VYPR

CVEs

38,008 total · page 156 of 761

  • CVE-2026-28783CriMar 4, 2026
    risk 0.52cvss 9.1epss 0.01

    Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack,…

  • CVE-2026-28697CriMar 4, 2026
    risk 0.52cvss 9.1epss 0.01

    Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling…

  • CVE-2025-69969CriMar 4, 2026
    risk 0.62cvss 9.6epss 0.00

    A lack of authentication and authorization mechanisms in the Bluetooth Low Energy (BLE) communication protocol of SRK Powertech Pvt Ltd Pebble Prism Ultra v2.9.2 allows attackers to reverse engineer the protocol and execute arbitrary commands on the device without establishing a…

  • CVE-2025-66944CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in vran-dev databaseir v.1.0.7 and before allows a remote attacker to execute arbitrary code via the query parameter in the search API endpoint

  • CVE-2025-66678CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the HwRwDrv.sys component of Nil Hardware Editor Hardware Read & Write Utility v1.25.11.26 and earlier allows attackers to execute arbitrary read and write operations via a crafted request.

  • CVE-2026-26478CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.03

    A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attackers to send a specially crafted UDP datagram and execute arbitrary shell code as the root account.

  • CVE-2025-59786CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.00

    2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to remain active after logout in web application.

  • CVE-2026-27446CriMar 4, 2026
    risk 0.65cvss 9.8epss 0.01

    Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to force a target broker to establish an outbound Core federation connection to an attacker-controlled…

  • CVE-2026-27441CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS command execution.

  • CVE-2026-29119CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    International Datacasting Corporation (IDC) SFX Series SuperFlex(SFX2100) SatelliteReceiver contains hardcoded and insecure credentials for the `admin` account. A remote unauthenticated attacker can use these undocumented credentials to access the satellite system directly via…

  • CVE-2026-28778CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver contains undocumented, hardcoded/insecure credentials for the `xd` user account. A remote unauthenticated attacker can log in via FTP using these credentials. Because the `xd` user has write…

  • CVE-2026-28777CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    International Datacasting Corporation (IDC) SFX2100 Satellite Receiver, trivial password for the `user` (usr) account. A remote unauthenticated attacker can exploit this to gain unauthorized SSH access to the system, while intially dropped into a restricted shell, an attacker…

  • CVE-2026-28776CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver contains hardcoded credentials for the `monitor` account. A remote unauthenticated attacker can use these trivial, undocumented credentials to access the system via SSH. While initially dropped…

  • CVE-2026-28775CriMar 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated Remote Code Execution (RCE) vulnerability exists in the SNMP service of International Datacasting Corporation (IDC) SFX Series SuperFlex SatelliteReceiver. The deployment insecurely provisions the `private` SNMP community string with read/write access by…

  • CVE-2026-3266CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in OpenText™ Filr allows Authentication Bypass. The vulnerability could allow unauthenticated users to get XSRF token and do RPC with carefully crafted programs. This issue affects Filr: through 25.1.2.

  • CVE-2026-28289CriMar 3, 2026
    risk 0.05cvss 10.0epss 0.03

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by…

  • CVE-2026-27971CriMar 3, 2026
    risk 0.57cvss 9.8epss 0.03

    Qwik is a performance focused javascript framework. qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any…

  • CVE-2026-26279CriMar 3, 2026
    risk 0.52cvss 9.1epss 0.01

    Froxlor is open source server administration software. Prior to 2.3.4, a typo in Froxlor's input validation code (== instead of =) completely disables email format checking for all settings fields declared as email type. This allows an authenticated admin to store arbitrary…

  • CVE-2026-26266CriMar 3, 2026
    risk 0.00cvss 9.3epss 0.00

    AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML…

  • CVE-2026-3224CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Authentication bypass in the Microsoft Entra ID (Azure AD) authentication mode in Devolutions Server 2025.3.15.0 and earlier allows an unauthenticated user to authenticate as an arbitrary Entra ID user via a forged JSON Web Token (JWT).

  • CVE-2026-3204CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displayed error message via a specially crafted URL.

  • CVE-2026-3130CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Enforcement of Behavioral Controls in Devolutions Server 2025.3.15 and earlier allows an authenticated attacker with the delete permission to delete a PAM account that is currently checked out by selecting it alongside at least one non-checked-out account and…

  • CVE-2026-2590CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper enforcement of the Disable password saving in vaults setting in the connection entry component in Devolutions Remote Desktop Manager 2025.3.30 and earlier allows an authenticated user to persist credentials in vault entries, potentially exposing sensitive information…

  • CVE-2026-27012CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenSTAManager is an open source management software for technical assistance and invoicing. In 2.9.8 and earlier, a privilege escalation and authentication bypass vulnerability in OpenSTAManager allows any attacker to arbitrarily change a user's group (idgruppo) by directly…

  • CVE-2026-25146CriMar 3, 2026
    risk 0.00cvss 9.6epss 0.00

    OpenEMR is a free and open source electronic health records and medical practice management application. From 5.0.2 to before 8.0.0, there are (at least) two paths where the gateway_api_key secret value is rendered to the client in plaintext. These secret keys being leaked could…

  • CVE-2026-24898CriMar 3, 2026
    risk 0.00cvss 10.0epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0, an unauthenticated token disclosure vulnerability in the MedEx callback endpoint allows any unauthenticated visitor to obtain the practice's MedEx API tokens,…

  • CVE-2026-24848CriMar 3, 2026
    risk 0.65cvss 9.9epss 0.07

    OpenEMR is a free and open source electronic health records and medical practice management application. In 7.0.4 and earlier, the disposeDocument() method in EtherFaxActions.php allows authenticated users to write arbitrary content to arbitrary locations on the server…

  • CVE-2026-3485CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.07

    A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This manipulation of the argument ST causes os command injection. It is possible to initiate the attack remotely. The exploit has been published and may be used.…

  • CVE-2025-70240CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard51.

  • CVE-2025-70239CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWAN_Wizard55.

  • CVE-2025-70234CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetQoS.

  • CVE-2025-70241CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWANType_Wizard5.

  • CVE-2025-70237CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetPortTr.

  • CVE-2025-70236CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDomainFilter.

  • CVE-2025-66945CriMar 3, 2026
    risk 0.59cvss 9.1epss 0.01

    A path traversal vulnerability exists in the ZIP extraction API of Zdir Pro 4.x. When a crafted ZIP archive is processed by the backend at /api/extract, files may be written outside the intended directory, leading to arbitrary file overwrite and potentially remote code execution

  • CVE-2024-55026CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.

  • CVE-2024-55024CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    An authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to perform Administrative actions using service accounts.

  • CVE-2024-55020CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS v20231011 allows attackers to execute arbitrary commands with root privileges.

  • CVE-2026-3136CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    An improper authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-1-26 allows a remote attacker to execute arbitrary code in the build environment. This vulnerability was patched on 26 January 2026, and no customer action is…

  • CVE-2026-24103CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    A buffer overflow vulnerability was discovered in goform/formSetMacFilterCfg in Tenda AC15V1.0 V15.03.05.18_multi.

  • CVE-2026-22891CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the Intan CLP parsing functionality of The Biosig Project libbiosig 3.9.2 and Master Branch (db9a9a63). A specially crafted Intan CLP file can lead to arbitrary code execution. An attacker can provide a malicious file to…

  • CVE-2025-70821CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component

  • CVE-2025-57622CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Step-Video-T2V allows a remote attacker to execute arbitrary code via the /vae-api , /caption-api , feature = pickle.loads(request.get_data()) component

  • CVE-2025-59059CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.

  • CVE-2026-22886CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a default administrative account (admin/ admin) and does not enforce a mandatory password change on first use. After the first successful login,…

  • CVE-2026-1492CriMar 3, 2026
    risk 0.59cvss 9.8epss 0.28

    The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the…

  • CVE-2026-2628CriMar 3, 2026
    risk 0.64cvss 9.8epss 0.01

    The All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 2.2.5. This makes it possible for unauthenticated attackers to bypass authentication and log in as other users,…

  • CVE-2026-26713CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.

  • CVE-2026-26712CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.

  • CVE-2026-26711CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.