VYPR

CVEs

37,387 total · page 11 of 748

  • CVE-2026-88617CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.00

    SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.

  • CVE-2026-79303CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.

  • CVE-2026-63696CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2026-63695CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

  • CVE-2026-61549CriSep 15, 2026
    risk 0.52cvss —epss 0.00

    Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod…

  • CVE-2026-59971CriSep 15, 2026
    risk 0.58cvss 10.0epss 0.00

    MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection,…

  • CVE-2026-55158CriSep 15, 2026
    risk 0.52cvss 9.1epss 0.00

    Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1, src/index.ts builds git checkout, git merge, and git format-patch commands by interpolating the attacker-controlled pull request head.ref value into strings…

  • CVE-2026-46495CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.1, the JMX RMI connector in opendj-server-legacy/src/main/java/org/opends/server/protocols/jmx/RmiConnector.java processes attacker-controlled credential objects before authentication without a restrictive…

  • CVE-2026-39919CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.00

    Ghostscript before 10.08.0 contains a heap-based buffer overflow vulnerability in the JPEG 2000 output adapter (base/sjpx_openjpeg.c) that allows attackers to cause memory corruption by supplying a crafted PDF containing a JPEG 2000 image with mismatched component subsampling…

  • CVE-2026-77179CriSep 15, 2026
    risk 0.61cvss —epss 0.00

    On macOS, the virtio-fs host server used by Docker Sandboxes improperly follows symlinks when reopening an unlinked file from a stored path. A malicious guest can replace a parent directory with a symlink, escape the shared workspace, and read or modify arbitrary host files as…

  • CVE-2026-92079CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92075CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92071CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92066CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92061CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect boundary conditions in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92059CriSep 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Incorrect boundary conditions in the DOM: Editor component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92057CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Enterprise Policies component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92051CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Spoofing issue due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92050CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Sandbox escape due to race condition in the XPConnect component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92048CriSep 15, 2026
    risk 0.59cvss 9.0epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92045CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to incorrect boundary conditions in the WebRTC component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92041CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the DOM: Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92038CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Remote Settings Client component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92037CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect boundary conditions in the DOM: Animation component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92036CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect boundary conditions in the Networking: HTTP component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92035CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

  • CVE-2026-92034CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156 and Thunderbird 156.

  • CVE-2026-92032CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

  • CVE-2026-92018CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 156, Firefox ESR 115.41, Firefox ESR 140.16, Firefox ESR 153.3, Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

  • CVE-2026-91998CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Casdoor through 4.4.0 contains an authorization bypass vulnerability in the /api/mcp endpoint that allows attackers with any application's clientId and clientSecret to gain unrestricted access to user administration across all organizations. Attackers can enumerate user records…

  • CVE-2026-91995CriSep 15, 2026
    risk 0.52cvss 9.1epss 0.01

    pig before 4.1.0 contains an authentication bypass vulnerability in the /register/password endpoint where password verification results are discarded, allowing any value as the current password. Remote attackers can submit a username with an incorrect current password to…

  • CVE-2026-89308CriSep 15, 2026
    risk 0.61cvss —epss 0.03

    An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execute arbitrary commands on the underlying operating system and achieve remote code execution.

  • CVE-2026-57148CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.00

    PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py falls back to the public dev-secret-change-me HS256 signing key when PLATFORM_JWT_SECRET is unset, while the startup and token-issuance guards are disabled because PLATFORM_ENV…

  • CVE-2026-57147CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    PraisonAI is a multi-agent teams system. Prior to 0.1.6, praisonai_platform/services/auth_service.py assigns the public dev-secret-change-me value to JWT_SECRET when PLATFORM_JWT_SECRET is unset, and its production guard does not run when PLATFORM_ENV is also unset because that…

  • CVE-2026-57141CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mode.ts executes model-generated JavaScript with new Function() and with(sandbox), while a regular-expression blocklist can be bypassed with Function('return…

  • CVE-2026-57140CriSep 15, 2026
    risk 0.54cvss 9.4epss 0.00

    PraisonAI is a multi-agent teams system. From 1.6.0 until 1.7.2, AgentOS in src/praisonai-ts/src/os/agentos.ts uses the 0.0.0.0 default from src/praisonai-ts/src/os/config.ts and registers GET /api/agents and POST /api/chat without authentication middleware. A remote caller who…

  • CVE-2026-57139CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.00

    PraisonAI is a multi-agent teams system. From 1.5.0 until 1.7.2, MCPServer.startHttp() in src/praisonai-ts/src/mcp/server.ts binds without a host restriction and forwards every HTTP POST request to handleRequest() without authentication or authorization. Any network client that…

  • CVE-2026-57138CriSep 15, 2026
    risk 0.57cvss 9.9epss 0.00

    PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist plus shadowed process and require…

  • CVE-2026-52824CriSep 15, 2026
    risk 0.52cvss —epss 0.02

    Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as…

  • CVE-2026-62379CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without…

  • CVE-2026-62263CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A…

  • CVE-2026-48717CriSep 15, 2026
    risk 0.52cvss —epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a code_challenge. Because that…

  • CVE-2026-46619CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows…

  • CVE-2026-45052CriSep 15, 2026
    risk 0.53cvss —epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the…

  • CVE-2026-45051CriSep 15, 2026
    risk 0.53cvss —epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the…

  • CVE-2026-90711CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    proxy-addr is a Node.js module that determines a request's client address behind trusted reverse proxies, and it backs Express req.ip and req.ips. In versions 1.1.0 through 2.0.7, a trust subnet written in IPv4-mapped IPv6 notation with an IPv4-sized prefix, such as…

  • CVE-2026-91003CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.01

    A flaw has been found in D-Link DI-8300 16.07. The affected element is the function rzgl_asp of the file /rzgl.asp of the component CGI Service. This manipulation of the argument redirct_url causes stack-based buffer overflow. Remote exploitation of the attack is possible. The…

  • CVE-2026-91001CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    A security flaw has been discovered in D-Link DI-8400 16.07. This affects the function ddns_asp of the file /ddns.asp of the component DDNS Configuration. Performing a manipulation of the argument serv/user/host/wild/mx/bmx/cust/ip results in stack-based buffer overflow. The…

  • CVE-2026-90847CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.02

    A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-12944CriSep 14, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role…