VYPR

CVEs

381,769 total · page 258 of 7,636

  • CVE-2026-85436HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.02

    MOOS essential-moos through 10.0.1 contains a buffer overflow vulnerability in CMOOSUDPLink::ReadPktFromArray() that allows remote attackers to corrupt heap memory by sending UDP datagrams with negative declared lengths. Attackers can send crafted UDP packets to the configured…

  • CVE-2026-85435CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.00

    MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including…

  • CVE-2026-85434CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.00

    MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.

  • CVE-2026-85433CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners…

  • CVE-2026-85432HigSep 3, 2026
    risk 0.46cvss 8.2epss 0.01

    MOOS core-moos through 10.4.0 fails to validate client identity in MOOSDB message processing, allowing authenticated attackers to attribute writes to other clients by supplying arbitrary source identifiers in serialized messages. Attackers can forge message origins and cancel…

  • CVE-2026-85431HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.03

    MOOS essential-moos through version 10.0.1 contains an unauthenticated UDP packet injection vulnerability in pMOOSBridge when configured with UDPListen. Attackers can send crafted UDP packets to the configured port to inject arbitrary variables into the local MOOS community with…

  • CVE-2026-85430CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.01

    MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject…

  • CVE-2026-85429HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.00

    MOOS-IvP uFldNodeComms through 24.8.1 trusts the source node identity from the message body rather than validating it from the connection source. Attackers can craft NODE_MESSAGE packets with spoofed source identities to impersonate other nodes and post arbitrary variable…

  • CVE-2026-85428CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS…

  • CVE-2026-85427HigSep 3, 2026
    risk 0.46cvss 8.1epss 0.01

    MOOS essential-moos pAntler through 10.0.1 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary programs by publishing a crafted MISSION_FILE message to the MOOSDB. Attackers can publish a mission file containing malicious Run…

  • CVE-2026-85426CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets…

  • CVE-2026-85425CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands…

  • CVE-2026-85424CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names…

  • CVE-2026-85378HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function AuthController::_initialize of the file App/Admin/Controller/ChapterController.class.php of the component…

  • CVE-2026-85241MedSep 3, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to…

  • CVE-2026-85225HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly…

  • CVE-2026-83711CriSep 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-80098CriSep 3, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70352CriSep 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70178HigSep 3, 2026
    risk 0.55cvss 8.5epss 0.01

    Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-69857HigSep 3, 2026
    risk 0.55cvss 8.5epss 0.01

    Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network.

  • CVE-2026-65818HigSep 3, 2026
    risk 0.55cvss 8.5epss 0.01

    Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62916CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.01

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62906HigSep 3, 2026
    risk 0.48cvss 7.4epss 0.01

    Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-18330MedSep 3, 2026
    risk 0.40cvss —epss 0.00

    A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who captures an HTTP login session may use the known shared RSA private key to decrypt the administrator password; the weakened AES session key further reduces the…

  • CVE-2026-18167HigSep 3, 2026
    risk 0.50cvss —epss 0.00

    A stack-based buffer overflow vulnerability exists in the EasyMesh module of TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit crafted input that causes the easymesh daemon to crash and may potentially achieve remote code execution on the device. …

  • CVE-2026-85224CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched…

  • CVE-2026-85223CriSep 3, 2026
    risk 0.64cvss 9.9epss 0.03

    A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The…

  • CVE-2026-64200HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a…

  • CVE-2026-64199HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB…

  • CVE-2026-64198HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a…

  • CVE-2026-64197HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This…

  • CVE-2026-64196HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue…

  • CVE-2026-64195HigSep 3, 2026
    risk 0.51cvss 7.8epss 0.00

    There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

  • CVE-2026-9745MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect…

  • CVE-2026-9744MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2026-9736MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.

  • CVE-2026-9036MedSep 3, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2026-8862HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing…

  • CVE-2026-85458LowSep 3, 2026
    risk 0.14cvss —epss 0.00

    Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height.

  • CVE-2026-85222CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command…

  • CVE-2026-85208HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller. Performing a manipulation of the argument…

  • CVE-2026-85063MedSep 3, 2026
    risk 0.38cvss —epss 0.01

    node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options enabled treats a duplicate __proto__ header as an existing property in…

  • CVE-2026-85062MedSep 3, 2026
    risk 0.38cvss —epss 0.01

    Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.ts, src/colorModels/lchString.ts, and…

  • CVE-2026-85061CriSep 3, 2026
    risk 0.58cvss 10.0epss 0.01

    MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an…

  • CVE-2026-84185MedSep 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifies a General JSON Serialization JWS using a set of keys. Due to a coding error, the library fails to…

  • CVE-2026-82521MedSep 3, 2026
    risk 0.27cvss 5.3epss 0.00

    parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path traversal sequences, the filename sanitization function produces an empty string, and a fallback to the raw…

  • CVE-2026-82520HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.01

    parsedmarc before 11.0.1 decompresses gzip and ZIP attachments in a single unbounded read with no limit on decompressed output size. Because parsedmarc automatically processes incoming DMARC report emails without user interaction, an unauthenticated remote attacker can send a…

  • CVE-2026-77465HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.01

    toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions recurse through nested arrays and inline…

  • CVE-2026-71429MedSep 3, 2026
    risk 0.33cvss 6.2epss 0.00

    stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, and replace in src/core/filters/filter-base.js recompute the full path string from the nesting stack for…