VYPR

CVEs

381,337 total · page 232 of 7,627

  • CVE-2026-14296HigSep 7, 2026
    risk 0.49cvss 7.5epss 0.00

    When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verification. The MCUboot in the bare (upstream) configuration assumes that if there is at least a single slot for…

  • CVE-2026-86279MedSep 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file auth_process.php of the component Login. This manipulation causes session fixiation. It is possible to initiate…

  • CVE-2026-86278MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_subjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack…

  • CVE-2026-86277HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. Impacted is an unknown function of the file delete_exam.php. The manipulation of the argument ID leads to authorization bypass. The attack is possible to be carried…

  • CVE-2026-79698CriSep 7, 2026
    risk 0.64cvss 9.9epss 0.03

    A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This…

  • CVE-2026-79697CriSep 7, 2026
    risk 0.65cvss 9.9epss 0.05

    A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects…

  • CVE-2026-86276HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has…

  • CVE-2026-86275MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This vulnerability affects the function register of the file auth.php. Performing a manipulation of the argument role results in improper privilege management. Remote…

  • CVE-2026-86274MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in projeto-siga siga up to 11.0.2.10/11.0.2.13/11.1.1. This affects the function ExAutenticacaoController.autenticar of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExAutenticacaoController.java of the component Authentication…

  • CVE-2026-86273HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the…

  • CVE-2026-86272HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was determined in Beijing Meite Software Technology U+Smart Enjoyment WebSite 18.6001.1096.1000. This impacts an unknown function of the file /Report/Upload/UploadFormImg.ashx. Executing a manipulation of the argument File can lead to unrestricted upload. It is…

  • CVE-2026-86271MedSep 7, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in FluentCMS up to 0.0.5. This affects the function GetAccessible of the file src/Backend/FluentCMS.Services/Permissions/PermissionManager.cs. Performing a manipulation results in missing authorization. It is possible to initiate the attack remotely.…

  • CVE-2026-86270MedSep 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/settings_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has…

  • CVE-2026-86315MedSep 7, 2026
    risk 0.33cvss 6.2epss 0.00

    An out-of-bounds write caused by numeric truncation Samsung Open Source Escargot on Linux x86-64 allows an attacker who can supply JavaScript for execution to corrupt native memory and crash the host process via a crafted class definition whose instance initialization entry…

  • CVE-2026-86269MedSep 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/emp_edit1.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-86268HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in itsourcecode School Management System 1.0. Impacted is an unknown function of the file User_Login.php. The manipulation of the argument email results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

  • CVE-2026-86267MedSep 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in itsourcecode Information System Society Membership System 1.0. This issue affects some unknown processing of the file /society/check_student.php. The manipulation of the argument student_id leads to sql injection. Remote exploitation…

  • CVE-2026-86265MedSep 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/us_transac.php. Such manipulation of the argument Username leads to sql injection. It is possible to launch the attack…

  • CVE-2026-86314MedSep 7, 2026
    risk 0.33cvss 6.2epss 0.00

    Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted WebAssembly module in which a 32-bit unsigned addition wraps…

  • CVE-2026-86313HigSep 7, 2026
    risk 0.44cvss 7.8epss 0.00

    Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers. This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

  • CVE-2026-86264MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endpoint. This manipulation of the argument…

  • CVE-2026-86263HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The…

  • CVE-2026-86262HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order…

  • CVE-2026-86261HigSep 7, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Controller. Executing a manipulation of…

  • CVE-2026-86260MedSep 7, 2026
    risk 0.42cvss 6.5epss 0.01

    A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserController.java of the component Password Recovery.…

  • CVE-2026-86245MedSep 7, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument companyname results in sql injection. It is possible to initiate…

  • CVE-2026-86244MedSep 7, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipulation of the argument url leads to cross site scripting. The…

  • CVE-2026-86241MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidationKey causes use of hard-coded…

  • CVE-2026-86240MedSep 7, 2026
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[] results in server-side request forgery. The attack can be…

  • CVE-2026-86239MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of…

  • CVE-2026-20518MedSep 7, 2026
    risk 0.29cvss 4.4epss 0.00

    In geniezone, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: ALPS10867524 /…

  • CVE-2026-20517MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900510; Issue ID:…

  • CVE-2026-20516MedSep 7, 2026
    risk 0.36cvss 5.5epss 0.00

    In MiracastService, there is a possible escalation of privilege due to a confused deputy. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11060069 / DTV04881615; Issue ID: MSV-7882.

  • CVE-2026-20515MedSep 7, 2026
    risk 0.36cvss 5.5epss 0.00

    In gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11122991; Issue ID: MSV-8132.

  • CVE-2026-20514MedSep 7, 2026
    risk 0.29cvss 4.4epss 0.00

    In Audio HAL, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087632;…

  • CVE-2026-20513MedSep 7, 2026
    risk 0.29cvss 4.4epss 0.00

    In Audio HAL, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087533;…

  • CVE-2026-20512MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In Audio HAL, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11087540;…

  • CVE-2026-20511MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In SurfaceFlinger, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11123860; Issue ID:…

  • CVE-2026-20510MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In camera middleware, there is a possible escalation of privilege due to double free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11134622; Issue…

  • CVE-2026-20509MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In Power HAL, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue…

  • CVE-2026-20508MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In Power HAL, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11165543; Issue ID:…

  • CVE-2026-20507MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID:…

  • CVE-2026-20506MedSep 7, 2026
    risk 0.44cvss 6.7epss 0.00

    In Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11191981; Issue ID:…

  • CVE-2026-20504MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.00

    In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-20503MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.00

    In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2026-20502HigSep 7, 2026
    risk 0.55cvss 8.4epss 0.00

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196.

  • CVE-2026-20501HigSep 7, 2026
    risk 0.55cvss 8.4epss 0.00

    In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197.

  • CVE-2026-20500MedSep 7, 2026
    risk 0.36cvss 5.5epss 0.00

    In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.

  • CVE-2026-16876CriSep 7, 2026
    risk 0.60cvss —epss 0.00

    An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

  • CVE-2026-86238MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument Name/Subject can lead to cross site scripting. The attack…