VYPR

CVEs

38,008 total · page 164 of 761

  • CVE-2026-25227CriFeb 12, 2026
    risk 0.00cvss 9.1epss 0.01

    authentik is an open-source identity provider. From 2021.3.1 to before 2025.8.6, 2025.10.4, and 2025.12.4, when using delegated permissions, a User that has the permission Can view * Property Mapping or Can view Expression Policy is able to execute arbitrary code within the…

  • CVE-2026-24895CriFeb 12, 2026
    risk 0.57cvss 9.8epss 0.01

    FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters during case conversion. The logic computes the split index (for finding .php) on a lowercased copy of the request path but applies…

  • CVE-2026-24044CriFeb 12, 2026
    risk 0.60cvss —epss 0.00

    Element Server Suite Community Edition (ESS Community) deploys a Matrix stack using the provided Helm charts and Kubernetes distribution. The ESS Community Helm Chart secrets initialization hook (using matrix-tools container before 0.5.7) is using an insecure Matrix server key…

  • CVE-2025-70314CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable

  • CVE-2026-26219CriFeb 12, 2026
    risk 0.59cvss 9.1epss 0.00

    newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other…

  • CVE-2026-26218CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.01

    newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default…

  • CVE-2025-70981CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

  • CVE-2026-26216CriFeb 12, 2026
    risk 0.58cvss 10.0epss 0.06

    Crawl4AI versions prior to 0.8.0 contain a remote code execution vulnerability in the Docker API deployment. The /crawl endpoint accepts a hooks parameter containing Python code that is executed using exec(). The __import__ builtin was included in the allowed builtins, allowing…

  • CVE-2025-69634CriFeb 12, 2026
    risk 0.59cvss 9.0epss 0.00

    Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token…

  • CVE-2025-14014CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before…

  • CVE-2025-10969CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E-Commerce Services Inc. E-Commerce Package allows Blind SQL Injection. This issue affects E-Commerce Package: through 27112025.

  • CVE-2025-15573CriFeb 12, 2026
    risk 0.61cvss 9.4epss 0.00

    The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in the Alibaba Cloud (mqtt001.solaxcloud.com, TCP 8883). This allows attackers in a man-in-the-middle position to act as the legitimate MQTT server and issue…

  • CVE-2025-14892CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.00

    The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having any kind of account on the targeted site and perform unauthorized actions due to a hardcoded secret.

  • CVE-2026-1729CriFeb 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it…

  • CVE-2026-26215CriFeb 11, 2026
    risk 0.61cvss —epss 0.01

    manga-image-translator version beta-0.3 and prior in shared API mode contains an unsafe deserialization vulnerability that can lead to unauthenticated remote code execution. The FastAPI endpoints /simple_execute/{method} and /execute/{method} deserialize attacker-controlled…

  • CVE-2026-20677CriFeb 11, 2026
    risk 0.59cvss 9.0epss 0.00

    A race condition was addressed with improved handling of symbolic links. This issue is fixed in iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, visionOS 26.3. A shortcut may be able to bypass sandbox…

  • CVE-2025-67135CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access control via a code replay attack.

  • CVE-2026-26021CriFeb 11, 2026
    risk 0.57cvss 9.8epss 0.01

    set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input…

  • CVE-2026-25994CriFeb 11, 2026
    risk 0.03cvss 9.8epss 0.02

    PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a buffer overflow vulnerability exists in PJNATH ICE Session when processing credentials with excessively long usernames.

  • CVE-2020-37186CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP shell file and execute arbitrary system…

  • CVE-2020-37184CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite SEH handlers and execute system commands by injecting malicious…

  • CVE-2020-37183CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload in the License Name input field to…

  • CVE-2020-37181CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) through a malicious registration code input. Attackers can craft a payload with specific offsets and partial SEH overwrite…

  • CVE-2020-37176CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Torrent 3GP Converter 1.51 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload targeting the application's registration dialog to trigger code…

  • CVE-2020-37153CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.05

    ASTPP 4.0.1 contains multiple vulnerabilities including cross-site scripting and command injection in SIP device configuration and plugin management interfaces. Attackers can exploit these flaws to inject system commands, hijack administrator sessions, and potentially execute…

  • CVE-2025-69872CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache directory can achieve arbitrary code execution when a victim application reads from the cache.

  • CVE-2025-70085CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf to format two filenames (Source1Filename and the string returned by FileUtil_FileStateStr) into this buffer without any length checking and without using…

  • CVE-2025-69874CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.

  • CVE-2026-25084CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Authentication for ZLAN5143D can be bypassed by directly accessing internal URLs.

  • CVE-2026-24789CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    An unprotected API endpoint allows an attacker to remotely change the device password without providing authentication.

  • CVE-2025-64075CriFeb 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows remote attackers to bypass authentication and perform administrative actions by supplying a crafted session cookie value.

  • CVE-2026-2249CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    METIS DFS devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges. This results in…

  • CVE-2026-2248CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    METIS WIC devices (versions <= oscore 2.1.234-r18) expose a web-based shell at the /console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with root (UID 0) privileges. This results…

  • CVE-2025-12059CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry and Trade Inc. Logo j-Platform allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Logo j-Platform: from 3.29.6.4…

  • CVE-2025-8668CriFeb 11, 2026
    risk 0.61cvss 9.4epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07…

  • CVE-2025-8025CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was…

  • CVE-2025-66277CriFeb 11, 2026
    risk 0.64cvss 9.8epss 0.01

    A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2026-1357CriFeb 11, 2026
    risk 0.59cvss 9.8epss 0.33

    The Migration, Backup, Staging – WPvivid Backup & Migration plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Upload in versions up to and including 0.9.123. This is due to improper error handling in the RSA decryption process combined with a lack of path…

  • CVE-2026-26009CriFeb 10, 2026
    risk 0.57cvss 9.9epss 0.01

    Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install scripts defined in server templates execute directly on the host operating system as root via bash -c, with no sandboxing or containerization. Any user with…

  • CVE-2026-25993CriFeb 10, 2026
    risk 0.00cvss 9.8epss 0.01

    EverShop is a TypeScript-first eCommerce platform. During category update and deletion event handling, the application embeds path / request_path values—derived from the url_key stored in the database—into SQL statements via string concatenation and passes them to execute().…

  • CVE-2026-21531CriFeb 10, 2026
    risk 0.64cvss 9.8epss 0.02

    Deserialization of untrusted data in Azure SDK allows an unauthorized attacker to execute code over a network.

  • CVE-2026-1774CriFeb 10, 2026
    risk 0.57cvss 9.8epss 0.01

    CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

  • CVE-2026-23906CriFeb 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension enabled * LDAP authenticator configured * Underlying LDAP server permits anonymous bind   …

  • CVE-2025-11242CriFeb 10, 2026
    risk 0.64cvss 9.8epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade Inc. Okulistik allows Server Side Request Forgery. This issue affects Okulistik: through 21102025.

  • CVE-2026-2096CriFeb 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Agentflow developed by Flowring has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents by using a specific functionality.

  • CVE-2026-2095CriFeb 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Agentflow developed by Flowring has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to exploit a specific functionality to obtain arbitrary user authentication token and log into the system as any user.

  • CVE-2026-0509CriFeb 10, 2026
    risk 0.62cvss 9.6epss 0.00

    SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no…

  • CVE-2026-0488CriFeb 10, 2026
    risk 0.64cvss 9.9epss 0.01

    An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database…

  • CVE-2026-25939CriFeb 9, 2026
    risk 0.52cvss 9.1epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through version 1.2.10, an authorization bypass vulnerability in the FUXA allows an unauthenticated, remote attacker to create and modify arbitrary schedulers, exposing connected ICS/SCADA…

  • CVE-2026-25938CriFeb 9, 2026
    risk 0.57cvss 9.8epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. From 1.2.8 through 1.2.10, an authentication bypass vulnerability in FUXA allows an unauthenticated, remote attacker to execute arbitrary code on the server when the Node-RED plugin is enabled. This has…