VYPR

CVEs

378,488 total · page 120 of 7,570

  • CVE-2026-68006CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

  • CVE-2026-15419HigSep 10, 2026
    risk 0.45cvss epss 0.00

    In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to corrupt kernel pool memory, resulting in arbitrary code execution with escalated privileges.

  • CVE-2026-15418LowSep 10, 2026
    risk 0.16cvss epss 0.00

    In the silabser.sys driver for CP210x devices v11.5.0 and earlier, a local unprivileged user with a malicious device can use malformed packets to leak up to 145 bytes of uninitialized kernel pool memory. This vulnerability affects Windows 10 and earlier.

  • CVE-2026-15417MedSep 10, 2026
    risk 0.45cvss epss 0.00

    In the silabser.sys Windows 8 driver for CP210x devices, a local unprivileged user can use incorrect driver settings to cause a kernel crash.

  • CVE-2026-88050MedSep 10, 2026
    risk 0.29cvss 5.5epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, RecodedCharID::DeSerialize in src/ccutil/unicharcompress.h validates length_ but accepts negative code_ values from a crafted .traineddata recoder component. UnicharCompress::ComputeCodeRange in…

  • CVE-2026-88049MedSep 10, 2026
    risk 0.29cvss 5.5epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, prior .traineddata hardening added bounds checks to NetworkIO::CopyTimeStepGeneral and NetworkIO::Randomize in src/lstm/networkio.cpp but left NetworkIO::WriteTimeStepPart and NetworkIO::AddTimeStepPart…

  • CVE-2026-88048HigSep 10, 2026
    risk 0.39cvss 7.1epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected::Forward, MatrixDotVector in…

  • CVE-2026-88047HigSep 10, 2026
    risk 0.44cvss 7.8epss 0.00

    Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whitespace-delimited token into a fixed…

  • CVE-2026-88046MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone core does not reject parent-directory segments in source Object.Remote() values before fs/list, fs/walk, fs/sync, and fs/operations pass those…

  • CVE-2026-88045HigSep 10, 2026
    risk 0.42cvss 7.5epss 0.01

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to multipart.NewRW().Reserve before…

  • CVE-2026-88044CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and…

  • CVE-2026-85228CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted…

  • CVE-2026-73699HigSep 10, 2026
    risk 0.47cvss 7.2epss 0.01

    FileRun before 2026.3.0 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary code by exploiting incorrect options passed to unserialize() in the Perms::getPerms() method, where a positional array is used instead of the required…

  • CVE-2026-73698HigSep 10, 2026
    risk 0.47cvss 7.2epss 0.00

    FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators to execute arbitrary SQL by submitting the description parameter as an array, causing the getValuesString() method in DB/DP.php to interpolate raw array values directly…

  • CVE-2026-73694HigSep 10, 2026
    risk 0.47cvss 7.2epss 0.02

    FileRun before 2026.3.0 contains an OS command injection vulnerability caused by a no-op redefinition of escapeshellcmd() in CLI.php that strips shell-metacharacter escaping, allowing attacker-controlled input to reach an exec() sink unsanitized. Attackers can exploit this…

  • CVE-2026-73693HigSep 10, 2026
    risk 0.57cvss 8.8epss 0.02

    FileRun before 2026.3.0 contains an OS command injection vulnerability in the PhotoProofSheet handler that allows authenticated users with upload permission to execute arbitrary commands by uploading files with shell metacharacters in their names. Attackers can upload a file…

  • CVE-2026-68488CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

  • CVE-2026-68487CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

  • CVE-2026-65639CriSep 10, 2026
    risk 0.62cvss epss 0.02

    OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects…

  • CVE-2026-65638CriSep 10, 2026
    risk 0.60cvss epss 0.03

    Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by…

  • CVE-2026-52098CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/ endpoint

  • CVE-2026-52097MedSep 10, 2026
    risk 0.44cvss 6.8epss 0.00

    An issue in AppFlowy 0.11.8 allows a remote attacker to execute arbitrary code via the afLaunchUri, _afLaunchLocalUri (url_launcher.dart), OpenFilex.open, localPathRegex (common_patterns.dart) components

  • CVE-2026-88959HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.00

    Anchor CMS through 0.12.7 fails to enforce role-based access control in admin user-management endpoints, allowing any authenticated low-privilege user to create administrator accounts or modify existing ones. Attackers with editor or user roles can POST directly to…

  • CVE-2026-88940MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    knowns through 0.33.0 fails to validate the path query parameter in the workspace browse endpoint, allowing remote attackers to enumerate arbitrary directories on the host filesystem. Attackers can traverse the directory structure to locate project directories and identify…

  • CVE-2026-88939HigSep 10, 2026
    risk 0.47cvss 8.3epss 0.00

    knowns through 0.33.0 exempts the project.set action from permission guard checks unconditionally, allowing read-only agent sessions to bypass restrictions. Attackers can invoke project.set to repoint the server at another project directory and obtain write access capabilities.

  • CVE-2026-88938MedSep 10, 2026
    risk 0.35cvss 6.5epss 0.00

    knowns through 0.33.0 fails to confine the path argument of the code.find MCP tool to the project root, allowing AI agent sessions to read source files anywhere on the host. Attackers can supply absolute paths or relative traversal sequences to the path argument and retrieve…

  • CVE-2026-88937HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.01

    knowns through 0.33.0 fails to properly validate template destination paths in the code generation template engine, allowing attackers to read and write arbitrary files outside the project root. Attackers can supply malicious templates that traverse directories to overwrite…

  • CVE-2026-88899CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.00

    knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

  • CVE-2026-88018CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty…

  • CVE-2026-88017HigSep 10, 2026
    risk 0.40cvss 7.3epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the server-wide userPass map[string]string…

  • CVE-2026-88016HigSep 10, 2026
    risk 0.39cvss 7.1epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and later directory metadata is applied through…

  • CVE-2026-88015MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, backend/local with --links or links=true exposes symlink targets as .rclonelink objects, and fs.RangeOption.Decode can pass an unchecked positive Range…

  • CVE-2026-88014MedSep 10, 2026
    risk 0.34cvss 6.3epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.72.0 until 1.75.1, the archive ZIP backend method (*Fs).readZip in backend/archive/zip/zip.go accepts archive/zip.File.Name values from an untrusted central…

  • CVE-2026-88013LowSep 10, 2026
    risk 0.17cvss 3.7epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backend/http/http.go, while its fshttp.NewClient…

  • CVE-2026-88012MedSep 10, 2026
    risk 0.27cvss 5.3epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connection and the HTTP/3 server has no…

  • CVE-2026-88011HigSep 10, 2026
    risk 0.46cvss 8.1epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from…

  • CVE-2026-88009HigSep 10, 2026
    risk 0.46cvss 8.2epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path evaluates routing, path sanitization,…

  • CVE-2026-87913MedSep 10, 2026
    risk 0.38cvss 5.9epss 0.00

    A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a…

  • CVE-2026-87912MedSep 10, 2026
    risk 0.31cvss 5.9epss 0.00

    A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that…

  • CVE-2026-81468CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.02

    Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2026-81467CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.03

    Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2026-81052MedSep 10, 2026
    risk 0.44cvss 6.8epss 0.00

    Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to arbitrary code execution.

  • CVE-2026-81051MedSep 10, 2026
    risk 0.43cvss 6.6epss 0.00

    Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability. A low privileged attacker with physical access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2026-81049MedSep 10, 2026
    risk 0.29cvss 4.4epss 0.00

    Dell ThinOS 10, versions prior to 2605_10.2616, contain a Missing Support for Integrity Check vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

  • CVE-2026-81048CriSep 10, 2026
    risk 0.63cvss 9.6epss 0.01

    Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote…

  • CVE-2026-81046CriSep 10, 2026
    risk 0.61cvss 9.4epss 0.00

    Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.

  • CVE-2026-79987HigSep 10, 2026
    risk 0.50cvss 8.8epss 0.00

    A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

  • CVE-2026-4130HigSep 10, 2026
    risk 0.46cvss 7.1epss 0.00

    There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affects NI SystemLink and NI SystemLink…

  • CVE-2026-4129HigSep 10, 2026
    risk 0.53cvss 8.1epss 0.00

    There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI SystemLink and NI SystemLink Server…

  • CVE-2026-88924HigSep 10, 2026
    risk 0.45cvss 7.0epss 0.00

    A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a…