VYPR

CVEs

378,486 total · page 119 of 7,570

  • CVE-2026-11813HigSep 10, 2026
    risk 0.51cvss 7.8epss 0.00

    A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.

  • CVE-2022-26962MedSep 10, 2026
    risk 0.35cvss 5.4epss 0.00

    Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary…

  • CVE-2026-89087HigSep 10, 2026
    risk 0.47cvss 7.3epss 0.00

    The cstruct package before 6.3.0 for OCaml mishandles indexes.

  • CVE-2026-89086CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

  • CVE-2026-89054HigSep 10, 2026
    risk 0.46cvss 8.2epss 0.00

    A missing authorization vulnerability in OpenNMS Horizon allows configuration changes without authentication. The Spring Security policy for the /api/v2 REST API defines authorization rules for every HTTP method except PATCH, so the shipped @PATCH configuration endpoints for…

  • CVE-2026-89011HigSep 10, 2026
    risk 0.39cvss 7.1epss 0.00

    isomorphic-git before 1.42.0 contains a prototype pollution vulnerability in the getRemoteInfo function that allows a malicious Git server operator to pollute Object.prototype by advertising crafted ref names containing '__proto__' path segments during ref negotiation. Attackers…

  • CVE-2026-88062CriSep 10, 2026
    risk 0.55cvss epss 0.01

    OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency…

  • CVE-2026-88061MedSep 10, 2026
    risk 0.31cvss epss 0.00

    career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops local web dashboard web/ exposed command-spawning and user-file-writing /api routes without validating request origin or restricting clients to loopback addresses.…

  • CVE-2026-84432MedSep 10, 2026
    risk 0.27cvss epss 0.00

    Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/controllers/dialog/board/custom_slot.php) saveTemplate() action. The action created a board_slot_proxy Block and dispatched an AddCustomSlotToBoardCommand…

  • CVE-2026-9338MedSep 10, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to trigger excessive resource consumption, potentially leading to reduced availability of the…

  • CVE-2026-9336MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafted HTTP request to an administrative endpoint. A remote attacker could exploit this vulnerability to cause the server to exhaust filesystem space.

  • CVE-2026-89049CriSep 10, 2026
    risk 0.57cvss 9.9epss 0.00

    A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user…

  • CVE-2026-88060HigSep 10, 2026
    risk 0.49cvss epss 0.01

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes untrusted input inside template…

  • CVE-2026-88059MedSep 10, 2026
    risk 0.19cvss 4.0epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.1, Angular's @angular/common HttpTransferCache can cache an authenticated response when Server-Side Rendering…

  • CVE-2026-88058HigSep 10, 2026
    risk 0.49cvss epss 0.01

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular server-side rendering (SSR) in @angular/platform-server serializes ProcessingInstruction DOM nodes…

  • CVE-2026-88057MedSep 10, 2026
    risk 0.27cvss epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.28, 21.2.20, and 22.1.0, Angular's compiler and runtime in @angular/core and @angular/compiler could omit or select an incorrect…

  • CVE-2026-88056HigSep 10, 2026
    risk 0.49cvss epss 0.00

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes user-controlled resource or request URLs…

  • CVE-2026-88036HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88035MedSep 10, 2026
    risk 0.31cvss 4.7epss 0.00

    A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-name value is accepted and copied past the end of a small buffer. A party able to set the driver's connection settings may cause the application that embeds…

  • CVE-2026-88034HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C++ Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88033HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Java Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88032MedSep 10, 2026
    risk 0.38cvss 5.9epss 0.00

    A use-after-free in the reactive client-side encryption component of the MongoDB Java Driver can cause native resources to be freed while an affected encrypted operation is still using them when the operation is cancelled. A party able to cause such an operation to be cancelled…

  • CVE-2026-88021HigSep 10, 2026
    risk 0.39cvss 7.1epss 0.00

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the Connect service mesh that may allow a service to reach a destination it is not authorized to access. When building Envoy RBAC rules to enforce Connect intentions, Consul did not correctly escape…

  • CVE-2026-87993HigSep 10, 2026
    risk 0.43cvss 7.7epss 0.00

    The consul-template library is vulnerable to an information disclosure issue in its error handling path that may allow Vault secret values to appear in template error messages, log output, and downstream surfaces such as Nomad task events. This vulnerability (CVE-2026-87993) is…

  • CVE-2026-87107MedSep 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog deregistration path that may allow a local ACL token to delete peer-imported catalog objects. A caller with {{service:write}} or {{node:write}} permission may exploit this issue to remove…

  • CVE-2026-87106MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Consul and Consul Enterprise are vulnerable to a denial of service in the native RPC listener that may allow an authenticated client to exhaust server memory before ACL authorization is evaluated. A client that can complete the internal RPC mTLS handshake may exploit this issue…

  • CVE-2026-87090HigSep 10, 2026
    risk 0.47cvss 8.3epss 0.00

    Consul and Consul Enterprise are vulnerable to an authorization bypass in the catalog node-write path that may allow an authenticated attacker to delete another node's catalog registration and take over its node identity. An attacker with a token granting node-write permission…

  • CVE-2026-68527MedSep 10, 2026
    risk 0.38cvss epss 0.00

    Concrete CMS versions 8.3.0 through 9.5.2 are vulnerable to an authorization bypass in the Calendar event edit dialog (concrete/controllers/dialog/event/edit.php). The dialog checked permissions against the calendar identifier supplied in the request rather than the calendar…

  • CVE-2026-89046HigSep 10, 2026
    risk 0.46cvss 8.2epss 0.01

    zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header…

  • CVE-2026-89045MedSep 10, 2026
    risk 0.19cvss 4.0epss 0.00

    zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the…

  • CVE-2026-89044MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final through 4.2.17.Final fail to properly validate the final transfer coding in the Transfer-Encoding header, allowing attackers to smuggle requests by using malformed encoding declarations. Attackers can split…

  • CVE-2026-89043HigSep 10, 2026
    risk 0.41cvss 7.4epss 0.00

    passport-saml-encrypted through 0.1.13 contains an XML signature wrapping vulnerability where signature verification and assertion extraction use independent XPath lookups with no cross-validation. Attackers holding any validly signed SAML message can prepend a forged unsigned…

  • CVE-2026-89042CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to…

  • CVE-2026-88055MedSep 10, 2026
    risk 0.29cvss 5.5epss 0.00

    AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-preferences, and MetaGenerator inserts…

  • CVE-2026-88054MedSep 10, 2026
    risk 0.29cvss 5.5epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED layers in a crafted .traineddata model. During…

  • CVE-2026-88053HigSep 10, 2026
    risk 0.44cvss 7.8epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadIntTemplates in src/classify/intproto.cpp reads NumClassPruners, NumClasses, and NumProtoSets from the TESSDATA_INTTEMP component of a crafted .traineddata file and uses those values as loop…

  • CVE-2026-88052HigSep 10, 2026
    risk 0.44cvss 7.8epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_insert_backwards_compatible can…

  • CVE-2026-88051HigSep 10, 2026
    risk 0.44cvss 7.8epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a cap or an invariant check.…

  • CVE-2026-88031HigSep 10, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Go Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88030HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Ruby Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88029HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Python Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88028MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper neutralization of special elements in data query logic in the polymorphic relation handling of the MongoDB integration for Laravel can cause a caller-supplied relation identifier to be interpreted as a query condition rather than as a literal identifier. An…

  • CVE-2026-88027HigSep 10, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper neutralization of special elements in data query logic in the embedded-document relation handling of the MongoDB integration for Laravel can cause a caller-supplied embedded record identifier to be interpreted as a query condition rather than as a literal identifier. An…

  • CVE-2026-88026MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper neutralization of regular-expression metacharacters in the LINQ query translation component of the MongoDB C# Driver can cause a caller-supplied character sequence to alter a regular-expression predicate generated by an affected application. An authenticated user who…

  • CVE-2026-88025HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB C# Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88024HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB Rust Driver can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88023HigSep 10, 2026
    risk 0.54cvss 8.3epss 0.00

    Improper neutralization of special elements in data query logic in the GridFS component of the MongoDB PHP Library can cause a caller-supplied structured file identifier to be interpreted as a query condition rather than as a literal identifier. An authenticated user who can…

  • CVE-2026-88022HigSep 10, 2026
    risk 0.50cvss 7.7epss 0.00

    Improper neutralization of special elements in data query logic in the MongoDB integration for Laravel can cause an array supplied to an explicit equality filter to be interpreted as a query condition rather than as a literal value. This affects the three-argument `where` method…

  • CVE-2026-68006CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

  • CVE-2026-15419HigSep 10, 2026
    risk 0.45cvss epss 0.00

    In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.