VYPR

CVEs

381,824 total · page 262 of 7,637

  • CVE-2026-81292HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

  • CVE-2026-81282MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

  • CVE-2026-81281MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

  • CVE-2026-75602MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.01

    OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before…

  • CVE-2026-85239MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the…

  • CVE-2026-85238MedSep 3, 2026
    risk 0.37cvss 6.8epss 0.00

    MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session…

  • CVE-2026-85237HigSep 3, 2026
    risk 0.46cvss 8.1epss 0.00

    A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker…

  • CVE-2026-85236HigSep 3, 2026
    risk 0.50cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an…

  • CVE-2026-85138HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public…

  • CVE-2026-85137HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit…

  • CVE-2026-84967MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades…

  • CVE-2026-84966MedSep 3, 2026
    risk 0.33cvss 5.1epss 0.00

    An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory…

  • CVE-2026-84965MedSep 3, 2026
    risk 0.33cvss 5.1epss 0.00

    An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still writes through the stale pointer. On builds where sizes are 32 bits, an unauthenticated party able to supply a…

  • CVE-2026-84964MedSep 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same heap object to be released twice. An…

  • CVE-2026-84963MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or the corresponding field to be omitted, while the parsing operation still reports success and returns no…

  • CVE-2026-84962MedSep 3, 2026
    risk 0.27cvss 4.2epss 0.00

    An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's identity, escalating database-level access into cloud key control and defeating client-side encryption.

  • CVE-2026-83961HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default.…

  • CVE-2026-82525MedSep 3, 2026
    risk 0.36cvss 5.5epss 0.00

    Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedding malicious external entity references and attacker-controlled XSLT stylesheets within a Report.xml file…

  • CVE-2026-75036MedSep 3, 2026
    risk 0.27cvss —epss 0.00

    A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet controller could reach network resources outside the management cluster. A user who can supply bundle content to a repository referenced by a `GitRepo` resource…

  • CVE-2026-75035HigSep 3, 2026
    risk 0.43cvss 7.7epss 0.00

    A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user, the ext.cattle.io/v1 Token store dropped its internal owner filter instead of returning an empty result. Any authenticated user could therefore list and watch…

  • CVE-2026-75034HigSep 3, 2026
    risk 0.41cvss 7.4epss 0.00

    A flaw was found in Rancher Manager. The SAML assertion replay protection introduced by the fix for CVE-2026-44946 recorded consumed assertion IDs in a per-process cache, so each replica only detected replays that reached the same pod. In a high-availability deployment, an…

  • CVE-2026-71963HigSep 3, 2026
    risk 0.50cvss 8.8epss 0.01

    Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets core.fsmonitor to an attacker-controlled…

  • CVE-2026-57445HigSep 3, 2026
    risk 0.57cvss —epss 0.00

    Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In dfba919e218e20d52db9f7b2e8d292d45a46c91b and prior, normal beneficiary payout paths in StreamingEscrow…

  • CVE-2026-55658HigSep 3, 2026
    risk 0.50cvss 7.7epss 0.00

    Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool…

  • CVE-2026-53924HigSep 3, 2026
    risk 0.57cvss —epss 0.00

    Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. Prior to 0xc9d4e0dacd937364793278180551e59d93cd43f9, StreamingEscrow.claim() correctly rejects withdrawals…

  • CVE-2026-53720MedSep 3, 2026
    risk 0.26cvss —epss 0.00

    pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, then argon2i_32 will write past the end of…

  • CVE-2026-50554MedSep 3, 2026
    risk 0.27cvss 5.3epss 0.00

    Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the service runs the query with Unscoped() (bypassing GORM's…

  • CVE-2026-48486HigSep 3, 2026
    risk 0.42cvss 7.5epss 0.00

    Signum Node is a HDD-mined cryptocurrency using an energy efficient and fair Proof-of-Commitment (PoC+) consensus algorithm. Prior to version 3.9.9, an integer overflow in BlockServiceImpl.applyBlock() allowed a miner to receive an arbitrarily inflated block reward by crafting a…

  • CVE-2026-85230MedSep 3, 2026
    risk 0.28cvss 5.4epss 0.00

    A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rendered and were not validated when the configuration was saved. As a result, an authenticated user able to…

  • CVE-2026-85227MedSep 3, 2026
    risk 0.33cvss 6.1epss 0.00

    MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The taggedAttributes and galaxyAttachedAttributes URL parameters were inserted into the query-builder rules without HTML escaping before being serialized as JSON…

  • CVE-2026-85226MedSep 3, 2026
    risk 0.21cvss 4.3epss 0.00

    MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from matching attribute values without applying the distribution, sharing group, organization, or other access-control restrictions associated with the correlated…

  • CVE-2026-85221CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.00

    MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verification unless the calling…

  • CVE-2026-85216CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but…

  • CVE-2026-85214HigSep 3, 2026
    risk 0.53cvss 8.1epss 0.01

    vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including…

  • CVE-2026-85213HigSep 3, 2026
    risk 0.42cvss 7.6epss 0.00

    Kill Bill through 0.24.21 fails to enforce permission annotations on several AdminResource endpoints including getQueueEntries, invalidatesCache, and putOutOfRotation. Authenticated users with minimal account:read permissions can read internal queues, flush server caches, and…

  • CVE-2026-85212HigSep 3, 2026
    risk 0.47cvss 8.3epss 0.01

    CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check…

  • CVE-2026-85211HigSep 3, 2026
    risk 0.50cvss 7.7epss 0.00

    Label Studio fails to apply organization filters when resolving storage URIs for tasks and projects in proxy_api.py endpoints. Attackers can access other tenants' cloud storage objects by creating a separate organization and supplying arbitrary file URIs to presign or stream…

  • CVE-2026-85210MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. Attackers can query the endpoint with filter_criterion parameters to retrieve usernames holding specific…

  • CVE-2026-85199HigSep 3, 2026
    risk 0.50cvss —epss 0.01

    Eclipse aeriOS Self-orchestrator versions prior to 1.2.1 contain a path traversal vulnerability in the REST API. User-controlled identifiers used to create, update, or delete Self-orchestrator resources were incorporated into filesystem paths without adequate validation or…

  • CVE-2026-85183CriSep 3, 2026
    risk 0.53cvss 9.3epss 0.00

    Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable…

  • CVE-2026-85182HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body.

  • CVE-2026-85181CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full…

  • CVE-2026-85180HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.01

    Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET…

  • CVE-2026-85179HigSep 3, 2026
    risk 0.48cvss 8.5epss 0.00

    Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data…

  • CVE-2026-85178HigSep 3, 2026
    risk 0.43cvss 7.7epss 0.00

    Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can…

  • CVE-2026-85177MedSep 3, 2026
    risk 0.28cvss 5.4epss 0.00

    CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system inbox messages. Attackers can update any message's columns including is_del, look, and uid to delete, mark…

  • CVE-2026-85176HigSep 3, 2026
    risk 0.50cvss 8.8epss 0.01

    DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including…

  • CVE-2026-85135MedSep 3, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repository/Service/Resources/ZipAdapter.php of the component MediaPool. The manipulation results in…

  • CVE-2026-84989HigSep 3, 2026
    risk 0.39cvss 7.1epss 0.00

    ntopng is a web-based network traffic monitoring application. In versions 6.7.0 through 6.7.260717, two REST v2 endpoints that manage ntopng's tag/badge feature — `POST /lua/rest/v2/delete/tag/tag.lua` and `POST /lua/rest/v2/edit/tag/tag.lua` — perform no authorization check…

  • CVE-2026-84971MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted value where an application will decrypt it,…