signature arrives. This could allow an attacker that does not actually possess…

▾ SunlitISC · BIND 9EPSS 0.24%via NVD
CVE-2026-19668Medium· 5.3
1w ago

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record

A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular kind of invalid DNSSEC record. Default limits on "max-records-per-type" and "max-types-per-name" help mitigate the ex…

▾ SunlitISC · BIND 9EPSS 0.47%via NVD
CVE-2026-77119Medium· 5.9
1w ago

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure delegation and letting a forged unsigned answer through. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0…

▾ SunlitISC · BIND 9EPSS 0.23%via NVD
CVE-2026-75029Medium· 5.3
1w ago

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record)

In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SOA record). If the RDATA is the same on all the copies, the record is appended to the in-memory RDATA set, which can c…

▾ SunlitISC · BIND 9EPSS 0.71%via NVD
CVE-2026-77407High· 7.0
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, PlainAuth values defined in auth.go retain passwords as exported plaintext fields in Connection.Config.SASL after a successful PLAIN authentication handshake. The Connection…

▾ Twilightrabbitmq · amqp091-goEPSS 0.13%via NVD
CVE-2026-77406High· 8.2
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.Qos in channel.go accepts negative prefetchCount and prefetchSize integers and casts them directly to uint16 and uint32 fields in the basic.qos method because valida…

▾ Twilightrabbitmq · amqp091-goEPSS 0.41%via NVD
CVE-2026-77403High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Connection.openTune in connection.go accepts a server-advertised FrameMax below the AMQP frameMinSize value of 4096 bytes because the connection negotiation loop does not en…

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVE-2026-77410High· 8.9
1w ago

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client

RabbitMQ amqp091-go is a Go AMQP 0.9.1 client. Prior to 1.13.0, Channel.recvContent in channel.go preallocates the message body slice with the uint64 ch.header.Size value supplied by an AMQP content header without capping the allocation …

▾ Twilightrabbitmq · amqp091-goEPSS 0.52%via NVD
CVEs tagged “vex” — page 15 · VulnSea