VYPR

CVEs

379,380 total · page 158 of 7,588

  • CVE-2026-81985HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81984MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-81983HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81982MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-81981HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81980HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81979HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81978MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-81977MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that…

  • CVE-2026-81976HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81975HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81973HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-81192HigSep 8, 2026
    risk 0.39cvss 7.0epss 0.00

    `OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg`…

  • CVE-2026-80162MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-80161HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of…

  • CVE-2026-80160MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-80159MedSep 8, 2026
    risk 0.26cvss 4.0epss 0.00

    Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability to gain elevated access. Exploit depends on conditions beyond the attacker's control. Exploitation…

  • CVE-2026-7809Sep 8, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-79910MedSep 8, 2026
    risk 0.36cvss 5.5epss 0.00

    Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a…

  • CVE-2026-79909HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-79908HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-79907HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-79588MedSep 8, 2026
    risk 0.28cvss 4.3epss 0.00

    U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP.

  • CVE-2026-78971MedSep 8, 2026
    risk 0.30cvss 4.6epss 0.00

    In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

  • CVE-2026-78742MedSep 8, 2026
    risk 0.33cvss 6.1epss 0.00

    Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction.

  • CVE-2026-78741MedSep 8, 2026
    risk 0.33cvss 6.1epss 0.00

    Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) in the wysiwyg-CKEditor image upload feature.

  • CVE-2026-78738MedSep 8, 2026
    risk 0.33cvss 6.1epss 0.00

    Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature.

  • CVE-2026-78635MedSep 8, 2026
    risk 0.33cvss 5.0epss 0.00

    The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a…

  • CVE-2026-78631MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.00

    The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authentication credential readable by any local…

  • CVE-2026-78630MedSep 8, 2026
    risk 0.44cvss 6.7epss 0.00

    The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply crafted values, resulting in the execution…

  • CVE-2026-78629MedSep 8, 2026
    risk 0.36cvss 5.6epss 0.00

    The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptographic artifact, resulting in an…

  • CVE-2026-78622MedSep 8, 2026
    risk 0.39cvss 6.0epss 0.00

    The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recursive deletion of unintended directory…

  • CVE-2026-77827HigSep 8, 2026
    risk 0.46cvss 7.1epss 0.00

    Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

  • CVE-2026-45220Sep 8, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-45219Sep 8, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-30754HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.00

    A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file.…

  • CVE-2026-19651HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

  • CVE-2026-19625MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.00

    When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also…

  • CVE-2026-86810HigSep 8, 2026
    risk 0.41cvss 7.3epss 0.01

    A vulnerability was detected in Open-Web-Analytics up to 1.9.1. The impacted element is the function checkCapabilityAndAuthenticateUser of the file Core/Controller.php of the component Controller. Performing a manipulation results in improper authentication. The attack may be…

  • CVE-2026-86808HigSep 8, 2026
    risk 0.41cvss 7.3epss 0.01

    A security vulnerability has been detected in moltis-org moltis up to 20260818.10. The affected element is the function vault_unlock_handler/vault_recovery_handler of the file vault.rs. Such manipulation leads to missing authentication. The attack can be launched remotely. The…

  • CVE-2026-86806HigSep 8, 2026
    risk 0.40cvss 7.3epss 0.00

    A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name:…

  • CVE-2026-86464CriSep 8, 2026
    risk 0.57cvss epss 0.00

    In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak…

  • CVE-2026-85630MedSep 8, 2026
    risk 0.33cvss 6.1epss 0.00

    HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than literals allows attacker-influenced text in…

  • CVE-2026-85485MedSep 8, 2026
    risk 0.33cvss 6.1epss 0.00

    HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0.410000, the fix for CVE-2026-19872,…

  • CVE-2026-85484MedSep 8, 2026
    risk 0.33cvss 6.1epss 0.00

    HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Select into a label attribute and the other…

  • CVE-2026-84942HigSep 8, 2026
    risk 0.50cvss 8.7epss 0.00

    Improper input validation in the Vega expression function implementation in OpenSearch Dashboards allows a remote authenticated actor with dashboard write permissions to execute arbitrary JavaScript in the context of other users' browser sessions by saving a crafted Vega…

  • CVE-2026-84869CriKEVSep 8, 2026
    risk 0.76cvss 9.9epss 0.01

    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.

  • CVE-2026-84197CriSep 8, 2026
    risk 0.60cvss epss 0.00

    In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes…

  • CVE-2026-82007HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-82006HigSep 8, 2026
    risk 0.51cvss 7.8epss 0.00

    Photoshop Desktop is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.