VYPR

CVEs

381,305 total · page 223 of 7,627

  • CVE-2026-82056MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A race condition in MongoDB server's text index query parsing can cause a heap use-after-free read when handling upsert retry paths. Under certain concurrent index lifecycle operations, a raw pointer to internal text index metadata may be dereferenced after the underlying…

  • CVE-2026-82055MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A security issue exists in MongoDB's 2dsphere index key generation that can cause a server crash due to a null pointer dereference. When a specially crafted GeoJSON document is inserted into a collection with a 2dsphere index, an inconsistency in geometry parsing can leave an…

  • CVE-2026-82054MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a find command includes a specially crafted $jsonSchema filter field, the parser processes the input without enforcing adequate limits on iteration count or…

  • CVE-2026-82053HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.00

    A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity…

  • CVE-2026-82052MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.01

    The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the  regex match can start in the middle of a multi-code-unit character, triggering an assertion…

  • CVE-2026-81531MedSep 8, 2026
    risk 0.45cvss —epss 0.01

    An information disclosure vulnerability has been identified in Omada Controller.  An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users.  Successful…

  • CVE-2026-79570CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-79569CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-78997CriSep 8, 2026
    risk 0.60cvss 9.3epss 0.00

    UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain…

  • CVE-2026-78230MedSep 8, 2026
    risk 0.32cvss —epss 0.00

    AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on returned…

  • CVE-2026-78216MedSep 8, 2026
    risk 0.32cvss —epss 0.00

    AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, max, first, sum, avg) that builds an ad-hoc Ash.Query.Aggregate over a named field and returns its raw value. Ash field policies redact forbidden fields on…

  • CVE-2026-75156CriSep 8, 2026
    risk 0.52cvss 9.1epss 0.00

    Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are…

  • CVE-2026-52307MedSep 8, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.6 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the title field.

  • CVE-2026-47625HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could abuse missing authorization. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service.

  • CVE-2026-26084CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.00

    A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

  • CVE-2026-22575MedSep 8, 2026
    risk 0.32cvss 4.9epss 0.00

    An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 through 7.4.10, FortiManager Cloud 7.2 all versions may allow…

  • CVE-2026-20293HigSep 8, 2026
    risk 0.46cvss 7.1epss 0.00

    A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated…

  • CVE-2026-16497HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause excessive iteration. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-86853MedSep 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launches. This could make Firefox for iOS temporarily unusable until the page is closed. This vulnerability was fixed in Firefox for iOS 155.1.

  • CVE-2026-86840CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.00

    The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…

  • CVE-2026-86738HigSep 8, 2026
    risk 0.50cvss 8.7epss 0.00

    Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability in the Custom CSS field due to incomplete sanitization that reverses HTML encoding on greater-than and double-quote characters. Superusers can plant malicious CSS payloads using @import and url() references to…

  • CVE-2026-86737MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. Authenticated attackers can iterate asset IDs to retrieve barcodes and enumerate asset tags across tenants, including soft-deleted and cross-company assets.

  • CVE-2026-86736MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.00

    snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authenticated users to corrupt the assets.requests_counter through duplicate submissions and cancellations without active requests. Attackers can repeatedly call cancel…

  • CVE-2026-86735MedSep 8, 2026
    risk 0.26cvss 5.0epss 0.00

    snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule that fails to detect IPv6 transition addresses encoding private IPv4 targets. Attackers with super-admin privileges can configure webhook URLs using NAT64, 6to4,…

  • CVE-2026-86734MedSep 8, 2026
    risk 0.35cvss 6.5epss 0.01

    Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, allowing authenticated users to submit unbounded input that reaches synchronous CommonMark rendering. Attackers can submit large note values to exhaust PHP…

  • CVE-2026-86733HigSep 8, 2026
    risk 0.40cvss 7.2epss 0.01

    Snipe-IT before 8.7.0 streams the SQL entry from an uploaded backup archive directly into the MySQL/MariaDB command-line client (`mysql`) without the --binary-mode flag, so the client interprets lines beginning with backslash commands such as `\!` as local shell commands. An…

  • CVE-2026-86732HigSep 8, 2026
    risk 0.50cvss 8.8epss 0.01

    Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via…

  • CVE-2026-86731MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when the targeted user is an…

  • CVE-2026-86730HigSep 8, 2026
    risk 0.50cvss 8.8epss 0.01

    Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse…

  • CVE-2026-86729HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.00

    WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize…

  • CVE-2026-86728HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive…

  • CVE-2026-86727HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    AVideo through 29.0 contains an information disclosure vulnerability in plugin/Live/stats.json.php that allows unauthenticated attackers to retrieve stream keys and m3u8 URLs by accessing the endpoint without authentication. Attackers can enumerate private, unlisted, and…

  • CVE-2026-86726MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticated streamers to enumerate source stream keys and identities of all other streamers' active restreams. The endpoint fails to filter results by user ownership,…

  • CVE-2026-86725HigSep 8, 2026
    risk 0.46cvss 7.1epss 0.00

    AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in the SocialMediaPublisher plugin's add.json.php endpoint that allows authenticated users to modify other users' OAuth token records. Attackers can supply arbitrary row IDs to…

  • CVE-2026-86724MedSep 8, 2026
    risk 0.35cvss 6.5epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in plugin/YPTWallet/view/saveBalance.php that allows attackers to set arbitrary wallet balances by relying only on session cookies without token validation.…

  • CVE-2026-86723HigSep 8, 2026
    risk 0.53cvss 8.1epss 0.00

    AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit…

  • CVE-2026-86722HigSep 8, 2026
    risk 0.46cvss 8.1epss 0.00

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability where sqlDAL caches empty result sets that writeSql never invalidates. Attackers with a valid password can bypass email two-factor authentication on new devices because…

  • CVE-2026-86721HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without…

  • CVE-2026-86720HigSep 8, 2026
    risk 0.46cvss 8.1epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ownership of live_restreams_id in resendRestreamer.json.php, allowing authenticated users with canStream to access other users' restream destinations. Attackers can broadcast their live stream…

  • CVE-2026-86719MedSep 8, 2026
    risk 0.28cvss 5.4epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulnerability in the CustomizeUser plugin endpoint plugin/CustomizeUser/swapUser.json.php. The endpoint takes users_id from $_REQUEST and invokes User::swapUser()…

  • CVE-2026-86718HigSep 8, 2026
    risk 0.39cvss 7.1epss 0.00

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token…

  • CVE-2026-86666HigSep 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in aircheng-org iWebShop-5 up to 5.15. Impacted is the function upload_json/uploadFile of the file controllers/pic.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit has been released to the…

  • CVE-2026-86600HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.01

    In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the…

  • CVE-2026-79574CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

  • CVE-2026-79573MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList component via the busid, id, and taskid parameters. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-79572HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows attackers to read sensitive files, scan internal networks, or launch server attacks via supplying a crafted XML payload.

  • CVE-2026-56101MedSep 8, 2026
    risk 0.27cvss 5.3epss 0.01

    OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() function within sys/net80211/ieee80211_crypto_tkip.c that allows unauthenticated attackers within RF range to trigger denial of service by sending two malformed…

  • CVE-2026-16769HigSep 8, 2026
    risk 0.46cvss —epss 0.00

    An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.

  • CVE-2026-16037HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.

  • CVE-2026-16025HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper validation of specified quantity in input vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Input Data Manipulation. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from…