VYPR

CVEs

378,628 total · page 215 of 7,573

  • CVE-2026-51748MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the sendStaticInfoToMaster function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to update stored slave inventory records via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-19513HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.01

    The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public form state URL hashes can be…

  • CVE-2026-18808CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.

  • CVE-2026-18210CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This issue affects Products's Store: before…

  • CVE-2026-16675HigSep 1, 2026
    risk 0.55cvss —epss 0.00

    A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated…

  • CVE-2026-13348MedSep 1, 2026
    risk 0.45cvss —epss 0.00

    CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by performing an arbitrary number of authentication attempts when redirect handling is disabled.

  • CVE-2026-13337MedSep 1, 2026
    risk 0.33cvss —epss 0.00

    CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into the NetBotz via the web-service interface or webui.

  • CVE-2026-13336HigSep 1, 2026
    risk 0.47cvss —epss 0.01

    CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system commands when a system back up is restored that has been maliciously modified.

  • CVE-2026-12663HigSep 1, 2026
    risk 0.45cvss —epss 0.00

    A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of…

  • CVE-2026-12661MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become…

  • CVE-2025-12768HigSep 1, 2026
    risk 0.56cvss —epss 0.00

    A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.

  • CVE-2024-14047HigSep 1, 2026
    risk 0.47cvss 7.2epss 0.00

    A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with existing access to the system could pre-position malicious filesystem links, causing a subsequent elevated…

  • CVE-2024-10085HigSep 1, 2026
    risk 0.53cvss —epss 0.00

    CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large number of OPC UA requests are sent to the platform.

  • CVE-2026-84235HigSep 1, 2026
    risk 0.57cvss —epss 0.00

    A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

  • CVE-2026-84149CriSep 1, 2026
    risk 0.60cvss —epss 0.00

    This vulnerability exists in the ERP system due to exposure of repository information through a publicly accessible .git directory. An unauthenticated remote attacker could exploit this vulnerability by accessing the exposed .git directory and retrieving repository metadata and…

  • CVE-2026-84148CriSep 1, 2026
    risk 0.60cvss —epss 0.00

    This vulnerability exists in the ERP system due to improper authentication and authorization controls in the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by manipulating parameter which could lead to exposure of sensitive information…

  • CVE-2026-84147CriSep 1, 2026
    risk 0.65cvss —epss 0.01

    This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the…

  • CVE-2026-84145HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-84144HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Internally found bugs present in Thunderbird 154 and Thunderbird ESR 153.1. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in…

  • CVE-2026-84143CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-84142CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and…

  • CVE-2026-84141CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84140CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84139MedSep 1, 2026
    risk 0.40cvss 6.1epss 0.00

    Clickjacking issue in the DOM: Events component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84138MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Denial-of-service in the PDF Viewer component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

  • CVE-2026-84137MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Spoofing issue in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84136MedSep 1, 2026
    risk 0.40cvss 6.1epss 0.00

    Other issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84135CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

  • CVE-2026-84134CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Other issue in the Profile Backup component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84133CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Site isolation issue in the DOM: Push Subscriptions component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84132HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Networking: HTTP component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84131HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84130HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84129CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84128HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in the WebDriver BiDi component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

  • CVE-2026-84127MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Information disclosure in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 155.

  • CVE-2026-84126MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect boundary conditions in the Layout: Grid component. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

  • CVE-2026-84125MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84124MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84123HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation due to use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84122MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84121CriSep 1, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to use-after-free in the DOM: Security component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84120MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the Audio/Video component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84119CriSep 1, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to use-after-free in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84118MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    Use-after-free in the JavaScript: GC component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

  • CVE-2026-84117HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege escalation in Firefox for Android. This vulnerability was fixed in Firefox 155.

  • CVE-2026-84061MedSep 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in zhongyu09 OpenChatBI up to 0.3.0. Affected by this vulnerability is the function _validate_sql_safety of the file openchatbi/text2sql/generate_sql.py. Performing a manipulation results in sql injection. The attack can be initiated remotely.…

  • CVE-2026-7877MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    The WP Recipe Maker Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprm-call-to-action' shortcode in all versions up to, and including, 10.5.0 due to insufficient input sanitization and output escaping on user supplied attributes.…

  • CVE-2026-79683HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to write attacker-controlled content to arbitrary filesystem paths.

  • CVE-2026-58575HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability. An authenticated attacker could potentially exploit this vulnerability to escalate privileges to Administrator.