Search: "sun"

1458 CVEs found

CVE-2026-24994
5.3 MEDIUM

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Pho...

Published: 2026-02-03
Products: 0
CVE-2026-23086
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: cap TX credit to local buffer size The virtio transports derives its TX credit directly from peer_buf_alloc, which i...

Published: 2026-02-04
Products: 10
Vendors:
linux

An issue in Sunbird-Ed SunbirdEd-portal v1.13.4 allows attackers to obtain sensitive information. The application disables TLS/SSL certificate validation by setting 'rejectUnauthorized': false in HTTP...

Published: 2026-02-11
Products: 1
Vendors:
sunbird
CVE-2026-23219
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: mm/slab: Add alloc_tagging_slab_free_hook for memcg_alloc_abort_single When CONFIG_MEM_ALLOC_PROFILING_DEBUG is enabled, the follo...

Published: 2026-02-18
Products: 10
Vendors:
linux
CVE-2025-67973
6.5 MEDIUM

Missing Authorization vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sunshine Pho...

Published: 2026-02-20
Products: 0
CVE-2026-25897
6.5 MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, an Integer Overflow vulnerability exists in the sun decoder. On...

Published: 2026-02-24
Products: 2
Vendors:
imagemagick
CVE-2025-70033
5.4 MEDIUM

An issue pertaining to CWE-79: Improper Neutralization of Input During Web Page Generation was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Published: 2026-03-09
Products: 1
Vendors:
sunbird
CVE-2025-70032
6.1 MEDIUM

An issue pertaining to CWE-601: URL Redirection to Untrusted Site was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Published: 2026-03-09
Products: 1
Vendors:
sunbird

An issue pertaining to CWE-1333: Inefficient Regular Expression Complexity (4.19) was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Published: 2026-03-09
Products: 1
Vendors:
sunbird

An issue pertaining to CWE-352: Cross-Site Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Published: 2026-03-09
Products: 1
Vendors:
sunbird

An issue pertaining to CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4.

Published: 2026-03-09
Products: 1
Vendors:
sunbird

An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in Sunbird-Ed SunbirdEd-portal v1.13.4. This allows attackers to obtain sensitive information

Published: 2026-03-11
Products: 1
Vendors:
sunbird

In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix cache_request leak in cache_release When a reader's file descriptor is closed while in the middle of reading a cache_r...

Published: 2026-04-03
Products: 0
CVE-2026-39564
5.3 MEDIUM

Insertion of Sensitive Information Into Sent Data vulnerability in sunshinephotocart Sunshine Photo Cart sunshine-photo-cart allows Retrieve Embedded Sensitive Data.This issue affects Sunshine Photo C...

Published: 2026-04-08
Products: 0
CVE-2026-21726
5.3 MEDIUM

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/r...

Published: 2026-04-15
Products: 1
Vendors:
grafana

A security vulnerability has been detected in Sunwood-ai-labs command-executor-mcp-server up to 0.1.0. This impacts the function execute_command of the file src/index.ts of the component MCP Interface...

Published: 2026-05-01
Products: 0

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

Published: 2026-05-02
Products: 0

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution ...

Published: 2026-05-02
Products: 0