VYPR

CVEs

38,008 total · page 159 of 761

  • CVE-2026-25959CriFeb 25, 2026
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_cliprdr_provide_data_` passes freed `pDstData` to `XChangeProperty` because the cliprdr channel thread calls `xf_cliprdr_server_format_data_response` which converts and uses the…

  • CVE-2026-25955CriFeb 25, 2026
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reuses a cached `XImage` whose `data` pointer references a freed RDPGFX surface buffer, because `gdi_DeleteSurface` frees `surface->data` without…

  • CVE-2026-25953CriFeb 25, 2026
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_AppUpdateWindowFromSurface` reads from a freed `xfAppWindow` because the RDPGFX DVC thread obtains a bare pointer via `xf_rail_get_window` without any lifetime protection, while the…

  • CVE-2026-25952CriFeb 25, 2026
    risk 0.00cvss 9.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `xf_SetWindowMinMaxInfo` dereferences a freed `xfAppWindow` pointer because `xf_rail_get_window` in `xf_rail_server_min_max_info` returns an unprotected pointer from the `railWindows` hash…

  • CVE-2026-0542CriFeb 25, 2026
    risk 0.60cvss —epss 0.01

    ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute code within the ServiceNow Sandbox.    ServiceNow addressed…

  • CVE-2026-24908CriFeb 25, 2026
    risk 0.00cvss 9.9epss 0.01

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, an SQL injection vulnerability in the Patient REST API endpoint allows authenticated users with API access to execute arbitrary SQL queries through…

  • CVE-2026-27739CriFeb 25, 2026
    risk 0.53cvss —epss 0.01

    The Angular SSR is a server-rise rendering tool for Angular applications. Versions prior to 21.2.0-rc.1, 21.1.5, 20.3.17, and 19.2.21 have a Server-Side Request Forgery (SSRF) vulnerability in the Angular SSR request handling pipeline. The vulnerability exists because…

  • CVE-2026-21902CriFeb 25, 2026
    risk 0.65cvss 9.8epss 0.18

    An Incorrect Permission Assignment for Critical Resource vulnerability in the On-Box Anomaly detection framework of Juniper Networks Junos OS Evolved on PTX Series allows an unauthenticated, network-based attacker to execute code as root. The On-Box Anomaly detection framework…

  • CVE-2026-27849CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP connection, which is normally used for configuring devices inside the mesh network. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

  • CVE-2026-27728CriFeb 25, 2026
    risk 0.58cvss 9.9epss 0.03

    OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vulnerability in `NetworkPathMonitor.performTraceroute()` allows any authenticated project user to execute arbitrary operating system commands on the Probe…

  • CVE-2026-27727CriFeb 25, 2026
    risk 0.57cvss 9.8epss 0.02

    mchange-commons-java, a library that provides Java utilities, includes code that mirrors early implementations of JNDI functionality, including support for remote `factoryClassLocation` values, by which code can be downloaded and invoked within a running application. If an…

  • CVE-2026-20129CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an affected system as a user who has the netadmin role. The vulnerability is due to improper authentication for requests that…

  • CVE-2026-20127CriKEVFeb 25, 2026
    risk 0.87cvss 10.0epss 0.88

    A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to…

  • CVE-2026-27848CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection, which are ultimately run as the root user. This issue affects MR9600: 1.0.4.205530; MX4200: 1.0.13.210200.

  • CVE-2026-27847CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    Due to improper neutralization of special elements, SQL statements can be injected via the handshake of a TLS-SRP connection. This can be used to inject known credentials into the database that can be utilized to successfully complete the handshake and use the protected service.…

  • CVE-2026-27702CriFeb 25, 2026
    risk 0.57cvss 9.9epss 0.01

    Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability in Budibase's view filtering implementation allows any authenticated user (including free tier accounts) to execute arbitrary…

  • CVE-2025-69771CriFeb 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform via a crafted .srt subtitle file. Because the script…

  • CVE-2025-1242CriFeb 25, 2026
    risk 0.59cvss 9.1epss 0.01

    The administrative credentials can be extracted through application API responses, mobile application reverse engineering, and device firmware reverse engineering. The exposure may result in an attacker gaining full administrative access to the Gardyn IoT Hub exposing connected…

  • CVE-2026-27699CriFeb 25, 2026
    risk 0.52cvss 9.1epss 0.01

    The `basic-ftp` FTP client library for Node.js contains a path traversal vulnerability (CWE-22) in versions prior to 5.2.0 in the `downloadToDir()` method. A malicious FTP server can send directory listings with filenames containing path traversal sequences (`../`) that cause…

  • CVE-2026-2624CriFeb 25, 2026
    risk 0.67cvss 9.8epss 0.02

    Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301.

  • CVE-2026-0704CriFeb 25, 2026
    risk 0.59cvss 9.1epss 0.00

    In affected version of Octopus Deploy it was possible to remove files and/or contents of files on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows.

  • CVE-2025-62878CriFeb 25, 2026
    risk 0.64cvss 9.9epss 0.01

    A malicious user can manipulate the parameters.pathPattern to create PersistentVolumes in arbitrary locations on the host node, potentially overwriting sensitive files or gaining access to unintended directories.

  • CVE-2026-25785CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system.

  • CVE-2026-27744CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for public ticket pages. The plugin appends untrusted request parameters into HTML that is later rendered by a template using unfiltered…

  • CVE-2026-27743CriFeb 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The SPIP referer_spam plugin versions prior to 1.3.0 contain an unauthenticated SQL injection vulnerability in the referer_spam_ajouter and referer_spam_supprimer action handlers. The handlers read the url parameter from a GET request and interpolate it directly into SQL LIKE…

  • CVE-2026-27641CriFeb 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI).…

  • CVE-2026-27637CriFeb 25, 2026
    risk 0.00cvss 9.8epss 0.01

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.206, FreeScout's `TokenAuth` middleware uses a predictable authentication token computed as `MD5(user_id + created_at + APP_KEY)`. This token is static (never…

  • CVE-2026-27597CriFeb 25, 2026
    risk 0.58cvss 10.0epss 0.01

    Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be used to achieve remote code execution (RCE). The issue has been fixed in version…

  • CVE-2026-27822CriFeb 25, 2026
    risk 0.52cvss 9.0epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to version 1.0.0-alpha.83, a Stored Cross-Site Scripting (XSS) vulnerability in the RustFS Console allows an attacker to execute arbitrary JavaScript in the context of the management console. By bypassing the PDF…

  • CVE-2026-27626CriFeb 25, 2026
    risk 0.57cvss 9.9epss 0.01

    OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, OliveTin's shell mode safety check (`checkShellArgumentSafety`) blocks several dangerous argument types but not `password`. A user supplying a `password`-typed…

  • CVE-2026-27614CriFeb 25, 2026
    risk 0.53cvss 9.3epss 0.00

    Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.13, an unauthenticated attacker who can submit events to a Bugsink project can store arbitrary JavaScript in an event. The payload executes only if a user explicitly views the affected Stacktrace in the web…

  • CVE-2026-27606CriFeb 25, 2026
    risk 0.57cvss 9.8epss 0.02

    Rollup is a module bundler for JavaScript. Versions prior to 2.80.0, 3.30.0, and 4.59.0 of the Rollup module bundler (specifically v4.x and present in current source) is vulnerable to an Arbitrary File Write via Path Traversal. Insecure file name sanitization in the core engine…

  • CVE-2026-24849CriFeb 25, 2026
    risk 0.03cvss 9.9epss 0.02

    OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any…

  • CVE-2026-27593CriFeb 24, 2026
    risk 0.53cvss 9.3epss 0.01

    Statmatic is a Laravel and Git powered content management system (CMS). Prior to versions 6.3.3 and 5.73.10, an attacker may leverage a vulnerability in the password reset feature to capture a user's token and reset the password on their behalf. The attacker must know the email…

  • CVE-2026-22553CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.01

    All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

  • CVE-2026-21410CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.01

    InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.

  • CVE-2026-26342CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X-User-Token) with insufficient expiration. An attacker who obtains a valid token (for example via interception, log exposure, or token reuse on a shared…

  • CVE-2026-26341CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.03

    Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior ship with default credentials that are not forced to be changed during installation or commissioning. An attacker who can reach the management interface can authenticate using the default…

  • CVE-2026-26222CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.02

    Altec DocLink (now maintained by Beyond Limits Inc.) version 4.0.336.0 exposes insecure .NET Remoting endpoints over TCP and HTTP/SOAP via Altec.RDCHostService.exe using the ObjectURI "doclinkServer.soap". The service does not require authentication and is vulnerable to unsafe…

  • CVE-2026-27590CriFeb 24, 2026
    risk 0.57cvss 9.8epss 0.01

    Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's FastCGI path splitting logic computes the split index on a lowercased copy of the request path and then uses that byte index to slice the original path. This is unsafe for Unicode…

  • CVE-2026-27588CriFeb 24, 2026
    risk 0.52cvss 9.1epss 0.01

    Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `host` request matcher is documented as case-insensitive, but when configured with a large host list (>100 entries) it becomes case-sensitive due to an optimized matching path.…

  • CVE-2026-27587CriFeb 24, 2026
    risk 0.52cvss 9.1epss 0.01

    Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, Caddy's HTTP `path` request matcher is intended to be case-insensitive, but when the match pattern contains percent-escape sequences (`%xx`) it compares against the request's escaped path…

  • CVE-2026-27586CriFeb 24, 2026
    risk 0.52cvss 9.1epss 0.00

    Caddy is an extensible server platform that uses TLS by default. Prior to version 2.11.1, two swallowed errors in `ClientAuthentication.provision()` cause mTLS client certificate authentication to silently fail open when a CA certificate file is missing, unreadable, or…

  • CVE-2026-27515CriFeb 24, 2026
    risk 0.59cvss 9.1epss 0.00

    Binardat 10G08-0800GSM network switch firmware versions prior to V300SP10260209 generate predictable numeric session identifiers in the web management interface. An attacker can guess valid session IDs and hijack authenticated sessions.

  • CVE-2026-27507CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain hard-coded administrative credentials that cannot be changed by users. Knowledge of these credentials allows full administrative access to the device.

  • CVE-2025-69985CriFeb 24, 2026
    risk 0.67cvss 9.8epss 0.06

    FUXA 1.2.8 and prior contains an Authentication Bypass vulnerability leading to Remote Code Execution (RCE). The vulnerability exists in the server/api/jwt-helper.js middleware, which improperly trusts the HTTP "Referer" header to validate internal requests. A remote…

  • CVE-2026-27208CriFeb 24, 2026
    risk 0.60cvss 9.2epss 0.01

    bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involving OS Command Injection and Privilege Escalation. This allows an attacker to execute arbitrary commands with root privileges within the container, potentially…

  • CVE-2026-2807CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.00

    Memory safety bugs present in Firefox 147 and Thunderbird 147. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 148 and…

  • CVE-2026-2806CriFeb 24, 2026
    risk 0.59cvss 9.1epss 0.01

    Uninitialized memory in the Graphics: Text component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.

  • CVE-2026-2805CriFeb 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Invalid pointer in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 148 and Thunderbird 148.