VYPR

CVEs

378,485 total · page 117 of 7,570

  • CVE-2026-78130HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

  • CVE-2026-78129MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

  • CVE-2026-78127LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

  • CVE-2026-78126MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

  • CVE-2026-78124LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

  • CVE-2026-78123MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

  • CVE-2026-84941MedSep 11, 2026
    risk 0.45cvss epss 0.00

    An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful…

  • CVE-2026-81906MedSep 11, 2026
    risk 0.34cvss epss 0.00

    Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that…

  • CVE-2026-81905MedSep 11, 2026
    risk 0.34cvss epss 0.00

    Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a…

  • CVE-2026-77807HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.01

    The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated…

  • CVE-2026-18121MedSep 11, 2026
    risk 0.34cvss epss 0.00

    Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event…

  • CVE-2026-17176HigSep 11, 2026
    risk 0.50cvss epss 0.04

    An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including…

  • CVE-2026-16174HigSep 10, 2026
    risk 0.57cvss epss 0.00

    Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to…

  • CVE-2026-16172MedSep 10, 2026
    risk 0.39cvss epss 0.00

    Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver…

  • CVE-2026-9768Sep 10, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-87958HigSep 10, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.

  • CVE-2026-86093HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a…

  • CVE-2026-86087MedSep 10, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.

  • CVE-2026-84889HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-82107CriSep 10, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

  • CVE-2026-82100CriSep 10, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

  • CVE-2026-82099HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

  • CVE-2026-82098HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-82097HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.

  • CVE-2026-82095HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

  • CVE-2026-82092HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

  • CVE-2026-81941HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local…

  • CVE-2026-81940HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

  • CVE-2026-81554HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.

  • CVE-2026-81551HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.

  • CVE-2026-81550HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

  • CVE-2026-81540HigSep 10, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.

  • CVE-2026-81268HigSep 10, 2026
    risk 0.46cvss 8.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

  • CVE-2026-81265HigSep 10, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5.

  • CVE-2026-81213HigSep 10, 2026
    risk 0.56cvss 8.6epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.

  • CVE-2026-81211HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

  • CVE-2026-81210HigSep 10, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but…

  • CVE-2026-81207HigSep 10, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller.…

  • CVE-2026-81204CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

  • CVE-2026-80436HigSep 10, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.

  • CVE-2026-80434HigSep 10, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.

  • CVE-2026-80424CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

  • CVE-2026-80380HigSep 10, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.

  • CVE-2026-80378HigSep 10, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.

  • CVE-2026-79742HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

  • CVE-2026-79725MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.

  • CVE-2026-79724CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-79723MedSep 10, 2026
    risk 0.33cvss 5.0epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.

  • CVE-2026-79590MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and…

  • CVE-2026-78575HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.