VYPR

CVEs

37,387 total · page 16 of 748

  • CVE-2026-85228CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted…

  • CVE-2026-68488CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

  • CVE-2026-68487CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

  • CVE-2026-65639CriSep 10, 2026
    risk 0.62cvss —epss 0.02

    OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects…

  • CVE-2026-65638CriSep 10, 2026
    risk 0.60cvss —epss 0.03

    Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by…

  • CVE-2026-52098CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/ endpoint

  • CVE-2026-88899CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.00

    knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

  • CVE-2026-88018CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty…

  • CVE-2026-81468CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.02

    Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2026-81467CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.03

    Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2026-81048CriSep 10, 2026
    risk 0.63cvss 9.6epss 0.01

    Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote…

  • CVE-2026-81046CriSep 10, 2026
    risk 0.61cvss 9.4epss 0.00

    Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.

  • CVE-2026-88008CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns…

  • CVE-2026-88007CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each…

  • CVE-2026-81800CriSep 10, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

  • CVE-2026-88877CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.00

    Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such…

  • CVE-2026-88869CriSep 10, 2026
    risk 0.53cvss 9.3epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through…

  • CVE-2026-88864CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning…

  • CVE-2026-38626CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

  • CVE-2026-9163CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.

  • CVE-2026-78082CriSep 10, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and…

  • CVE-2026-8323CriSep 10, 2026
    risk 0.60cvss 9.3epss 0.00

    URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

  • CVE-2026-88285CriSep 10, 2026
    risk 0.61cvss 9.4epss 0.00

    GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.

  • CVE-2026-88278CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

  • CVE-2026-59679CriSep 10, 2026
    risk 0.59cvss 9.0epss 0.00

    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The…

  • CVE-2026-44950CriSep 10, 2026
    risk 0.59cvss 9.0epss 0.00

    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination…

  • CVE-2026-13745CriSep 10, 2026
    risk 0.53cvss —epss 0.00

    A vulnerability in the Gemini CLI and associated GitHub Action allowed an unprivileged attacker to achieve an arbitrary code execution in Gemini CLI via untrusted local .env files overriding GEMINI_CLI_HOME.

  • CVE-2026-80352CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource…

  • CVE-2026-80351CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. An improper neutralization of directives in dynamically evaluated Maven configuration allows tenant-controlled repository content to influence code…

  • CVE-2026-7188CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2.

  • CVE-2026-78361CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation checks on one of its front-end request handlers, and does not restrict which option name a caller may supply, allowing unauthenticated users to delete arbitrary…

  • CVE-2026-77770CriSep 10, 2026
    risk 0.65cvss 10.0epss 0.00

    The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a validated transaction before deleting site options whose names come from unauthenticated request input, allowing any visitor to delete arbitrary options, which can…

  • CVE-2026-84939CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default enabled). This issue affects Apache…

  • CVE-2026-67593CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through…

  • CVE-2026-57967CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from…

  • CVE-2026-49364CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. …

  • CVE-2026-19583CriSep 10, 2026
    risk 0.57cvss 9.9epss 0.01

    Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for…

  • CVE-2026-18351CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid()…

  • CVE-2026-87931CriSep 10, 2026
    risk 0.62cvss 9.6epss 0.00

    A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be…

  • CVE-2026-88069CriSep 9, 2026
    risk 0.53cvss —epss 0.00

    Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted archive or disk image, attacker-controlled file paths could be used without ensuring that the resulting destination remained within the intended extraction…

  • CVE-2026-71805CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers can upload arbitrary files and write them outside the intended storage directory via the directory parameter in POST /app-api/infra/file/upload.

  • CVE-2026-71801CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core configuration file, which is not overridden or removed in the production environment profile. A remote, unauthenticated attacker can…

  • CVE-2026-36433CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components

  • CVE-2026-87911CriSep 9, 2026
    risk 0.62cvss 9.6epss 0.01

    An OS command injection weakness in the read-only enforcement of the SQL validation component in Amazon awslabs postgres-mcp-server before 1.1.7 might allow an unauthenticated actor to execute operating system commands on the host of a self-managed PostgreSQL server by placing a…

  • CVE-2026-54694CriSep 9, 2026
    risk 0.55cvss 9.6epss 0.00

    SkillTree is a micro-learning gamification platform. Prior to version 4.4.2, two independent code flaws combine into a single exploitable attack chain, with three distinct exploitation paths of escalating impact. `StringHighlighter.js` builds an HTML string by interpolating raw…

  • CVE-2026-87929CriSep 9, 2026
    risk 0.64cvss 9.8epss 0.00

    MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can mint a malicious ci_session cookie with…

  • CVE-2026-47156CriSep 9, 2026
    risk 0.53cvss —epss 0.01

    MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowing their username), including the…

  • CVE-2026-68484CriSep 9, 2026
    risk 0.59cvss —epss 0.00

    Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges.

  • CVE-2026-67403CriSep 9, 2026
    risk 0.59cvss —epss 0.00

    Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant…

  • CVE-2026-67401CriSep 9, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component