VYPR

CVEs

381,306 total · page 226 of 7,627

  • CVE-2026-74859MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries.

  • CVE-2026-71377CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from…

  • CVE-2026-71376CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20…

  • CVE-2026-67367HigSep 8, 2026
    risk 0.56cvss 8.6epss 0.01

    A vulnerability has been identified in SIMOVE Fleetmanager V3.1 (All versions < V3.1.13), SIMOVE Fleetmanager V3.2 (All versions < V3.2.4), SIMOVE Fleetmanager V3.3 (All versions < V3.3.2), SIMOVE Fleetmanager V4.0 (All versions < V4.0.1), SIPLANT V1.7 (All versions), SIPLANT…

  • CVE-2026-62654MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in which the device downloads and executes program code from a network server without verifying its…

  • CVE-2026-62653MedSep 8, 2026
    risk 0.44cvss 6.8epss 0.00

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is placed into a special firmware-update mode is not properly validated, resulting in a memory corruption…

  • CVE-2026-62652MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from which debugging symbols have not been removed. This could allow an unauthenticated attacker with access to the publicly available firmware update files to more…

  • CVE-2026-62650HigSep 8, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request…

  • CVE-2026-62649HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire…

  • CVE-2026-62648HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory.…

  • CVE-2026-62647HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.01

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG),…

  • CVE-2026-62646HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.01

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A session identifier is generated using an algorithm with insufficient randomness, resulting in a token with low entropy that can be predicted or brute-forced within a feasible number of attempts. This…

  • CVE-2026-62645CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized…

  • CVE-2026-58113MedSep 8, 2026
    risk 0.40cvss 6.1epss 0.00

    A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2506.0010), Teamcenter V2512 (All versions < V2512.2607), Teamcenter V2606 (All versions < V2606.2607). Affected applications do not properly encode…

  • CVE-2026-50093CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.00

    A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A…

  • CVE-2026-34223HigSep 8, 2026
    risk 0.53cvss 8.2epss 0.00

    A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All…

  • CVE-2026-84820HigSep 8, 2026
    risk 0.39cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.

  • CVE-2026-84818HigSep 8, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.

  • CVE-2026-84817HigSep 8, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.

  • CVE-2026-81806HigSep 8, 2026
    risk 0.47cvss 7.2epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.

  • CVE-2026-81802MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.

  • CVE-2026-81798HigSep 8, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appointments: from n/a through 4.0.2.1.

  • CVE-2026-81792MedSep 8, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woocommerce-catalog-enquiry allows Privilege Escalation.This issue affects Product Catalog Enquiry for WooCommerce by MultiVendorX: from n/a through 6.1.5.

  • CVE-2026-81790HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Csomagpontok és szállítási címkék WooCommerce-hez: from n/a before 4.2.8.

  • CVE-2026-81781HigSep 8, 2026
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Unbounce Landing Pages: from n/a through 1.1.4.

  • CVE-2026-76561HigSep 8, 2026
    risk 0.47cvss 7.2epss 0.01

    A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's…

  • CVE-2026-71375HigSep 8, 2026
    risk 0.48cvss 7.4epss 0.00

    Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from…

  • CVE-2026-71374CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through…

  • CVE-2026-48888HigSep 8, 2026
    risk 0.49cvss 7.5epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.

  • CVE-2026-86519MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has…

  • CVE-2026-86518MedSep 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and…

  • CVE-2026-86517MedSep 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-86516MedSep 8, 2026
    risk 0.24cvss 4.7epss 0.00

    A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in…

  • CVE-2026-86515MedSep 8, 2026
    risk 0.21cvss 4.3epss 0.01

    A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manipulation of the argument range_start/range_end leads to resource consumption. The attack may be performed…

  • CVE-2026-86514MedSep 8, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-86513MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation…

  • CVE-2026-86512MedSep 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/github/fge/jsonpatch/CopyOperation.java of the component Copy Move Operations. The manipulation leads to…

  • CVE-2026-86511MedSep 8, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack…

  • CVE-2026-75811MedSep 8, 2026
    risk 0.38cvss —epss 0.00

    Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause hardware damage by bypassing driver authentication and accessing critical model-specific registers.Refer to…

  • CVE-2026-75810MedSep 8, 2026
    risk 0.37cvss —epss 0.00

    Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigger system management interrupts (SMIs). Repeatedly triggering SMI may lead to a denial-of-service (DoS)…

  • CVE-2026-75809MedSep 8, 2026
    risk 0.38cvss —epss 0.00

    Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver authentication and using IOCTLs to read from and write to PCIe configuration space.Refer to the ' Security…

  • CVE-2026-75808MedSep 8, 2026
    risk 0.37cvss —epss 0.00

    Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by bypassing driver authentication and allocating an unrestricted amount of memory.Refer to the ' Security…

  • CVE-2026-19397HigSep 8, 2026
    risk 0.50cvss —epss 0.00

    Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the '  Security Update for ASUS Control Center…

  • CVE-2026-18023MedSep 8, 2026
    risk 0.37cvss —epss 0.00

    Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose sensitive information from uninitialized memory via a crafted IOCTL request that bypasses the driver's security verification mechanism. Refer to the ' Security…

  • CVE-2026-16006MedSep 8, 2026
    risk 0.37cvss —epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCTL request by bypassing the driver's verification, potentially providing further insight into the kernel…

  • CVE-2026-16005MedSep 8, 2026
    risk 0.38cvss —epss 0.00

    Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verification, which can corrupt data structures and cause a system crash (BSOD).Refer to the ' Security Update for…

  • CVE-2026-16004MedSep 8, 2026
    risk 0.38cvss —epss 0.00

    Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL requests by bypassing the driver's verification. Refer to the ' Security Update for Armoury Crate App' section on…

  • CVE-2026-16003LowSep 8, 2026
    risk 0.13cvss —epss 0.00

    Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IOCTL request by bypassing the driver's verification.Refer to the ' Security Update for Armoury Crate…

  • CVE-2026-12962MedSep 8, 2026
    risk 0.34cvss —epss 0.00

    A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application's local service…

  • CVE-2026-86510CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and…