VYPR

CVEs

37,995 total · page 131 of 760

  • CVE-2018-25316CriApr 29, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send GET requests to the goform/AdvSetDns endpoint with a crafted admin language…

  • CVE-2026-30893CriApr 29, 2026
    risk 0.52cvss 9.0epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary…

  • CVE-2026-26015CriApr 29, 2026
    risk 0.64cvss 9.8epss 0.02

    DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote…

  • CVE-2026-5166CriApr 29, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software Center allows Path Traversal. This issue affects Pardus Software Center: before 0.6.4.

  • CVE-2026-41940CriKEVApr 29, 2026
    risk 0.93cvss 9.8epss 0.99

    cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.

  • CVE-2026-38992CriApr 29, 2026
    risk 0.64cvss 9.8epss 0.01

    Cockpit v2.13.5 and earlier is vulnerable to arbitrary code execution via the filter parameter within multiple endpoints. This vulnerability allows an attacker to run system commands on the underlying infrastructure via the MongoLite $func operator.

  • CVE-2026-36841CriApr 29, 2026
    risk 0.64cvss 9.8epss 0.02

    TOTOLINK N200RE V5 was discovered to contain a command injection vulnerability via the macstr and bandstr parameters in the formMapDelDevice function.

  • CVE-2026-42523CriApr 29, 2026
    risk 0.52cvss 9.0epss 0.01

    Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous…

  • CVE-2026-42249CriApr 29, 2026
    risk 0.57cvss 9.8epss 0.01

    Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derived from HTTP headers…

  • CVE-2026-42248CriApr 29, 2026
    risk 0.57cvss 9.8epss 0.01

    Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is…

  • CVE-2026-3325CriApr 29, 2026
    risk 0.65cvss —epss 0.00

    SQL injection (SQLi) in MegaCMS v12.0.0, specifically in the “id_territorio” parameter of the “/web_comunications/cms/get_provincias” endpoint. The vulnerability arises from inadequate validation and sanitisation of user input. Specifically, via a POST request, the…

  • CVE-2026-7333CriApr 28, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in GPU in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-41446CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Snap One WattBox 800 and 820 series firmware versions prior to 2.10.0.0 contain undisclosed diagnostic HTTP endpoints that require only the device MAC address and service tag for authentication, both of which are printed in plaintext on the physical device label. Attackers with…

  • CVE-2026-41386CriApr 28, 2026
    risk 0.52cvss 9.1epss 0.01

    OpenClaw before 2026.3.22 contains a privilege escalation vulnerability where bootstrap setup codes are not bound to intended device roles and scopes during pairing. Attackers can exploit this during first-use device pairing to escalate privileges beyond their intended role and…

  • CVE-2026-3893CriApr 28, 2026
    risk 0.61cvss 9.4epss 0.01

    The Carlson VASCO-B GNSS Receiver lacks an authentication mechanism, allowing an attacker with network access to directly access and modify its configuration and operational functions without needing credentials.

  • CVE-2026-24178CriApr 28, 2026
    risk 0.57cvss 9.8epss 0.01

    NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthenticated attacker may cause authorization bypass through user-controlled key. A successful exploit of this vulnerability may lead to privilege escalation, data…

  • CVE-2026-41873CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Pony Mail leading to admin account takeover. This issue affects all versions of the Lua implementation of Pony Mail. There is a Python…

  • CVE-2025-60889CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.00

    Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.

  • CVE-2026-7321CriApr 28, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to incorrect boundary conditions in the WebRTC: Networking component. This vulnerability was fixed in Firefox 150, Thunderbird 150, Firefox ESR 140.10.1, and Thunderbird 140.10.1.

  • CVE-2026-7248CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.04

    A vulnerability was found in D-Link DI-8100 16.07.26A1. This affects the function tgfile_htm of the file tgfile.htm of the component CGI Endpoint. The manipulation of the argument fn results in buffer overflow. The attack can be executed remotely. The exploit has been made…

  • CVE-2026-7244CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge results in os command injection. It is…

  • CVE-2026-7243CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is…

  • CVE-2026-7242CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may…

  • CVE-2026-7241CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is…

  • CVE-2026-7240CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setVpnAccountCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument User leads to os command injection. The attack can be…

  • CVE-2026-7204CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setPptpServerCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument enable causes os command injection. The attack may be…

  • CVE-2026-7203CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument enable results in os command injection. The attack can be…

  • CVE-2026-7202CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWiFiWpsStart of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument wscDisabled leads to os command injection. The attack can be…

  • CVE-2026-32644CriApr 28, 2026
    risk 0.64cvss 9.8epss 0.00

    Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.

  • CVE-2026-40976CriApr 28, 2026
    risk 0.52cvss 9.1epss 0.01

    In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default…

  • CVE-2026-7156CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument HTTP results in os command injection. The attack may be launched remotely.…

  • CVE-2026-7155CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setLoginPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument admpass leads to os command injection. The attack may…

  • CVE-2026-7154CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setAdvancedInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument tty_server can lead to os command injection. The attack…

  • CVE-2024-46636CriApr 27, 2026
    risk 0.61cvss 9.4epss 0.00

    NASA Earth Observing System Data and Information System (EOSDIS) MODAPS v8.1 was discovered to contain a SQL injection vulnerability in the category parameter

  • CVE-2026-7153CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setMiniuiHomeInfoShow of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument sys_info results in os command…

  • CVE-2026-7152CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setTelnetCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument telnet_enabled leads to os command injection. It is possible…

  • CVE-2026-35903CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.01

    MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, the device does not verify the Digest response parameter in subsequent RTSP…

  • CVE-2026-31255CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.01

    A command injection vulnerability exists in Tenda AC18 V15.03.05.05_multi. The vulnerability is located in the /goform/SetSambaCfg interface, where improper handling of the guestuser parameter allows attackers to execute arbitrary system commands.

  • CVE-2026-7140CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument HTTP leads to os command injection. The attack may be performed from…

  • CVE-2026-7139CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument mode causes os command injection. The attack is possible to be carried…

  • CVE-2026-7138CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setNtpCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument tz results in os command injection. The attack can be executed…

  • CVE-2026-7137CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setStorageCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument sambaEnabled leads to os command injection. Remote…

  • CVE-2026-7136CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setDmzCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument wanIdx can lead to os command injection. The attack…

  • CVE-2026-41462CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.01

    ProjeQtor versions 7.0 through 12.4.3 contain an unauthenticated SQL injection vulnerability in the login functionality where the login variable is directly concatenated into a SQL query without parameterization or sanitization. Attackers can inject arbitrary SQL expressions…

  • CVE-2026-30352CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability in the /devserver/start endpoint of leonvanzyl autocoder commit 79d02a allows attackers to execute arbitrary code via providing a crafted command parameter.

  • CVE-2026-7125CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge leads to os command injection. The attack may be…

  • CVE-2026-7124CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setIpv6LanCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument addrPrefixLen can lead to os command…

  • CVE-2026-7123CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setIptvCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument setIptvCfg results in os command injection. The attack can be initiated…

  • CVE-2026-7122CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack…

  • CVE-2026-7121CriApr 27, 2026
    risk 0.64cvss 9.8epss 0.03

    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. This manipulation of the argument wizard causes os command injection. It is possible to initiate the attack…