VYPR

CVEs

37,805 total · page 2 of 757

  • CVE-2026-102628CriOct 1, 2026
    risk 0.60cvss 9.3epss 0.00

    The Cadmos LTI application hosted at cadmos.eummena.io had Laravel debug mode enabled (APP_DEBUG=true, APP_ENV=local) in a publicly accessible environment. An unauthenticated attacker could send a GET request and trigger an unhandled exception, causing Laravel to expose the…

  • CVE-2026-55083CriOct 1, 2026
    risk 0.52cvss 9.1epss 0.01

    DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization.…

  • CVE-2026-103922CriOct 1, 2026
    risk 0.53cvss 9.3epss 0.00

    Capacitor is a cross-platform native runtime for web applications. From 6.0.0 until 6.2.2, 7.6.9, 8.3.5, 8.4.3, and 8.5.1, the Android and iOS WebView navigation guard validates a target URL's host and scheme but not its path, allowing a victim who activates an untrusted link to…

  • CVE-2026-96659CriOct 1, 2026
    risk 0.59cvss 9.1epss 0.00

    A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as…

  • CVE-2026-96658CriOct 1, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions…

  • CVE-2026-59797CriOct 1, 2026
    risk 0.57cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

  • CVE-2026-57941CriOct 1, 2026
    risk 0.57cvss 9.8epss 0.00

    Use After Free vulnerability in Apache HTTP Server's mod_http2 via shared session->bbtmp re-entrancy This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

  • CVE-2026-56154CriOct 1, 2026
    risk 0.57cvss 9.8epss 0.00

    Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...}) This issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.

  • CVE-2026-13043CriOct 1, 2026
    risk 0.60cvss —epss 0.00

    A missing authentication vulnerability in the Kernel Memory Access Driver (PSKMAD) used by WatchGuard endpoint security products allows a local, authenticated attacker to bypass the driver's access-control handshake and issue arbitrary privileged commands to the driver,…

  • CVE-2026-94620CriOct 1, 2026
    risk 0.54cvss —epss 0.00

    Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the…

  • CVE-2026-12627CriOct 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during client response processing.

  • CVE-2026-79898CriOct 1, 2026
    risk 0.59cvss 9.1epss 0.01

    Fortra BoKS Manager contains a command injection vulnerability in crlserver. An authenticated user authorized to add CRL URLs through BCC, the WSI REST or SOAP API, or the cacrl command-line interface could cause shell command substitution to be processed by crlserver as root on…

  • CVE-2026-62071CriOct 1, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.

  • CVE-2026-103752CriOct 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.

  • CVE-2026-79901CriOct 1, 2026
    risk 0.64cvss 9.9epss 0.00

    In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the service principal and can estimate the…

  • CVE-2026-103264CriOct 1, 2026
    risk 0.52cvss 9.1epss 0.00

    Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware serials as authentication tokens in addition to device UUIDs. Unauthenticated attackers who know or guess these non-secret identifiers can…

  • CVE-2026-103255CriOct 1, 2026
    risk 0.52cvss 9.0epss 0.00

    n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to…

  • CVE-2026-103248CriOct 1, 2026
    risk 0.52cvss 9.0epss 0.00

    n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all…

  • CVE-2026-103244CriOct 1, 2026
    risk 0.57cvss 9.8epss 0.01

    ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore via Socket.IO to plant admin users and…

  • CVE-2026-103655CriOct 1, 2026
    risk 0.53cvss —epss 0.00

    MISP contains a vulnerability in its two-factor authentication (TOTP) verification process that permits a valid one-time code to be accepted more than once within its time-based validity window. The issue exists in the user login flow where a TOTP code is verified as a second…

  • CVE-2026-75957CriOct 1, 2026
    risk 0.57cvss 9.8epss 0.01

    The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checkout` function. This is due to the…

  • CVE-2026-15989CriOct 1, 2026
    risk 0.57cvss 9.8epss 0.00

    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key…

  • CVE-2025-41753CriOct 1, 2026
    risk 0.64cvss 9.8epss 0.01

    The object name of a dynamically created BACnet File Object is interpreted as a file path without sufficient validation. Because relative paths are not limited to the intended directory, an unauthenticated remote attacker can traverse outside of it and read or overwrite…

  • CVE-2026-101148CriOct 1, 2026
    risk 0.65cvss 10.0epss 0.00

    The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an unset or blank key as valid, which allows unauthenticated attackers to create and download full site backups, including the database with user…

  • CVE-2026-92966CriOct 1, 2026
    risk 0.59cvss 9.1epss 0.00

    The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.0. This is due to the software allowing users to execute an action that does not…

  • CVE-2026-82829CriOct 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Hitachi Coding Software Suite contains a vulnerability related to Hidden Functionality vulnerability which allows an attacker to gain unauthorized access by exploiting hidden accounts or hard coded credentials. This issue affects Hitachi Coding Software Suite: through 3.3.0.

  • CVE-2026-82827CriOct 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Hitachi Coding Software Suite contains a vulnerability related to Use of Hard-coded Cryptographic Key. The Hardcoding of JWT signing secret key allows an attacker to generate unauthorized Bearer tokens and exploit administrative functions. This issue affects Hitachi Coding…

  • CVE-2026-82825CriOct 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Hitachi Coding Software Suite contains a vulnerability related to Missing Authentication for Critical Function. This allows an unauthenticated attacker to invoke a critical API, potentially leading to unauthorized retrieval or alteration of sensitive information, or unauthorized…

  • CVE-2026-82824CriOct 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.

  • CVE-2026-76142CriOct 1, 2026
    risk 0.60cvss —epss 0.00

    Insufficient authentication and access control on the internal-only IPC SOAP endpoint of the Genian NAC/ZTNA policy server allows an unauthenticated attacker to invoke internal functions

  • CVE-2026-14157CriOct 1, 2026
    risk 0.61cvss —epss 0.01

    Use of an Externally Controlled Format String in the ASUS Router modules allow a remote authenticated user to execute arbitrary commands via a crafted file uploaded through the web management interface.

  • CVE-2026-101283CriSep 30, 2026
    risk 0.53cvss —epss 0.00

    iperf3 3.20–3.21 (esnet/iperf) has a pre-auth heap buffer overflow in decrypt_rsa_message(): a 256-byte RSA buffer is BIO_read with the attacker-controlled ciphertext length (guard warns only), so an unauthenticated client overflows the heap via an oversized authtoken; fixed…

  • CVE-2026-92173CriSep 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Prior to v74.0.0.878.1682 of Meta Horizon OS, MediaSyncJobReceiver could be induced to send a privileged PendingIntent including a com.oculus.vrshell CallerIdentity to an arbitrary application listening via NotificationListenerService. That would allow the application to…

  • CVE-2026-51872CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Devika v1.0 is vulnerable to Code Injection via the Runner.run_code function in src/agents/runner/runner.py.

  • CVE-2026-51871CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Devika v1.0 is vulnerable to Code Injection in the Runner.execute function in src/agents/runner/runner.py which allows an attacker to achieve arbitrary code execution by exploiting the direct execution of LLM-generated content.

  • CVE-2026-51870CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.01

    DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.

  • CVE-2026-51867CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    agentgpt v.1.0.0 is vulnerable to Incorrect Access Control in next/src/server/api/routers/agentRouter.ts. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a data-access operation without a visible owner, tenant, workspace, or…

  • CVE-2026-51866CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    In DB-GPT 0.7.5 and 0.8.0, a skill uploaded through the real /api/v1/skills/upload route can later be executed through the real /api/v1/chat/react-agent flow.

  • CVE-2026-51864CriSep 30, 2026
    risk 0.59cvss 9.1epss 0.01

    DB-GPT v0.7.5 and v0.8.0 contains directory traversal in python_file_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/python_upload_api.py:42). A remote attacker can use the validated exploitation path to write files outside the intended workspace or storage boundary.

  • CVE-2026-51861CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to Code Injection in src/backend/bisheng/api/v1/validate.py.

  • CVE-2026-51859CriSep 30, 2026
    risk 0.59cvss 9.1epss 0.01

    bisheng 2.3.0, 2.4.0, and 2.4.0-beta1 is vulnerable to directory traversal in save_download_file (src/backend/bisheng/core/cache/utils.py:290).

  • CVE-2026-51858CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, TerminalToolkit.shell_exec allows prompt-driven shell command execution without an approval boundary.

  • CVE-2026-51857CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    In camel-ai camel 0.2.91a1, v0.2.91a2 and v0.2.91a3, CodeExecutionToolkit can run model-produced Python code through SubprocessInterpreter without an approval boundary.

  • CVE-2026-51856CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    In agentscope 1.0.18, 1.0.19, and 1.0.19 when the RealtimeAgent session exposes execute_python_code as an available tool, a remote WebSocket user can prompt the agent to call that tool and run Python code in the service environment. In the validated path, RealtimeAgent._acting…

  • CVE-2026-102149CriSep 30, 2026
    risk 0.61cvss 9.4epss 0.00

    Kiteworks Email Protection Gateway did not sufficiently restrict which account a certificate could be assigned to. This could allow an attacker to associate a certificate with another user's account, affecting the confidentiality and integrity of that account's encrypted mail…

  • CVE-2026-102147CriSep 30, 2026
    risk 0.60cvss 9.3epss 0.00

    A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauthenticated attacker to store crafted content that later executes arbitrary JavaScript in the authenticated session of an administrator who views the affected page. This could have permitted the…

  • CVE-2026-102115CriSep 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Kiteworks Core did not correctly validate a parameter submitted to the password reset workflow. An unauthenticated attacker who knew the email address of a user with a locally stored password could potentially reset that account's password without access to the emailed reset…

  • CVE-2026-102106CriSep 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper authentication in a Kiteworks Email Protection Gateway administrative service. An administrative service in Kiteworks Email Protection Gateway did not consistently enforce administrator authentication, so the required password check could be bypassed. An attacker who…

  • CVE-2026-102105CriSep 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted…

  • CVE-2026-102104CriSep 30, 2026
    risk 0.59cvss 9.1epss 0.00

    Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Server-Side Request Forgery (SSRF). A server-side request forgery (SSRF) weakness in Kiteworks Email Protection Gateway could allow a remote, unauthenticated attacker to induce the gateway to issue crafted…