VYPR

CVEs

37,811 total · page 24 of 757

  • CVE-2026-14563CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including…

  • CVE-2026-14560CriSep 11, 2026
    risk 0.65cvss 10.0epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the…

  • CVE-2026-14559CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.

  • CVE-2026-8778CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This…

  • CVE-2026-82107CriSep 10, 2026
    risk 0.62cvss 9.6epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.

  • CVE-2026-82100CriSep 10, 2026
    risk 0.62cvss 9.6epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.

  • CVE-2026-81204CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

  • CVE-2026-80424CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.

  • CVE-2026-79724CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-78573CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

  • CVE-2026-71640CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows unsafe vehicle motion via improper handling of expired trajectory data in the replanning pipeline

  • CVE-2026-45764CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.01

    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, a protocol change while processing HTTP/2 traffic could lead to type confusion in Suricata. Crafted traffic may cause…

  • CVE-2026-19646CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 could allow a remote attacker to redirect users to an arbitrary domain due to improper validation of the HTTP Host header.

  • CVE-2026-89094CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.01

    Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

  • CVE-2026-85025CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow security restrictions and session…

  • CVE-2026-75940CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.

  • CVE-2026-89086CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.

  • CVE-2026-88062CriSep 10, 2026
    risk 0.55cvss —epss 0.01

    OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers. In 3.8.49 and earlier, the OmniRoute POST /api/acp/agents custom ACP agent endpoint accepted attacker-controlled binary and versionCommand values and used only a self-consistency…

  • CVE-2026-89049CriSep 10, 2026
    risk 0.57cvss 9.9epss 0.01

    A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user…

  • CVE-2026-88056CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.01

    Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.30, 21.2.22, and 22.1.4, Angular Server-Side Rendering in @angular/platform-server processes user-controlled resource or request URLs…

  • CVE-2026-89042CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    passport-saml-encrypted through 0.1.13 makes SAML signature verification conditional on an optional cert option, allowing attackers to bypass authentication by submitting unsigned SAML responses. Attackers can post forged SAML responses with arbitrary NameID and attributes to…

  • CVE-2026-68006CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker to execute arbitrary code via the ext/puma_http11/http11_parser.rl file

  • CVE-2026-88044CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.70.0 until 1.75.1, the serve/start RC interface accepts per-server proxyOpt.AuthProxy settings, and the FTP and S3 constructors in cmd/serve/ftp/ftp.go and…

  • CVE-2026-85228CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.01

    An integer overflow in the tensor buffer validation component in Amazon Deep Java Library (DJL) from 0.13.0 through 0.36.0 on all platforms might allow a remote unauthenticated actor to obtain information from adjacent process memory or cause a denial of service via a crafted…

  • CVE-2026-68488CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.00

    A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

  • CVE-2026-68487CriSep 10, 2026
    risk 0.64cvss 9.9epss 0.01

    Path traversal in Plesk's Backup Manager causes arbitrary file write as root by an authenticated customer.

  • CVE-2026-65639CriSep 10, 2026
    risk 0.62cvss —epss 0.01

    OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execute arbitrary commands as root, due to insufficient validation of feed-supplied rule data. The vulnerability affects…

  • CVE-2026-65638CriSep 10, 2026
    risk 0.60cvss —epss 0.02

    Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF service account via shell command injection. The vulnerability affects versions of the software originally distributed by…

  • CVE-2026-52098CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/ endpoint

  • CVE-2026-88899CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

  • CVE-2026-88018CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty…

  • CVE-2026-81468CriSep 10, 2026
    risk 0.59cvss 9.1epss 0.02

    Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2026-81467CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.03

    Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command…

  • CVE-2026-81048CriSep 10, 2026
    risk 0.63cvss 9.6epss 0.02

    Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote…

  • CVE-2026-81046CriSep 10, 2026
    risk 0.61cvss 9.4epss 0.01

    Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Arbitrary Code Execution within the application context.

  • CVE-2026-88008CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns…

  • CVE-2026-88007CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.01

    Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each…

  • CVE-2026-81800CriSep 10, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.

  • CVE-2026-88877CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such…

  • CVE-2026-88869CriSep 10, 2026
    risk 0.53cvss 9.3epss 0.01

    AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through…

  • CVE-2026-88864CriSep 10, 2026
    risk 0.52cvss 9.1epss 0.00

    Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase PostgREST. A holder of an ordinary Capgo full API key can insert a row with status='active' and enforce_sso=true, bypassing the intended backend SSO provisioning…

  • CVE-2026-38626CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php.

  • CVE-2026-9163CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics GisLab Laboratory Management System allows SQL Injection. This issue affects GisLab Laboratory Management System: from 1.4.03 before 1.5.

  • CVE-2026-78082CriSep 10, 2026
    risk 0.60cvss —epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and…

  • CVE-2026-8323CriSep 10, 2026
    risk 0.60cvss 9.3epss 0.00

    URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

  • CVE-2026-88285CriSep 10, 2026
    risk 0.61cvss 9.4epss 0.01

    GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issue PTZ or raw serial commands.

  • CVE-2026-88278CriSep 10, 2026
    risk 0.64cvss 9.8epss 0.00

    GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.

  • CVE-2026-59679CriSep 10, 2026
    risk 0.59cvss 9.0epss 0.00

    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The…

  • CVE-2026-44950CriSep 10, 2026
    risk 0.59cvss 9.0epss 0.00

    fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination…

  • CVE-2026-80352CriSep 10, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerability in custom resource configuration allows an authorized CR author to inject arbitrary Kubernetes objects, potentially enabling unauthorized resource…