VYPR

CVEs

113,598 total · page 10 of 2,272

  • CVE-2026-55071higAug 12, 2026
    risk 0.38cvss epss

    ## Stata Command Injection via Unsanitized `package` in `ado_package_install` ### Summary The `ado_package_install` MCP tool in `stata-mcp` concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can…

  • CVE-2026-19311HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or delete arbitrary index data via a crafted inline monitor request with unintentional data source and input index parameters.

  • CVE-2026-18952HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user to perform server-side request forgery and read local files via a crafted URL parameter to the threat intel source configuration…

  • CVE-2026-73327HigAug 12, 2026
    risk 0.42cvss 7.6epss 0.01

    Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP…

  • CVE-2026-73298HigAug 12, 2026
    risk 0.57cvss epss 0.01

    The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for moving container service configurations to Azure Kubernetes Service. In version 2.1.2 and earlier, a security vulnerability was…

  • CVE-2026-69106HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

  • CVE-2026-49467HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on…

  • CVE-2026-44741HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's translation grid date filter — the user-supplied `property` field from the filter JSON is interpolated directly into a…

  • CVE-2026-42018HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

  • CVE-2026-18713HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.

  • CVE-2026-18669HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine component. An authenticated attacker can execute a maliciously planted script with root authority.

  • CVE-2026-18235HigAug 12, 2026
    risk 0.54cvss 8.3epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input validation.

  • CVE-2026-17418HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-17271HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.

  • CVE-2026-17248HigAug 12, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper neutralization of special elements in an OS command.

  • CVE-2026-17110HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands and obtain sensitive information due to improper privilege management.

  • CVE-2026-16931HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper handling of zero-length TCP options.

  • CVE-2026-16907HigAug 12, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to improper bounds checking.

  • CVE-2026-16906HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16904HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper privilege management during monitor owner reassignment.

  • CVE-2026-16863HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-of-bounds read.

  • CVE-2026-16856HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16627HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to escalate privileges due to improper sanitization of HTML content rendered in a…

  • CVE-2026-15423HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a…

  • CVE-2026-48554HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.01

    Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macro substitution through the com_data parameter. When a notification command references $NOTIFICATIONCOMMENT$ or…

  • CVE-2026-48553HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.01

    Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection through the Nagios Remote Data Processor (NRDP). When a custom variable defined on a host, service, or contact is referenced in a…

  • CVE-2026-48551HigAug 12, 2026
    risk 0.48cvss 7.4epss 0.00

    Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated…

  • CVE-2026-18847HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.

  • CVE-2026-18683HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user to execute commands.

  • CVE-2026-18499HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.

  • CVE-2026-18098HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XML injection flaw.

  • CVE-2026-17095HigAug 12, 2026
    risk 0.54cvss 8.3epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.

  • CVE-2026-73325HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by supplying a crafted model.pt checkpoint file, as QuantizedModelLoader.load_quantized_model_pt() unconditionally calls torch.load…

  • CVE-2026-73293HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProjectOrGlobalRoleBySlug allow a project manager to use POST /api/project/{id}/roles to create a custom manager role with permission…

  • CVE-2026-73292HigAug 12, 2026
    risk 0.47cvss 8.3epss 0.00

    Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an…

  • CVE-2026-69105HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and availability.

  • CVE-2026-68968HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. The authorization dependency parsed it with `int()` while the route handler parsed it as pydantic's `NonNegativeInt`, which accepts…

  • CVE-2026-68759HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    A holder of a valid integration credential may impersonate other users under specific conditions.

  • CVE-2026-67587HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the stored callback path. Because `SyncCallback` is itself an Airflow class it passes the default `allowed_deserialization_classes`…

  • CVE-2026-67260HigAug 12, 2026
    risk 0.47cvss 7.3epss 0.00

    Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value through the task…

  • CVE-2026-65941HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitrary code in the context of the IIS application service account.

  • CVE-2026-65937HigAug 12, 2026
    risk 0.52cvss 8.0epss 0.00

    In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

  • CVE-2026-58076HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's `executor_config`…

  • CVE-2026-15803HigAug 12, 2026
    risk 0.57cvss epss 0.00

    In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF data or query results, permitting DOCTYPE declarations, external entity references, and external DTD loading. This is due to an…

  • CVE-2026-52776higAug 12, 2026
    risk 0.38cvss epss

    ### Summary `compliance-trestle` 4.0.3 (latest) ships an `URLSecurityValidator` in `trestle/core/remote/security.py` to block SSRF to loopback / link-local / cloud-metadata endpoints from the HTTPSFetcher and SFTPFetcher remote-fetch paths. The allowlist is incomplete and can…

  • CVE-2026-48798higAug 12, 2026
    risk 0.38cvss epss

    ## Summary `ScpClient.Download(string directoryName, DirectoryInfo directoryInfo)` writes files and directories using names returned by the remote SCP server during recursive downloads, with no validation that the resulting path stays inside the requested local directory. A…

  • CVE-2026-73431HigAug 12, 2026
    risk 0.50cvss epss 0.00

    Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the user's login. Although the token signature and age were…

  • CVE-2026-73291HigAug 12, 2026
    risk 0.39cvss 7.1epss 0.00

    Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET…

  • CVE-2026-73289HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using…

  • CVE-2026-73286HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap:…