VYPR

CVEs

379,218 total · page 141 of 7,585

  • CVE-2026-71808HigSep 9, 2026
    risk 0.57cvss 8.8epss 0.00

    A SQL Injection vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote authenticated attackers to execute arbitrary SQL commands via the ${} string concatenation in AdminMapper.java and multiple other Mapper files (including MerchantWithdrawRecordMapper.java and…

  • CVE-2026-71803MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. When processing returns, the backend fails to filter or escape the goodsName parameter, directly concatenating it into the order log description; the frontend subsequently renders this content using…

  • CVE-2026-71802MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the announcement content undergoes HTML escaping on the server side, the client-side preview code reverses the escaped entities using jQuery's…

  • CVE-2026-71801CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can…

  • CVE-2026-53956MedSep 9, 2026
    risk 0.28cvss 5.4epss 0.00

    Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling package metadata from conda channels. During…

  • CVE-2026-50165HigSep 9, 2026
    risk 0.39cvss epss 0.00

    alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. An Improper Access Control issue in versions prior to 2.0-M5-2605 allows an organization owner to read system-level configuration secrets through organization/event scoped…

  • CVE-2026-36433CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components

  • CVE-2026-87911CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.01

    An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a…

  • CVE-2026-79324HigSep 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET…

  • CVE-2026-73789MedSep 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability in the web-based management interface of CPPM guest account management services could allow an unauthenticated remote attacker to manipulate account settings. Successful exploitation could allow an attacker to extend network access beyond policy limits, leading…

  • CVE-2026-73788MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in the ClearPass OnGuard agent could allow an authenticated remote attacker to elevate their own privileges on a vulnerable ClearPass OnGuard deployment. Successful exploitation could allow an attacker to obtain root privileges, leading to potentially…

  • CVE-2026-73787HigSep 9, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the CPPM web interface could allow an authenticated remote attacker to access directory information on a vulnerable system. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2026-73786HigSep 9, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the web-based management interface of CPPM could allow an unauthenticated remote attacker to conduct a Denial-of-Service (DoS) attack. Successful exploitation could allow an attacker to cause instability and degrade performance of the vulnerable CPPM server.

  • CVE-2026-73769HigSep 9, 2026
    risk 0.47cvss 7.2epss 0.01

    A vulnerability in the web-based management interface of vulnerable CPPM systems could allow an authenticated remote attacker to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.

  • CVE-2026-71616MedSep 9, 2026
    risk 0.33cvss 6.2epss 0.00

    An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to cause a denial of service via the function gf_route_media_complete_object(). Fixed in 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.

  • CVE-2026-71614HigSep 9, 2026
    risk 0.48cvss 8.4epss 0.00

    An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e4093392e1f847c90d20e031e893cd942fef938.

  • CVE-2026-71613HigSep 9, 2026
    risk 0.44cvss 7.8epss 0.00

    Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function. Fixed in 9a253a07fd3f6b48022bba74302bf39388dda859.

  • CVE-2026-71612HigSep 9, 2026
    risk 0.48cvss 8.4epss 0.00

    Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_process() function. Fixed in fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6.

  • CVE-2026-61915MedSep 9, 2026
    risk 0.20cvss 4.2epss 0.00

    An issue was discovered in Cyrus IMAP before 3.12.4. There is a VPATCH BYPARAM double-free. An authenticated calendar user could crash a Cyrus CalDAV worker with a PATCH containing PATCH-ACTION="BYPARAM@..." against a resource with two or more properties of the matched kind. The…

  • CVE-2026-61911MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    An issue was discovered in Cyrus IMAP before 3.12.4. There is a Sieve mailbox existence oracle. An authenticated user could install a Sieve script that probed whether another user's private mailbox existed, or read the value of shared mailbox annotations, by observing which…

  • CVE-2026-61910LowSep 9, 2026
    risk 0.16cvss 3.5epss 0.00

    An issue was discovered in Cyrus IMAP before 3.12.4. Mailbox/set let a sharee change a special-use role on shared mailboxes. An authenticated user with maySetKeywords on another user's mailbox could change that mailbox's specialuse annotation. This could allow the sharee to…

  • CVE-2026-61909LowSep 9, 2026
    risk 0.16cvss 3.5epss 0.00

    An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href ACL. An authenticated DAV user with some shared access to another user's calendar or address book could read even unshared events or contacts by including the target hrefs in a…

  • CVE-2026-61908LowSep 9, 2026
    risk 0.13cvss 3.1epss 0.00

    An issue was discovered in Cyrus IMAP before 3.12.4. A JMAP email-header blob ID can reference an out-of-bounds index. An authenticated user could attempt to download a crafted JMAP blob ID of the form H-, which could read past the end of the internal…

  • CVE-2026-38998MedSep 9, 2026
    risk 0.42cvss 6.5epss 0.00

    A use-after-free in the SocketDescriptor::tcpReadHandler1 function (liveMedia/RTPInterface.cpp) of LIVE555 Streaming Media (version 2026.02.26) allows attackers to cause a Denial of Service (DoS) via sending a series of crafted RTSP and HTTP requests to the server.

  • CVE-2026-79323HigSep 9, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST…

  • CVE-2026-79322HigSep 9, 2026
    risk 0.56cvss 8.6epss 0.00

    SQL injection in the RelatedProduct block in Mageplaza Blog for Magento 2 (mageplaza/magento-2-blog-extension) through 4.3.2 allows remote unauthenticated attackers to execute arbitrary SQL commands and read arbitrary database contents via the id parameter to /mpblog/post/view.

  • CVE-2026-61907MedSep 9, 2026
    risk 0.21cvss 4.3epss 0.00

    An issue was discovered in Cyrus IMAP before 3.12.4. JMAP snooze bypasses the destination-mailbox ACL. An authenticated user with insert permissions on another user's snoozed mailbox could cause insertion of mail to that user's inbox, or any other of their mailboxes whose id was…

  • CVE-2026-54694CriSep 9, 2026
    risk 0.55cvss 9.6epss 0.00

    SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw…

  • CVE-2026-52482HigSep 9, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service spawns /app/sh_for_telnet

  • CVE-2026-39020MedSep 9, 2026
    risk 0.36cvss 5.5epss 0.00

    An issue in WIngs3D v.2.4.1 allows a local attacker to cause a denial of service via a crafted Wavefront OBJ file

  • CVE-2025-51619MedSep 9, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability in the Thesycon DPC Latency Checker driver (dpc.sys) thru 1.4.0 allows local unprivileged users to cause a denial-of-service (BSOD) condition on Windows systems. The driver exposes an IOCTL interface (0x81772008) that accepts user-controlled input without…

  • CVE-2025-58363Sep 9, 2026
    risk 0.00cvss epss

    ### Summary A path traversal vulnerability in eKuiper's administrative management endpoints allows privileged users or attackers with access to management APIs to delete arbitrary files or directories on the host system. ### Details In `internal/plugin/native/manager.go`, the…

  • CVE-2025-24979Sep 9, 2026
    risk 0.00cvss epss

    ### Summary Server-side request forgery (SSRF) vulnerability in eKuiper allows an attacker with permissions to register external services or create rules to induce the eKuiper server to make requests to unintended network locations, such as internal services, loopback interfaces…

  • CVE-2025-24978lowSep 9, 2026
    risk 0.00cvss epss

    ### Summary A Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces. ### Details…

  • CVE-2026-87946Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87947Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87948Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87949Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87950Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87951Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87952Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87953Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87954Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-87955Sep 9, 2026
    risk 0.00cvss epss

    Mentioned in Drupal. See https://www.drupal.org/security for vendor details.

  • CVE-2026-8044HigSep 9, 2026
    risk 0.56cvss epss 0.00

    CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability exists that could cause remote code execution by an attacker with a privileged account when malicious arguments are provided as backup configuration parameters.

  • CVE-2026-87930HigSep 9, 2026
    risk 0.53cvss 8.1epss 0.00

    MaxSite CMS through 109.6 passes the ci_session cookie to unserialize() without class restrictions, allowing unauthenticated attackers to inject PHP objects. Attackers can forge valid session cookies using the hardcoded encryption key to trigger magic methods and corrupt…

  • CVE-2026-87929CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with…

  • CVE-2026-87928MedSep 9, 2026
    risk 0.35cvss 5.4epss 0.00

    MaxSite CMS versions 0.94 through 109.6 contain a cross-site scripting vulnerability in the admin_page upload handler that allows any logged-in user to upload HTML files. Attackers can upload HTML containing malicious scripts to the uploads/_pages/ directory, which executes in…

  • CVE-2026-87927HigSep 9, 2026
    risk 0.53cvss 8.2epss 0.00

    MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path…

  • CVE-2026-87876LowSep 9, 2026
    risk 0.13cvss 3.0epss 0.00

    Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.