VYPR

CVEs

37,811 total · page 27 of 757

  • CVE-2026-69829CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69824CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Integer underflow (wrap or wraparound) in Microsoft Standard XPS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69819CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Out-of-bounds write in RPC Runtime allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69769CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows HTTP Print Provider allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69768CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows RNDIS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69730CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows DNS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69715CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Out-of-bounds read in Windows Direct Show allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69641CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.01

    Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-69595CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Services for NFS ONCRPC XDR Driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69590CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

  • CVE-2026-69586CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Integer overflow or wraparound in Microsoft Windows PDF allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69579CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69525CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69496CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows Compressed Folder allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69493CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Out-of-bounds read in Windows Event Logging Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69491CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows Microsoft DirectMusic allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69463CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69431CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Telnet Client allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69408CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69356CriSep 8, 2026
    risk 0.61cvss 9.3epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-69276CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Integer underflow (wrap or wraparound) in Microsoft UxTheme Library (uxtheme.dll) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-68839CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67643CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67636CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.01

    Out-of-bounds read in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67631CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-67378CriSep 8, 2026
    risk 0.59cvss 9.0epss 0.01

    Untrusted pointer dereference in SQL Server allows an unauthorized attacker to execute code over a network.

  • CVE-2026-65669CriSep 8, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-82533CriSep 8, 2026
    risk 0.55cvss 9.6epss 0.01

    DeepSeek Harness before 0.1.2-alpha.1 contains an authentication bypass vulnerability that grants unauthenticated access to its local HTTP agent-control API by accepting a client-supplied loopback Host header in place of validating the actual TCP connection origin. On the…

  • CVE-2026-79570CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    mfish-nocode-pro v1.0.0 was discovered to contain a SQL injection vulnerability in the tableName parameter at /sys/dbConnect/data. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-79569CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Movie_Recommend v1.0.0 was discovered to contain a SQL injection vulnerability in the sort parameter at /loadingmore. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-78997CriSep 8, 2026
    risk 0.60cvss 9.3epss 0.00

    UC Browser for Android (package com.UCMobile.intl, version 13.7.8.1314) contains a Universal Cross-Site Scripting vulnerability that allows an attacker to execute arbitrary JavaScript in the context of any origin. An attacker hosts a specially crafted URL on a UC-owned domain…

  • CVE-2026-75156CriSep 8, 2026
    risk 0.52cvss 9.1epss 0.00

    Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not validate the issuer or audience of Azure AD `id_token`s during OAuth login. Deployments are affected only when the FAB auth manager is configured with Azure AD as an OAuth provider. Because the signing keys are…

  • CVE-2026-26084CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.00

    A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to access sensitive information via crafted HTTP requests.

  • CVE-2026-86840CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.00

    The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper authorization vulnerability in channel commission attribution. A signed account can supply an arbitrary registered `channel_id` when minting tokens without verifying that the caller is authorized to mint on…

  • CVE-2026-79574CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.

  • CVE-2026-79577CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in the /cas/login component of sso-master v1.0.0 allows attackers to authenticate into the application without a password via sending a crafted POST request.

  • CVE-2026-79576CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in the Single-Sign On (SSO) component of Digital-Infrastructure v9.6.7 allows attackers to authenticate as any user, including the Admin, without a password.

  • CVE-2026-79571CriSep 8, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the SellerAuthorizeAspect component of springboot-project v1.0.0 allows unauthenticated attackers to access all seller management interfaces and list all products/orders, put products on/off sale, finish/cancel orders, and modify categories without…

  • CVE-2026-61516CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session.…

  • CVE-2026-12745CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12744CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.02

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12650CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.02

    A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12647CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12646CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-12645CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.01

    A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

  • CVE-2026-77098CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Private Metrics Server contained an SQL injection condition affecting database operations. Software customers upgrade to resolved maintenance release. Update Private Metrics Server.

  • CVE-2026-77092CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.00

    Content Extractor contained a deserialization of untrusted data issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Content Extractor.

  • CVE-2026-77089CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Command Center API contained an authentication bypass issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update Command Center.

  • CVE-2026-78234CriSep 8, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource.…

  • CVE-2026-71377CriSep 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Command Argument Injection Vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from…