VYPR

CVEs

37,387 total · page 15 of 748

  • CVE-2026-80945CriSep 11, 2026
    risk 0.52cvss 9.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while it is still mapped…

  • CVE-2026-80926CriSep 11, 2026
    risk 0.57cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in oplock break notification smb2_oplock_break_noti() reads opinfo->conn without any lock and dereferences it after two allocations which may sleep. When the durable handle owning…

  • CVE-2026-53952CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. A logic flaw in GetSimple CMS (v3.4.0a and below) and GetSimpleCMS-CE (v3.3.22 and below) allows unauthenticated attackers to create a new administrator account. The…

  • CVE-2026-52630CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in Woltlab WCF v.6.2.4 and before allows a remote attacker to updateUserOptions in UserEditor.class.php and the update action in UserAction.class.php

  • CVE-2026-79396CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier stores static account credentials in unencrypted plaintext within bin/config.xml and compiled into the Sofia executable, allowing remote attackers to gain full…

  • CVE-2026-79395CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged…

  • CVE-2026-62105CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in ThemeREX Addons < 2.45.0 versions.

  • CVE-2026-62103CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Everest Forms <= 3.6.0 versions.

  • CVE-2026-54072CriSep 11, 2026
    risk 0.53cvss 9.3epss 0.00

    Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server…

  • CVE-2026-82617CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these finders through…

  • CVE-2026-72710CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    SPIP before 4.4.18 contains a mass assignment vulnerability in the editer_objet action that allows unauthenticated attackers to write arbitrary rows to any SQL table lacking a champs_editables allowlist by supplying an attacker-controlled arg parameter resolving to internal…

  • CVE-2026-72709CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    SPIP before version 4.4.18 contains a missing authorization vulnerability in sensitive actions under ecrire/action/ that allows unauthenticated attackers to invoke privileged actions by supplying only a valid CSRF nonce without any server-side permission check. Attackers can…

  • CVE-2026-54047CriSep 11, 2026
    risk 0.53cvss —epss 0.00

    Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID`…

  • CVE-2026-3869CriSep 11, 2026
    risk 0.60cvss —epss 0.01

    CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

  • CVE-2026-89010CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.03

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136.…

  • CVE-2026-89009CriSep 11, 2026
    risk 0.59cvss 9.1epss 0.01

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136.…

  • CVE-2026-87988CriSep 11, 2026
    risk 0.65cvss —epss 0.00

    An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user…

  • CVE-2026-87987CriSep 11, 2026
    risk 0.65cvss —epss 0.00

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment…

  • CVE-2026-87986CriSep 11, 2026
    risk 0.65cvss —epss 0.00

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without…

  • CVE-2026-87985CriSep 11, 2026
    risk 0.65cvss —epss 0.00

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system…

  • CVE-2026-87984CriSep 11, 2026
    risk 0.60cvss —epss 0.00

    An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise…

  • CVE-2026-87983CriSep 11, 2026
    risk 0.60cvss —epss 0.00

    An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the…

  • CVE-2026-71644CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the…

  • CVE-2026-84390CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via

  • CVE-2026-80462CriSep 11, 2026
    risk 0.65cvss 10.0epss 0.00

    A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

  • CVE-2026-89259CriSep 11, 2026
    risk 0.57cvss 9.8epss 0.00

    Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As…

  • CVE-2026-86793CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution via pickle REDUCE.

  • CVE-2026-47839CriSep 11, 2026
    risk 0.60cvss —epss 0.00

    A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses…

  • CVE-2026-14563CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including…

  • CVE-2026-14560CriSep 11, 2026
    risk 0.65cvss 10.0epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the…

  • CVE-2026-14559CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.

  • CVE-2026-8778CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This…

  • CVE-2026-82107CriSep 10, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

  • CVE-2026-82100CriSep 10, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

  • CVE-2026-81204CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

  • CVE-2026-80424CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

  • CVE-2026-79724CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-78573CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

  • CVE-2026-71640CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

  • CVE-2026-45764CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause…

  • CVE-2026-19646CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

  • CVE-2026-89094CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.01

    Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

  • CVE-2026-85025CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session…

  • CVE-2026-75940CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

  • CVE-2026-89086CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

  • CVE-2026-88062CriSep 10, 2026
    risk 0.55cvss —epss 0.01

    OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency…

  • CVE-2026-89049CriSep 10, 2026
    risk 0.57cvss 9.9epss 0.00

    A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user…

  • CVE-2026-89042CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to…

  • CVE-2026-68006CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

  • CVE-2026-88044CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and…