VYPR

CVEs

345,868 total · page 156 of 6,918

  • CVE-2026-45057Jun 4, 2026
    risk 0.00cvss epss 0.00

    ### Impact The message edit validation logic in the `matrix-sdk-ui` crate before 0.16.1 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrator (or an actor with…

  • CVE-2026-45056Jun 4, 2026
    risk 0.00cvss epss 0.00

    ### Impact The `matrix-sdk-crypto` crate before 0.16.1 is missing a check for the sender's user ID when decrypting an Olm-encrypted to-device message containing the `sender_device_keys` property. This could be exploited to spoof the sender of an encrypted to-device message,…

  • CVE-2026-44476Jun 4, 2026
    risk 0.00cvss epss 0.00

    ### Impact The `DynamicClientRegistrationController#register` action hard-codes `confidential: false` when creating applications (dynamic_client_registration_controller.rb:18-25), yet the response includes a client_secret and advertises `token_endpoint_auth_methods_supported:…

  • CVE-2026-44889Jun 4, 2026
    risk 0.00cvss epss 0.00

    ### Impact When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing the URL that the user is to be redirected to with Python's `urllib.parse`, and joining it to the base URL. `urlsplit` (called internally by `urljoin`) however treats…

  • CVE-2026-8762Jun 4, 2026
    risk 0.00cvss epss

    Rejected reason: After analysis, the originally reported behaviour was determined not to constitute a security vulnerability. The findings were parser-strictness defects without an exploitable framing-disagreement path in any tested deployment configuration.

  • CVE-2026-8037CriJun 4, 2026
    risk 0.62cvss 9.6epss 0.43

    OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints

  • CVE-2026-45433HigJun 4, 2026
    risk 0.57cvss epss 0.00

    This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the cryptographic private key from the firmware, which could lead to decryption of…

  • CVE-2026-43926MedJun 4, 2026
    risk 0.41cvss epss 0.00

    FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmation endpoint `/client/reset-password-confirm/:hash` is handled by a non-API controller and is not covered by FOSSBilling's rate limiter, which only…

  • CVE-2026-40605MedJun 4, 2026
    risk 0.30cvss epss 0.00

    Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access to delete directories outside the configured cache path. This can cause arbitrary…

  • CVE-2026-10861MedJun 4, 2026
    risk 0.33cvss 6.1epss 0.00

    An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without sufficiently enforcing that it was a local application path. An…

  • CVE-2026-10856MedJun 4, 2026
    risk 0.33cvss 6.1epss 0.00

    A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation rejected URLs containing an explicit scheme, host, or user component, but did…

  • CVE-2026-10855MedJun 4, 2026
    risk 0.21cvss 4.3epss 0.00

    An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization…

  • CVE-2026-10854MedJun 4, 2026
    risk 0.21cvss 4.3epss 0.00

    A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access…

  • CVE-2026-10810MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-10809MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the…

  • CVE-2026-10808MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly…

  • CVE-2026-10807MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image can lead to unrestricted upload. The attack may be…

  • CVE-2026-10806MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post results in unrestricted upload. The attack may be initiated remotely.…

  • CVE-2025-62338LowJun 4, 2026
    risk 0.21cvss 3.3epss 0.00

    HCL BigFix Cloud Lifecycle Management is affected by lack of input validation.  This low-level flaw allows unauthorized access and may lead to information exposure.

  • CVE-2025-59874HigJun 4, 2026
    risk 0.53cvss 8.1epss 0.00

    HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vulnerable.

  • CVE-2025-46638HigJun 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).

  • CVE-2019-25745HigJun 4, 2026
    risk 0.53cvss 8.2epss 0.00

    WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'tid' parameter. Attackers can send GET requests to the admin interface with…

  • CVE-2019-25744MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint…

  • CVE-2019-25743MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script…

  • CVE-2019-25742MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property…

  • CVE-2019-25741CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code. Attackers can craft a malicious MobaXterm sessions file with overflow data…

  • CVE-2019-25740MedJun 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Joomla com_jsjobs 1.2.6 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating custom userfield parameters. Attackers can send POST requests to the job.savejob task with path traversal sequences in the field_2…

  • CVE-2019-25739MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers can craft XSS payloads in the create_proposal endpoint that execute when…

  • CVE-2019-25738CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    WordPress Hybrid Composer 1.4.6 contains an unauthenticated settings change vulnerability that allows unauthenticated attackers to modify WordPress options by exploiting the hc_ajax_save_option action. Attackers can send POST requests to the admin-ajax.php endpoint with the…

  • CVE-2019-25737MedJun 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit payloads containing script tags and event handlers that execute in the admin area,…

  • CVE-2019-25736HigJun 4, 2026
    risk 0.55cvss 8.4epss 0.00

    LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address…

  • CVE-2019-25735HigJun 4, 2026
    risk 0.55cvss 8.4epss 0.00

    AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger…

  • CVE-2019-25734MedJun 4, 2026
    risk 0.26cvss 4.0epss 0.01

    Contact Form by WD 1.13.1 contains a cross-site request forgery vulnerability combined with local file inclusion that allows unauthenticated attackers to include arbitrary files by exploiting unsanitized action parameters. Attackers can craft malicious forms targeting the…

  • CVE-2019-25733HigJun 4, 2026
    risk 0.55cvss 8.4epss 0.00

    NetShareWatcher 1.5.8.0 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input. Attackers can craft a payload with overwritten SEH and NSEH pointers through the Restrictions custom…

  • CVE-2019-25732HigJun 4, 2026
    risk 0.53cvss 8.2epss 0.00

    PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to the search endpoint with crafted SQL payloads in the…

  • CVE-2019-25731MedJun 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST…

  • CVE-2019-25730HigJun 4, 2026
    risk 0.53cvss 8.2epss 0.00

    Listing Hub CMS 1.0 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to pages.php with crafted id values using error-based SQL…

  • CVE-2019-25729CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    PDF Signer 3.0 contains a server-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP commands through the CSRF-TOKEN cookie parameter. Attackers can craft malicious cookie values containing template injection…

  • CVE-2019-25728HigJun 4, 2026
    risk 0.53cvss 8.2epss 0.00

    Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including…

  • CVE-2019-25727CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a…

  • CVE-2019-25726HigJun 4, 2026
    risk 0.53cvss 8.2epss 0.00

    All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection…

  • CVE-2026-4104CriJun 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.

  • CVE-2026-45432HigJun 4, 2026
    risk 0.57cvss epss 0.00

    This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability by intercepting network traffic to obtain sensitive authentication information,…

  • CVE-2026-45431HigJun 4, 2026
    risk 0.57cvss epss 0.00

    This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker could exploit this vulnerability by injecting arbitrary and executing OS commands…

  • CVE-2026-10843HigJun 4, 2026
    risk 0.47cvss 7.2epss 0.00

    A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are provisioned with account-wide scope for destructive actions rather than being restricted to cluster-owned resources, enabling cross-scope impact after credential…

  • CVE-2026-10840HigJun 4, 2026
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the system:authenticated group write access to Kueue and cert-manager custom resources via the tekton-scheduler-role ClusterRole. When Kueue or cert-manager CRDs are…

  • CVE-2026-10804LowJun 4, 2026
    risk 0.16cvss 3.6epss 0.00

    A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The…

  • CVE-2026-10803LowJun 4, 2026
    risk 0.16cvss 3.6epss 0.00

    A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflow/data/digest_utils.py of the component Dataset Digest Computation. This manipulation causes use of weak hash. It is possible to launch the attack on the local…

  • CVE-2026-10802MedJun 4, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL API Endpoint. The manipulation results in resource consumption. It is possible…

  • CVE-2025-52612HigJun 4, 2026
    risk 0.46cvss 7.1epss 0.00

    HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. .