VYPR

CVEs

37,387 total · page 20 of 748

  • CVE-2026-6223CriSep 7, 2026
    risk 0.61cvss 9.4epss 0.00

    Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat App: from 2.1.7 through 07092026. NOTE: The vendor was contacted early about this disclosure but did not…

  • CVE-2026-61410CriSep 7, 2026
    risk 0.61cvss 9.4epss 0.01

    Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to remote…

  • CVE-2026-86299CriSep 7, 2026
    risk 0.65cvss 9.9epss 0.02

    A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command…

  • CVE-2026-86296CriSep 7, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The…

  • CVE-2026-79698CriSep 7, 2026
    risk 0.64cvss 9.9epss 0.02

    A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This…

  • CVE-2026-79697CriSep 7, 2026
    risk 0.65cvss 9.9epss 0.03

    A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects…

  • CVE-2026-16876CriSep 7, 2026
    risk 0.60cvss —epss 0.00

    An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

  • CVE-2026-86304CriSep 6, 2026
    risk 0.57cvss 9.8epss 0.00

    MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor. parse_assertion in MojoX::Authentication::Model::SAML2 calls Net::SAML2::Binding::POST->new with no cacert,…

  • CVE-2026-86219CriSep 6, 2026
    risk 0.57cvss 9.8epss 0.00

    Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept replayed authentication responses via unverified nonce in server_step. server_start generates a fresh nonce and sends it in the challenge, and nothing later compares that value against the nonce the client…

  • CVE-2026-19931CriSep 6, 2026
    risk 0.57cvss 9.8epss 0.01

    A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

  • CVE-2026-18924CriSep 6, 2026
    risk 0.52cvss 9.1epss 0.01

    A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

  • CVE-2026-86167CriSep 6, 2026
    risk 0.64cvss 9.9epss 0.02

    A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote exploitation of the attack is possible.…

  • CVE-2026-86165CriSep 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-86218CriKEVSep 6, 2026
    risk 0.76cvss 9.8epss 0.07

    N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

  • CVE-2026-75816CriSep 6, 2026
    risk 0.57cvss 9.8epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and…

  • CVE-2026-16310CriSep 6, 2026
    risk 0.64cvss 9.8epss 0.00

    The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the…

  • CVE-2026-86153CriSep 6, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

  • CVE-2026-86152CriSep 6, 2026
    risk 0.65cvss 10.0epss 0.02

    A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

  • CVE-2026-86151CriSep 6, 2026
    risk 0.59cvss 9.1epss 0.02

    A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.

  • CVE-2026-86149CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.02

    A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

  • CVE-2026-86148CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.02

    A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack…

  • CVE-2026-86060CriKEVSep 5, 2026
    risk 0.76cvss 9.8epss 0.01

    RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to…

  • CVE-2026-67276CriSep 5, 2026
    risk 0.60cvss —epss 0.00

    RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an…

  • CVE-2026-86190CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.00

    WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the…

  • CVE-2026-86189CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext…

  • CVE-2026-86184CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint…

  • CVE-2026-10196CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This…

  • CVE-2026-86124CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.01

    AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute arbitrary bash commands within the…

  • CVE-2026-86121CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reach TCP port 8000 to run shell commands…

  • CVE-2024-11080CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to…

  • CVE-2026-78362CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take…

  • CVE-2026-83627CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written…

  • CVE-2026-13447CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates…

  • CVE-2026-52777CriSep 5, 2026
    risk 0.54cvss —epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

  • CVE-2026-52766CriSep 5, 2026
    risk 0.52cvss 9.1epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in…

  • CVE-2026-75925CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending…

  • CVE-2026-50894CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.

  • CVE-2025-67066CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

  • CVE-2026-79391CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or…

  • CVE-2026-71625CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

  • CVE-2026-71624CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

  • CVE-2026-81939CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.01

    A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

  • CVE-2026-78328CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.01

    A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

  • CVE-2026-78327CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.02

    An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that…

  • CVE-2026-57163CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c).…

  • CVE-2026-57162CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This…

  • CVE-2026-78745CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

  • CVE-2026-75430CriSep 4, 2026
    risk 0.57cvss 9.8epss 0.01

    PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-31020CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An…

  • CVE-2026-75431CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.