VYPR

CVEs

113,601 total · page 11 of 2,273

  • CVE-2026-73291HigAug 12, 2026
    risk 0.39cvss 7.1epss 0.00

    Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET…

  • CVE-2026-73289HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using…

  • CVE-2026-73286HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap:…

  • CVE-2026-73285HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,…

  • CVE-2026-73284HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and…

  • CVE-2026-73264HigAug 12, 2026
    risk 0.42cvss 7.6epss 0.00

    Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST…

  • CVE-2026-68757HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    A user with access to a valid SAML response may impersonate another user under specific conditions.

  • CVE-2026-68752HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    A Project Resource Manager may gain broader administrative privileges under specific conditions.

  • CVE-2026-66375HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

  • CVE-2026-14478HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

  • CVE-2025-59323HigAug 12, 2026
    risk 0.55cvss 8.4epss 0.00

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for…

  • CVE-2025-59322HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.

  • CVE-2025-59319HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to certify the integrity of the intended boot partition and selects the first partition index matching a hardcoded type value. A crafted Linux partition could be inserted ahead of this intended target, allowing for…

  • CVE-2026-46369higAug 12, 2026
    risk 0.38cvss epss

    ### Impact The validity store treats a transaction with stored `block_number = X` as "in window" only when `X > last_bn - transaction_validity_window_blocks` (strict inequality). However the protocol's `Transaction::is_valid_at` accepts a transaction for inclusion in any block…

  • CVE-2026-35445higAug 12, 2026
    risk 0.38cvss epss

    ### Impact Affected versions of Winter CMS did not validate the handler name submitted through the form postback mechanism (`_handler` POST field) in the same way as AJAX requests (`X_WINTER_REQUEST_HANDLER` header). The AJAX path validates that handler names match the…

  • CVE-2026-32258higAug 12, 2026
    risk 0.38cvss epss

    ### Impact Authenticated Backend Users with the…

  • CVE-2026-32257higAug 12, 2026
    risk 0.38cvss epss

    ### Impact Users with the `backend.manage_branding` ("Customize the back-end") permission can provide custom CSS through **Settings → Customize Backend → Styles** that is…

  • CVE-2026-47231HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/documents-files.php` gates state-changing modes by checking that the actor has `hasUploadRight()` on the URL parameter `folder_uuid`. The `move_save` handler then operates on a *separate* URL…

  • CVE-2025-59327HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

  • CVE-2026-70468HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.01

    A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9…

  • CVE-2026-57858HigAug 12, 2026
    risk 0.58cvss 8.9epss 0.00

    Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows authenticated event owners to inject arbitrary JavaScript by supplying a malicious analytics tracking ID without sanitization.…

  • CVE-2026-53996HigAug 12, 2026
    risk 0.45cvss 7.0epss 0.00

    NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an access check on /dev/hdaudioN…

  • CVE-2026-70465HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.01

    A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS responses to the targeted…

  • CVE-2026-11325HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execution issue in `src/index.ts` reachable from certain GitHub Actions workflow configurations. Successful exploitation may expose…

  • CVE-2026-19566HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `'1' x ($width +…

  • CVE-2026-19426HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.00

    POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the system.

  • CVE-2025-41770HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt access via the client application. Successful exploitation prevents communication until the PLCnext service is manually restarted.

  • CVE-2026-19594HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation through two related weaknesses: path traversal (CWE-22) via unencoded `..` identifier path segments, and HTTP parameter pollution…

  • CVE-2026-18789HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as…

  • CVE-2026-18474HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when a non-default search field type is configured.

  • CVE-2026-18230HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL statement through one of its authenticated AJAX actions, which lacks an authorization check, allowing any authenticated user such as a Subscriber to perform SQL…

  • CVE-2026-18057HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The Events Manager WordPress plugin before 7.4.1 does not sanitise and escape a user-controlled value before using it in a SQL statement, allowing users with a subscriber account and above to perform SQL injection attacks and tamper with booking consent records belonging to…

  • CVE-2026-18049HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public endpoint actions and builds an option name from a client-supplied value without restricting it to its own options, allowing unauthenticated users to…

  • CVE-2026-18048HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not validate a client-controlled value used to build a file path in one of its public endpoint actions, and performs no authorisation check on it, allowing unauthenticated attackers to delete arbitrary ZIP archives…

  • CVE-2026-16977HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.

  • CVE-2026-16294HigAug 12, 2026
    risk 0.46cvss 7.1epss 0.00

    The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.1 does not validate one of its Podcast Episode URL settings before performing a server-side request with it, allowing users with a role as low as Contributor to perform Server-Side Request Forgery attacks…

  • CVE-2026-16253HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Total Upkeep WordPress plugin before 1.17.3 does not adequately protect the secret that authorizes its backup-restore functionality and exposes it to unauthenticated users, allowing them to disclose sensitive backup information and to force a full site restore that…

  • CVE-2026-14925HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The Import WP WordPress plugin before 2.14.23 does not perform any authorization check on one of its export-file download handlers, allowing unauthenticated attackers to download export files generated by administrators, which may contain user personal data such as email…

  • CVE-2026-13613HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.

  • CVE-2026-13171HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.00

    The Eventin WordPress plugin before 4.1.20 does not perform an authorization check on its waiting-list registration handler, allowing unauthenticated users to create WordPress user accounts for arbitrary email addresses and inject order records.

  • CVE-2026-64954HigAug 12, 2026
    risk 0.46cvss 8.2epss 0.00

    Velociraptor allows scheduling new collections via VQL queries in notebooks. For a user to schedule a new collection, they require the COLLECT_CLIENT permission. However, this is not enforced when the user can run a VQL query which resets the authorization provider. This allows…

  • CVE-2026-12234HigAug 12, 2026
    risk 0.44cvss 7.8epss 0.00

    The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsock_recvmsg() in subsys/net/lib/sockets/sockets.c snapshot the caller-supplied struct net_msghdr into a kernel-side copy with k_usermode_from_copy(), but then re-read the still-live user struct for subsequent…

  • CVE-2026-18961HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified…

  • CVE-2026-73122HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromised agent from a managed cluster to gain unauthorized access to sensitive information. Specifically, the agent can read all Secrets…

  • CVE-2026-66878HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subscription resources, can exploit this vulnerability. By manipulating the Channel.Spec.SecretRef.Namespace field, the user can cause…

  • CVE-2026-6484HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.00

    In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution.

  • CVE-2026-68447HigAug 12, 2026
    risk 0.39cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size CRIU checkpoint copies the MQD control stack using cp_hqd_cntl_stack_size from hardware without bounding it to the allocated BO region. If the…

  • CVE-2026-68446HigAug 12, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from userspace and should be validated against specific limits depending on which Shader Model (SM) is available.

  • CVE-2026-68445HigAug 12, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming writable vc4_gem_object_mmap() rejects a writable mapping of a validated shader BO, but leaves VM_MAYWRITE set. Userspace can map the BO read-only and then…

  • CVE-2026-68442HigAug 12, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps When btrfs_drop_extent_map_range() splits an extent map, the new split maps inherit the original map's flags through a local 'flags' variable.…