VYPR

CVEs

374,535 total · page 21 of 7,491

  • CVE-2026-77006CriSep 12, 2026
    risk 0.62cvss 9.6epss 0.00

    The WebTotem Backups WordPress plugin through 1.0.1 does not validate a user-supplied file path, does not check the capability of the user making the request, and discards the result of its own CSRF check, allowing any authenticated user, such as a subscriber, to delete…

  • CVE-2026-77005CriSep 12, 2026
    risk 0.62cvss 9.6epss 0.00

    The CODE MONKEYS PROPOSALS WordPress plugin through 1.0.1 does not validate a user-supplied file path before deleting a file, and does not check the capability of the user making the request, allowing any authenticated user, such as a subscriber, to delete arbitrary files on…

  • CVE-2026-75800CriSep 12, 2026
    risk 0.64cvss 9.8epss 0.00

    The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary…

  • CVE-2026-87719CriSep 12, 2026
    risk 0.64cvss 9.9epss 0.01

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could allow an authenticated user with Duo Chat access to obtain Advanced Search instance configurations and…

  • CVE-2026-85706CriKEVSep 12, 2026
    risk 0.77cvss 10.0epss 0.11

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path…

  • CVE-2026-90467MedSep 12, 2026
    risk 0.19cvss 4.0epss 0.00

    aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP parameters into MAIL FROM and RCPT TO command lines. Attackers can craft malicious addresses containing spaces and angle brackets to append parameters like…

  • CVE-2026-89268MedSep 12, 2026
    risk 0.28cvss 5.4epss 0.00

    QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers,…

  • CVE-2026-89267MedSep 12, 2026
    risk 0.21cvss 4.3epss 0.00

    starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the searchable_fields allowlist when configured as an empty list, allowing authenticated users to filter on non-searchable fields. Attackers can submit structured filter queries via the list API's where parameter to…

  • CVE-2026-89266HigSep 12, 2026
    risk 0.53cvss 8.2epss 0.00

    stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes,…

  • CVE-2026-90461MedSep 11, 2026
    risk 0.41cvss 6.3epss 0.00

    OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.

  • CVE-2026-90460HigSep 11, 2026
    risk 0.49cvss epss 0.00

    An issue was discovered in OpenStack Keystone before 29.0.3. Tokens obtained via delegated authentication methods (EC2 credentials, application credentials, OAuth1 access tokens, and trusts) are not blocked from creating, modifying, or deleting credentials via the…

  • CVE-2026-90457MedSep 11, 2026
    risk 0.38cvss epss 0.00

    The administrative password is hashed using a comparatively weak, fast algorithm for the credential store backing one authentication path, and the file containing that hash is written with permissions allowing it to be read by any local user. This is inconsistent with a…

  • CVE-2026-90456CriSep 11, 2026
    risk 0.53cvss epss 0.00

    An example environment-configuration file for a bundled inventory-management component ships with a fixed, publicly-known administrative password. A deployment that copies this example file into active configuration without running the setup routine that regenerates credentials…

  • CVE-2026-90455MedSep 11, 2026
    risk 0.34cvss epss 0.00

    A prior update that raised a bundled HTTP client library to a version remediating known vulnerabilities was later reverted, reintroducing the earlier, vulnerable version into a log-processing component. The only code path in that component using the library issues a request to a…

  • CVE-2026-90454MedSep 11, 2026
    risk 0.27cvss epss 0.00

    A deployment mode intended to expose only read access to a bundled packet-analysis component's interface denies a list of write-capable routes by pattern, but the pattern omits routes that modify tags attached to stored session records, and the proxy configuration otherwise…

  • CVE-2026-90453MedSep 11, 2026
    risk 0.26cvss epss 0.00

    A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer header, without validating it against the application's own origin. This allows an authenticated attacker to craft a request that causes another user's…

  • CVE-2026-90452MedSep 11, 2026
    risk 0.32cvss epss 0.00

    Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exchange do not verify the identity provider's server certificate. An attacker positioned on the network path between the proxy and the identity provider could…

  • CVE-2026-90451HigSep 11, 2026
    risk 0.46cvss epss 0.00

    An example environment-configuration file ships with a fixed, publicly-known secret value used to sign authentication cookies for a bundled packet-analysis component. A deployment that copies this example file into active configuration without running the setup routine that…

  • CVE-2026-90450MedSep 11, 2026
    risk 0.27cvss epss 0.00

    The application's role-authorization lookup defaults to granting access when a request handler's name is not present in its table of role requirements, rather than defaulting to deny. Any request handler that is not explicitly registered in this table is reachable by any…

  • CVE-2026-90449MedSep 11, 2026
    risk 0.38cvss epss 0.00

    When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party administrative interface directly to that interface without applying the gateway's own authentication requirement first. All access control for this administrative…

  • CVE-2026-90448HigSep 11, 2026
    risk 0.39cvss epss 0.00

    A deployment mode intended to expose only read access to stored data proxies a set of application programming interface routes without restricting which request methods are allowed. One such route accepts a request that creates or overwrites a stored record, including an…

  • CVE-2026-90447HigSep 11, 2026
    risk 0.39cvss epss 0.00

    A routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-supplied request header, rather than on any property the client cannot control. An authenticated user in possession of a shared service…

  • CVE-2026-90446MedSep 11, 2026
    risk 0.27cvss epss 0.00

    An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path of a backend request to the underlying search and analytics data store, without restricting its contents. This allows an authenticated attacker to substitute an…

  • CVE-2026-90445HigSep 11, 2026
    risk 0.39cvss epss 0.00

    An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries…

  • CVE-2026-90444HigSep 11, 2026
    risk 0.50cvss epss 0.00

    A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shell metacharacters. An automated process later constructs and runs a system command using the uploaded file's name, allowing an authenticated attacker to embed…

  • CVE-2026-90443MedSep 11, 2026
    risk 0.27cvss epss 0.00

    A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes…

  • CVE-2026-54258MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View` permissions to directly fetch media for events belonging…

  • CVE-2026-54248MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided deployment config to influence the policy…

  • CVE-2026-54241HigSep 11, 2026
    risk 0.41cvss 7.4epss 0.00

    libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer…

  • CVE-2026-54240HigSep 11, 2026
    risk 0.41cvss 7.4epss 0.00

    libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or…

  • CVE-2026-50018MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow (accepts TCP connection but never responds), each…

  • CVE-2026-50013HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). When multiple proxy requests are processed concurrently (the…

  • CVE-2026-49992MedSep 11, 2026
    risk 0.34cvss epss 0.00

    Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request forgery issues in their default team creation shortcuts for projects, customers, and activities. These endpoints are exposed through `GET` routes and directly…

  • CVE-2026-49846HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes…

  • CVE-2026-48496MedSep 11, 2026
    risk 0.33cvss 6.2epss 0.00

    OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to open a nonregular mapping file, such as a…

  • CVE-2026-45056MedSep 11, 2026
    risk 0.38cvss epss 0.00

    matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix clients. Starting in version 0.12.0 and prior to version 0.17.0, the matrix-sdk-crypto crate was missing a check for the user ID when decrypting an Olm-encrypted…

  • CVE-2026-44715HigSep 11, 2026
    risk 0.57cvss epss 0.00

    OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticated user can trigger administrative DWR services. Specifically, the `startHl7ArchiveMigration` method is accessible, which should be restricted to admin-level…

  • CVE-2026-59973higSep 11, 2026
    risk 0.38cvss epss

    ## Summary The published fix for GHSA-v6ph-xcq9-qxxj / CVE-2026-39885 added a direct hostname denylist for OpenAPI external `$ref` dereferencing, but the latest patched dependency `mcp-from-openapi` 2.3.0 still makes backend-origin requests to loopback when the target is…

  • CVE-2026-56825higSep 11, 2026
    risk 0.38cvss epss

    ## Title Missing authorization on product removal actions in CollectionProducts component ## Description A lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside `packages/admin/src/Livewire/Components/Collection/Col…

  • CVE-2026-56830Sep 11, 2026
    risk 0.00cvss epss

    ## Title Missing authorization on Media sub-form store action allows unpermissioned product media update ## Description A lack of authorization control on the `store()` method was found in `packages/admin/src/Livewire/Components/Products/Form/Media.php`. The security fix…

  • CVE-2026-56829higSep 11, 2026
    risk 0.38cvss epss

    ## Title Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component ## Description A lack of authorization control was discovered in the `stockAction()` method in `packages/admin/src/Livewire/Components/Products/VariantStock.php`. The…

  • CVE-2026-56828higSep 11, 2026
    risk 0.38cvss epss

    ## Summary Three Livewire admin components in `shopper/framework` (latest master at commit `fcd0c59`, released as v2.8.0) gate state-mutating actions on the read-only `view_users` permission. This is the same class as the issue Shopper fixed in v2.8.0 / PR #511 /…

  • CVE-2026-56826Sep 11, 2026
    risk 0.00cvss epss

    ## Summary Four Livewire components in the Settings area expose destructive Filament actions (`delete` / `edit`) that perform **no server-side authorization**. Any authenticated user who can reach the Settings pages — i.e. holding only the coarse `access_setting` permission,…

  • CVE-2026-56831Sep 11, 2026
    risk 0.00cvss epss

    ## Summary The Shopper Framework discount management functionality accepts negative discount values without server-side validation. It was confirmed that negative fixed-amount discounts can be created through the administrative interface, persisted to the database, and…

  • CVE-2026-81918MedSep 11, 2026
    risk 0.24cvss epss 0.00

    Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A user with edit_page_contents permissions could store a payload which executes in the browser of any visitor who viewed a page where the block was configured to…

  • CVE-2026-81917MedSep 11, 2026
    risk 0.26cvss epss 0.00

    Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the Document Library block, so a user with permission to edit file properties could store a script payload that executed in the browser of any visitor to a page…

  • CVE-2026-81907MedSep 11, 2026
    risk 0.33cvss epss 0.00

    Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function (POST /index.php/dashboard/system/express/entities/delete_entries) because the controller records but does not enforce a failed CSRF token check, allowing the…

  • CVE-2026-68535MedSep 11, 2026
    risk 0.33cvss epss 0.00

    Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's validate() method on submitted data, which, for file-referencing blocks such as hero_image and gallery, is where the referenced file is authorized against the…

  • CVE-2026-54174HigSep 11, 2026
    risk 0.47cvss 8.3epss 0.00

    melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signed `APKINDEX`, but never verified the data section hash (the…

  • CVE-2026-54166HigSep 11, 2026
    risk 0.39cvss 7.1epss 0.00

    Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Content Import feature. The `imageUrl` validation logic can…