VYPR

CVEs

373,797 total · page 16 of 7,476

  • CVE-2026-87985CriSep 11, 2026
    risk 0.65cvss epss 0.00

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using ANSI-C quoted arguments. These arguments are not properly inspected, enabling a crafted allowlisted command to execute arbitrary code on the user's system…

  • CVE-2026-87984CriSep 11, 2026
    risk 0.60cvss epss 0.00

    An arbitrary file write vulnerability in Mistral Vibe, introduced in version 1.3.4, allows an attacker to create or overwrite files outside the active workspace without user approval. Shell redirection destinations are omitted from permission checks, enabling otherwise…

  • CVE-2026-87983CriSep 11, 2026
    risk 0.60cvss epss 0.00

    An arbitrary file read vulnerability in Mistral Vibe, introduced in version 2.6.0, allows an attacker to bypass workspace restrictions using quoted absolute paths in allowlisted shell commands. Improper handling of quotation marks during path validation enables files outside the…

  • CVE-2026-87020HigSep 11, 2026
    risk 0.53cvss 8.1epss 0.01

    An integer overflow in a specified pitch and buffer-size computation leads to a heap out-of-bounds write when Orthanc DICOM Server decodes an attacker-supplied PNG.

  • CVE-2026-85979HigSep 11, 2026
    risk 0.56cvss epss 0.01

    Affected versions of Puppet Enterprise contain a command injection vulnerability in the handling of the java_keystore_passwd parameter. An authenticated user with Puppet administrative privileges can inject arbitrary shell commands by providing a specially crafted value for this…

  • CVE-2026-85083MedSep 11, 2026
    risk 0.44cvss 6.8epss 0.00

    The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and…

  • CVE-2026-82583HigSep 11, 2026
    risk 0.54cvss 8.3epss 0.00

    NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQL through a Database Connector API, which could result in disclosure of stored credentials for connected systems, arbitrary file write, and a denial-of-service condition.

  • CVE-2026-82578HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

  • CVE-2026-78224HigSep 11, 2026
    risk 0.53cvss 8.2epss 0.00

    The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE injection can allow data exfiltration and denial-of-service attacks.

  • CVE-2026-38058HigSep 11, 2026
    risk 0.53cvss 8.1epss 0.00

    The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these…

  • CVE-2026-38056HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link…

  • CVE-2026-89298MedSep 11, 2026
    risk 0.32cvss 4.9epss 0.00

    A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask…

  • CVE-2026-89212HigSep 11, 2026
    risk 0.56cvss 8.6epss 0.00

    A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were improperly restricted during XML-to-JSON processing. The issue affects Akana versions 2026.1, 2025.1.1, and all versions before 2024.1.6 (including older unsupported versions…

  • CVE-2026-71644CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in Robotics-STAR-Lab (SYSU STAR Group) RACER Tested affected version: commit abcdef1234567890 allows an attacker to cause unsafe trajectory planning and potential UAV collisions via a missing default case in the FSM that stops publishing swarm trajectories when the…

  • CVE-2026-71641Sep 11, 2026
    risk 0.00cvss epss 0.00

    An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an attacker to cause a denial of service via thenteraction between traj_server, poscmd_2_odom, and the EGOReplanFSM emergency recovery logic

  • CVE-2026-71416HigSep 11, 2026
    risk 0.50cvss 8.8epss 0.00

    Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious…

  • CVE-2026-57843MedSep 11, 2026
    risk 0.36cvss 5.5epss 0.00

    NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local users to obtain real kernel virtual addresses by opening world-accessible devices such as /dev/null or /dev/zero, which incorrectly receive the PK_KMEM process…

  • CVE-2026-57842HigSep 11, 2026
    risk 0.45cvss 7.0epss 0.00

    NetBSD contains a use-after-free and double-free vulnerability in msg_recv_copyin() within the COMPAT_NETBSD32 compatibility layer due to a missing return statement before the cleanup label on the success path. Any local user able to execute a 32-bit binary on a 64-bit NetBSD…

  • CVE-2026-15710MedSep 11, 2026
    risk 0.44cvss epss 0.00

    An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper…

  • CVE-2026-11765LowSep 11, 2026
    risk 0.21cvss 3.3epss 0.00

    Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Argument Injection. This issue affects Pardus Pen: before 4.2.1.

  • CVE-2026-84390CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access control via

  • CVE-2026-80462CriSep 11, 2026
    risk 0.65cvss 10.0epss 0.00

    A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific conditions.

  • CVE-2026-89259CriSep 11, 2026
    risk 0.57cvss 9.8epss 0.00

    Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissive configuration (--allow-addons, --allow-child-process, --allow-worker). As…

  • CVE-2026-89258MedSep 11, 2026
    risk 0.34cvss 6.3epss 0.00

    Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypassed. An attacker who can place — or who convinces a site author to place — a…

  • CVE-2026-89257MedSep 11, 2026
    risk 0.28cvss 5.4epss 0.00

    AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the attacker-supplied $_REQUEST['id'] to…

  • CVE-2026-89256HigSep 11, 2026
    risk 0.50cvss 8.7epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via…

  • CVE-2026-89255HigSep 11, 2026
    risk 0.50cvss 8.7epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by…

  • CVE-2026-89254HigSep 11, 2026
    risk 0.50cvss 8.7epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php…

  • CVE-2026-89253HigSep 11, 2026
    risk 0.50cvss 8.7epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(...,…

  • CVE-2026-89252MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS source and metadata by…

  • CVE-2026-89251MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST…

  • CVE-2026-89250HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed…

  • CVE-2026-89249HigSep 11, 2026
    risk 0.50cvss 8.7epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators…

  • CVE-2026-89248MedSep 11, 2026
    risk 0.27cvss 5.3epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON…

  • CVE-2026-89247MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emits Content-Type: application/xml and…

  • CVE-2026-89246MedSep 11, 2026
    risk 0.28cvss 5.4epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated users can inject formulas starting with…

  • CVE-2026-89245MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can craft a malicious form that submits a POST…

  • CVE-2026-89244MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href attribute without HTML encoding, allowing…

  • CVE-2026-89243HigSep 11, 2026
    risk 0.46cvss 8.1epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inject malicious HTML and…

  • CVE-2026-89242HigSep 11, 2026
    risk 0.40cvss 7.2epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can POST file paths or HTTP URLs…

  • CVE-2026-89241MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote…

  • CVE-2026-89240MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $securityFilter) directly into…

  • CVE-2026-89239MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding. Attackers can craft a Referer header…

  • CVE-2026-89148MedSep 11, 2026
    risk 0.28cvss 5.4epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does not run, and when the request…

  • CVE-2026-87776HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroyed, so each aborted compressed response…

  • CVE-2026-86793Sep 11, 2026
    risk 0.00cvss epss 0.00

    SGLang allows unauthenticated pickle deserialization through /update_weights_from_tensor when no auth keys are configured, and the SafeUnpickler policy can be bypassed because builtins.import and builtins.getattr are resolvable, enabling code execution via pickle REDUCE.

  • CVE-2024-12145MedSep 11, 2026
    risk 0.21cvss 4.3epss 0.00

    The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers,…

  • CVE-2026-89147HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data,…

  • CVE-2026-89146HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process…

  • CVE-2026-86813MedSep 11, 2026
    risk 0.31cvss 4.8epss 0.00

    The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends…