VYPR

CVEs

378,628 total · page 216 of 7,573

  • CVE-2026-53682MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated client can query the Security Domain hosts inventory via GET /ca/rest/securityDomain/hosts and receive a structured response enumerating internal PKI/CA hosts and roles (security domain topology and participating subsystems), without requiring a principal,…

  • CVE-2026-51747CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the keepAlive function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to emit indirect mesh heartbeat information toward the master via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51745MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the updatePriStaList function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to refresh the primary station list via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51744CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the recv_mesh_info_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to force mesh configuration synchronization from an attacker-controlled host via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51743CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the guest_wifi_sync function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to disable guest virtual AP interfaces via sending a crafted MQTT message to the cs_broker component.

  • CVE-2026-51742MedSep 1, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the discoverWan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger WAN discovery logic via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51741CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the clearDiagnosisLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase diagnosis logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-19472HigSep 1, 2026
    risk 0.57cvss —epss 0.00

    A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability

  • CVE-2026-19471MedSep 1, 2026
    risk 0.45cvss —epss 0.00

    Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected…

  • CVE-2026-18765CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.

  • CVE-2026-84200CriSep 1, 2026
    risk 0.52cvss 9.0epss 0.00

    Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the policy by crafting a resource name that…

  • CVE-2026-84199HigSep 1, 2026
    risk 0.43cvss 7.7epss 0.00

    Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions can direct Kyverno to make HTTP requests…

  • CVE-2026-84196HigSep 1, 2026
    risk 0.43cvss 7.7epss 0.00

    Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can target internal services, cloud…

  • CVE-2026-84195HigSep 1, 2026
    risk 0.43cvss 7.7epss 0.00

    Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCall requests to external or…

  • CVE-2026-84194HigSep 1, 2026
    risk 0.49cvss —epss 0.01

    LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enabled (enable_libvirt=true), the device hostname ($this->getDevice()->hostname) is concatenated into shell…

  • CVE-2026-84193MedSep 1, 2026
    risk 0.31cvss —epss 0.00

    LibreNMS through 26.2.0 contains a stored cross-site scripting vulnerability in legacy PHP template pages that render unescaped SNMP-sourced data fields including BGP peer descriptions, VRF names, process information, and SLA tags. Attackers with device management access or…

  • CVE-2026-84192HigSep 1, 2026
    risk 0.39cvss 7.1epss 0.00

    LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP templates that output SNMP-sourced and syslog-sourced data without escaping. An attacker who controls a monitored network device can inject arbitrary JavaScript through SNMP interface…

  • CVE-2026-84191MedSep 1, 2026
    risk 0.33cvss 6.1epss 0.00

    LibreNMS before 26.5.0 contains stored cross-site scripting vulnerabilities in VRF display pages where mplsVpnVrfDescription, vrf_name, and mplsVpnVrfRouteDistinguisher fields from SNMP polling are rendered without sanitization. Attackers controlling a monitored network device…

  • CVE-2026-84190HigSep 1, 2026
    risk 0.40cvss 7.2epss 0.01

    LibreNMS versions before 26.5.0 contain a remote code execution vulnerability in the AboutController where the snmpget configuration parameter is passed to shell_exec() without proper validation. An authenticated administrator can modify the snmpget configuration to point to a…

  • CVE-2026-84189HigSep 1, 2026
    risk 0.46cvss 8.1epss 0.00

    LibreNMS through 26.4.0 renders JSON fields (name, ip, model, author, commit message) returned by the admin-configurable Oxidized integration URL (oxidized.url) into the device showconfig page without applying htmlspecialchars(). An administrator who points the Oxidized URL at…

  • CVE-2026-84188MedSep 1, 2026
    risk 0.24cvss 4.8epss 0.00

    LibreNMS versions <= 26.4.0 contain a stored cross-site scripting vulnerability in the graph_descr. configuration settings, which are echoed verbatim without HTML escaping in includes/html/pages/graphs.inc.php. An administrator can store a malicious HTML payload that…

  • CVE-2026-84187HigSep 1, 2026
    risk 0.53cvss 8.2epss 0.00

    AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP…

  • CVE-2026-83595HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.00

    AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to…

  • CVE-2026-77194MedSep 1, 2026
    risk 0.27cvss 5.3epss 0.00

    The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is due to improper identity verification during the public registration flow in WordPress Multisite…

  • CVE-2026-76111HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke administrator-only operations, leading to privilege escalation.

  • CVE-2026-18550CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` function, which allows empty…

  • CVE-2026-11873MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed requests. The same unauthenticated error path emits large multi-line stack traces into the CA debug log, creating…

  • CVE-2026-10420MedSep 1, 2026
    risk 0.29cvss 5.5epss 0.00

    Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.

  • CVE-2025-15613MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify an external URL in a policy's apiCall/service configuration; although Service Call is…

  • CVE-2023-54356LowSep 1, 2026
    risk 0.17cvss 3.7epss 0.00

    Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2016-2183), which, over very long-lived TLS…

  • CVE-2026-84165HigSep 1, 2026
    risk 0.57cvss —epss 0.01

    A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticated user with basic permissions to execute commands on virtual machines belonging to other users via the…

  • CVE-2026-84059HigSep 1, 2026
    risk 0.48cvss 7.4epss 0.02

    A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Executing a manipulation of the argument ParameterArray can lead to command injection. The attack can be…

  • CVE-2026-82927MedSep 1, 2026
    risk 0.29cvss 5.5epss 0.00

    Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.

  • CVE-2026-82926MedSep 1, 2026
    risk 0.29cvss 5.5epss 0.00

    NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.

  • CVE-2026-4813CriSep 1, 2026
    risk 0.61cvss —epss 0.00

    A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not enable secure processing mode (FEATURE_SECURE_PROCESSING), allowing Java…

  • CVE-2026-59681HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads…

  • CVE-2026-59680HigSep 1, 2026
    risk 0.52cvss 8.0epss 0.02

    An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb read the shadowLastChange and shadowExpire fields with GetString(), which performs no numeric validation,…

  • CVE-2026-25706HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary…

  • CVE-2026-19914HigSep 1, 2026
    risk 0.40cvss 7.2epss 0.00

    The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

  • CVE-2026-16788MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-16786MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all versions up to, and including, 2.1.19 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-15101MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-78363MedSep 1, 2026
    risk 0.31cvss 4.8epss 0.00

    The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.…

  • CVE-2026-74916MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested with them, allowing unauthenticated attackers to have a page rendered under their own request context stored…

  • CVE-2026-13611MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key.

  • CVE-2026-78319CriSep 1, 2026
    risk 0.60cvss —epss 0.00

    A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this race condition to bypass intended security controls. This may result in the execution of unauthorized code.

  • CVE-2026-83772CriSep 1, 2026
    risk 0.64cvss 9.9epss 0.02

    A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-report.sh of the component JSON Parsing. The manipulation of the argument sender/recipients results in command…

  • CVE-2026-77189MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to generic SQL Injection via 'order' Shortcode Attribute in all versions up to, and including, 1.8.12.1 due to insufficient…

  • CVE-2026-75980MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribute in Post Content in all versions up to, and including, 4.8.1 due to insufficient input sanitization and…

  • CVE-2026-75964MedSep 1, 2026
    risk 0.33cvss 6.1epss 0.00

    The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions up to, and including, 4.0.0 due to insufficient input sanitization and…