VYPR

CVEs

37,387 total · page 19 of 748

  • CVE-2026-68839CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67643CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67636CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.01

    Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67631CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67378CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.01

    Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-65669CriSep 8, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-82533CriSep 8, 2026
    risk 0.55cvss 9.6epss 0.01

    DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the…

  • CVE-2026-79570CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-79569CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-78997CriSep 8, 2026
    risk 0.60cvss 9.3epss 0.00

    UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain…

  • CVE-2026-75156CriSep 8, 2026
    risk 0.52cvss 9.1epss 0.00

    Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are…

  • CVE-2026-26084CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.00

    A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

  • CVE-2026-86840CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.00

    The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…

  • CVE-2026-79574CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

  • CVE-2026-79577CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.

  • CVE-2026-79576CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

  • CVE-2026-79571CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without…

  • CVE-2026-61516CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session.…

  • CVE-2026-12745CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12744CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12650CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12647CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12646CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12645CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-77098CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

  • CVE-2026-77092CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.

  • CVE-2026-77089CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.

  • CVE-2026-78234CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.…

  • CVE-2026-71377CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from…

  • CVE-2026-71376CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20…

  • CVE-2026-62645CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized…

  • CVE-2026-50093CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.00

    A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A…

  • CVE-2026-71374CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through…

  • CVE-2026-86510CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.00

    A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and…

  • CVE-2026-86509CriSep 8, 2026
    risk 0.62cvss 9.6epss 0.00

    A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit…

  • CVE-2026-76969CriSep 8, 2026
    risk 0.61cvss 9.4epss 0.00

    @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or…

  • CVE-2026-66768CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.00

    SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow…

  • CVE-2026-58240CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component…

  • CVE-2026-44756CriSep 8, 2026
    risk 0.65cvss 10.0epss 0.00

    A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and…

  • CVE-2026-86543CriSep 7, 2026
    risk 0.57cvss 9.8epss 0.00

    knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/start endpoint to provision a public tunnel and republish…

  • CVE-2026-86542CriSep 7, 2026
    risk 0.52cvss 9.1epss 0.00

    knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to escape the imports directory and overwrite arbitrary files…

  • CVE-2026-75650CriKEVSep 7, 2026
    risk 0.77cvss 10.0epss 0.02

    Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code.…

  • CVE-2026-86480CriSep 7, 2026
    risk 0.64cvss 9.8epss 0.00

    In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

  • CVE-2026-86478CriSep 7, 2026
    risk 0.64cvss 9.8epss 0.00

    In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

  • CVE-2026-7861CriSep 7, 2026
    risk 0.64cvss 9.8epss 0.00

    Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): before 8.0.3.

  • CVE-2026-18922CriSep 7, 2026
    risk 0.57cvss 9.8epss 0.01

    A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL…

  • CVE-2026-86426CriSep 7, 2026
    risk 0.57cvss 9.8epss 0.02

    LibreNMS before 26.8.0 contains an authentication bypass vulnerability in the REST API that allows unauthenticated attackers to access protected endpoints by sending numeric values instead of string tokens. Attackers can exploit MySQL type coercion by sending small integers like…

  • CVE-2026-86419CriSep 7, 2026
    risk 0.52cvss 9.1epss 0.00

    Affected versions of MISP contain insufficient validation of server-side outbound HTTP destinations in feed retrieval and TAXII discovery functionality. In feed processing, redirects were followed without validating the redirect scheme or destination. The original request…

  • CVE-2026-80238CriSep 7, 2026
    risk 0.60cvss 9.3epss 0.00

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Execution with Unnecessary Privileges vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to…

  • CVE-2026-76578CriSep 7, 2026
    risk 0.57cvss 9.8epss 0.00

    A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory…