VYPR

CVEs

1,665 total · page 3 of 34

  • CVE-2025-68686MedKEVFeb 10, 2026
    risk 0.50cvss 5.9epss 0.01

    An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions may allow a remote…

  • CVE-2026-1731CriKEVFeb 6, 2026
    risk 0.92cvss 9.8epss 0.88

    BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating…

  • CVE-2026-21643CriKEVFeb 6, 2026
    risk 0.83cvss 9.8epss 0.94

    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

  • CVE-2025-15556HigKEVFeb 3, 2026
    risk 0.12cvss 7.5epss 0.01

    Notepad++ versions prior to 8.8.9, when using the WinGUp updater, contain an update integrity verification vulnerability where downloaded update metadata and installers are not cryptographically verified. An attacker able to intercept or redirect update traffic can cause the…

  • CVE-2026-1340CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.84

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2026-1281CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.82

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2025-40551CriKEVJan 28, 2026
    risk 0.85cvss 9.8epss 0.84

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

  • CVE-2025-40536HigKEVJan 28, 2026
    risk 0.74cvss 8.1epss 0.72

    SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain restricted functionality.

  • CVE-2026-24858CriKEVJan 27, 2026
    risk 0.83cvss 9.8epss 0.86

    An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through…

  • CVE-2026-21509HigKEVJan 26, 2026
    risk 0.68cvss 7.8epss 0.72

    Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-24423CriKEVJan 23, 2026
    risk 0.89cvss 9.8epss 0.88

    SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API method. The attacker could point the SmarterMail to the malicious HTTP server, which serves the malicious OS command. This command will be…

  • CVE-2026-0770CriKEVJan 23, 2026
    risk 0.83cvss 9.8epss 0.57

    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this…

  • CVE-2026-23760CriKEVJan 22, 2026
    risk 0.89cvss 9.8epss 0.96

    SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system…

  • CVE-2026-20045HigKEVJan 21, 2026
    risk 0.66cvss 8.2epss 0.04

    A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex…

  • CVE-2026-24061CriKEVJan 21, 2026
    risk 0.80cvss 9.8epss 0.98

    telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

  • CVE-2026-20963CriKEVJan 13, 2026
    risk 0.78cvss 9.8epss 0.32

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

  • CVE-2026-20805MedKEVJan 13, 2026
    risk 0.48cvss 5.5epss 0.05

    Exposure of sensitive information to an unauthorized actor in Desktop Windows Manager allows an authorized attacker to disclose information locally.

  • CVE-2025-66376HigKEVJan 5, 2026
    risk 0.53cvss 7.2epss 0.22

    Zimbra Collaboration (ZCS) 10 before 10.0.18 and 10.1 before 10.1.13 allows Classic UI stored XSS via Cascading Style Sheets (CSS) @import directives in an HTML e-mail message.

  • CVE-2025-52691CriKEVDec 29, 2025
    risk 0.93cvss 10.0epss 0.85

    Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution.

  • CVE-2025-68645HigKEVDec 22, 2025
    risk 0.65cvss 8.8epss 0.32

    A Local File Inclusion (LFI) vulnerability exists in the Webmail Classic UI of Zimbra Collaboration (ZCS) 10.0 and 10.1 because of improper handling of user-supplied request parameters in the RestFilter servlet. An unauthenticated remote attacker can craft requests to the…

  • CVE-2025-68613CriKEVDec 19, 2025
    risk 0.80cvss 9.9epss 0.98

    n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their workflow expression evaluation system. Under certain conditions, expressions…

  • CVE-2025-14847HigKEVDec 19, 2025
    risk 0.63cvss 7.5epss 0.83

    Mismatched length fields in Zlib compressed protocol headers may allow a read of uninitialized heap memory by an unauthenticated client. This issue affects all MongoDB Server v7.0 prior to 7.0.28 versions, MongoDB Server v8.0 versions prior to 8.0.17, MongoDB Server v8.2…

  • CVE-2025-14733CriKEVDec 19, 2025
    risk 0.77cvss 9.8epss 0.26

    An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a…

  • CVE-2025-40602MedKEVDec 18, 2025
    risk 0.55cvss 6.6epss 0.02

    A local privilege escalation vulnerability due to insufficient authorization in the SonicWall SMA1000 appliance management console (AMC).

  • CVE-2025-68461HigKEVDec 18, 2025
    risk 0.14cvss 7.2epss 0.21

    Roundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is prone to a Cross-Site-Scripting (XSS) vulnerability via the animate tag in an SVG document.

  • CVE-2025-43529HigKEVDec 17, 2025
    risk 0.70cvss 8.8epss 0.09

    A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.2, iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2, tvOS 26.2, visionOS 26.2, watchOS 26.2. Processing maliciously crafted web content may lead to…

  • CVE-2025-20393CriKEVDec 17, 2025
    risk 0.79cvss 10.0epss 0.30

    A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to execute arbitrary system commands on an affected device with root privileges. This…

  • CVE-2025-59374CriKEVDec 17, 2025
    risk 0.76cvss 9.8epss 0.01

    "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended…

  • CVE-2025-37164CriKEVDec 16, 2025
    risk 0.87cvss 10.0epss 0.90

    A remote code execution issue exists in HPE OneView.

  • CVE-2025-43520MedKEVDec 12, 2025
    risk 0.48cvss 5.5epss 0.00

    A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application may…

  • CVE-2025-43510HigKEVDec 12, 2025
    risk 0.63cvss 7.8epss 0.00

    A memory corruption issue was addressed with improved lock state checking. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1. A malicious application…

  • CVE-2025-14611CriKEVDec 12, 2025
    risk 0.83cvss 9.8epss 0.53

    Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a…

  • CVE-2025-14174HigKEVDec 12, 2025
    risk 0.71cvss 8.8epss 0.23

    Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 143.0.7499.110 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-8110HigKEVDec 10, 2025
    risk 0.69cvss 8.8epss 0.83

    Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

  • CVE-2025-62221HigKEVDec 9, 2025
    risk 0.63cvss 7.8epss 0.02

    Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-59718CriKEVDec 9, 2025
    risk 0.81cvss 9.8epss 0.63

    A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0…

  • CVE-2025-48633MedKEVDec 8, 2025
    risk 0.48cvss 5.5epss 0.00

    In hasAccountsOnAnyUser of DevicePolicyManagerService.java, there is a possible way to add a Device Owner after provisioning due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…

  • CVE-2025-48572HigKEVDec 8, 2025
    risk 0.63cvss 7.8epss 0.00

    In multiple locations, there is a possible way to launch activities from the background due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-34291HigKEVDec 5, 2025
    risk 0.69cvss 8.8epss 0.84

    Langflow versions up to and including 1.6.9 contain a chained vulnerability that enables account takeover and remote code execution. An overly permissive CORS configuration (allow_origins='*' with allow_credentials=True) combined with a refresh token cookie configured as…

  • CVE-2025-66644HigKEVDec 5, 2025
    risk 0.59cvss 7.2epss 0.03

    Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.

  • CVE-2025-55182CriKEVDec 3, 2025
    risk 0.87cvss 10.0epss 1.00

    A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code…

  • CVE-2025-58360HigKEVNov 25, 2025
    risk 0.74cvss 8.2epss 0.65

    GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms…

  • CVE-2025-58034HigKEVNov 18, 2025
    risk 0.66cvss 7.2epss 0.56

    An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0…

  • CVE-2025-13223HigKEVNov 17, 2025
    risk 0.70cvss 8.8epss 0.05

    Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-64446CriKEVNov 14, 2025
    risk 0.86cvss 9.8epss 0.92

    A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via…

  • CVE-2025-62215HigKEVNov 11, 2025
    risk 0.61cvss 7.0epss 0.06

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2025-60710HigKEVNov 11, 2025
    risk 0.63cvss 7.8epss 0.05

    Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

  • CVE-2025-12480CriKEVNov 10, 2025
    risk 0.78cvss 9.1epss 0.91

    Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to initial setup pages even after setup is complete.

  • CVE-2025-64328HigKEVNov 7, 2025
    risk 0.62cvss 7.2epss 0.85

    FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known…

  • CVE-2023-43000HigKEVNov 5, 2025
    risk 0.70cvss 8.8epss 0.04

    A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, Safari 16.6, iOS 15.8.7 and iPadOS 15.8.7. Processing maliciously crafted web content may lead to memory corruption.