VYPR

CVEs

382,439 total · page 289 of 7,649

  • CVE-2026-51956Sep 1, 2026
    risk 0.00cvss —epss 0.00

    A Broken Object Level Authorization vulnerability exists in Grashjs Atlas CMMS prior to v1.6.0. An authenticated user from one tenant can read and modify another tenant's company record by changing only the numeric ID in the /company/{id} endpoint. The application does not…

  • CVE-2026-51934Sep 1, 2026
    risk 0.00cvss —epss 0.01

    Buffer Overflow vulnerability in Shenzhen Jixiang Tengda Technology Co., Ltd. Tenda A18 v.15.13.07.09 allows a remote attacker to execute arbitrary code via the fromSetCmdlineRun function

  • CVE-2026-51788HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in cleverange_auth v.0.1.10 allows a remote attacker to cause a denial of service via the account_verification function and the accounts/models.py component

  • CVE-2026-84270MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more…

  • CVE-2026-84269MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer,…

  • CVE-2026-84268HigSep 1, 2026
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated…

  • CVE-2026-84267MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing…

  • CVE-2026-84232MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: attachment header when using…

  • CVE-2026-84207MedSep 1, 2026
    risk 0.28cvss 5.4epss 0.00

    Heym before 0.0.98 fails to apply SSRF egress guards to WebSocket Send and WebSocket Trigger nodes, allowing authenticated users to connect to internal services. Attackers can craft workflow nodes with arbitrary URLs and headers to reach internal services and read responses from…

  • CVE-2026-84206MedSep 1, 2026
    risk 0.21cvss 4.3epss 0.00

    Snipe-IT before 8.7.0 gates the bulk asset restore endpoint on the assets.edit permission instead of assets.delete, allowing users without delete rights to restore soft-deleted assets. Attackers with edit permissions can post asset identifiers to the bulk restore endpoint to…

  • CVE-2026-84205MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    GROWI contains an access control vulnerability in the GET /_api/v3/revisions/:id endpoint that validates access against a query parameter but returns the revision identified by the path parameter without confirming they reference the same page. Authenticated attackers can pair a…

  • CVE-2026-84204MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    GROWI contains an access control vulnerability in the GET /_api/v3/attachment/:id endpoint that fails to validate page access permissions. Authenticated attackers can retrieve attachment metadata from pages they cannot view by supplying known attachment identifiers.

  • CVE-2026-84203HigSep 1, 2026
    risk 0.46cvss 8.1epss 0.00

    Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new access tokens and rotate the refresh token…

  • CVE-2026-84202HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    ModelScope uses PyYAML's unsafe yaml.Loader to parse model configuration files, allowing arbitrary code execution through Python object construction tags. Attackers can craft malicious model repositories with poisoned configuration files that execute code when loaded by users.

  • CVE-2026-84201HigSep 1, 2026
    risk 0.46cvss 7.1epss 0.00

    appium-mcp-server through 0.1.61 fails to validate or normalize file paths in the write_file and write_files_batch tools, allowing attackers to write files outside the intended PROJECT_ROOT directory. Attackers can supply absolute paths or relative paths with parent directory…

  • CVE-2026-84153MedSep 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in Xinhu Rainrock RockOA up to 2.3.2. The impacted element is the function toaddval of the file /index.php?m=index&a=publicsavevalue&ajaxbool=true. Executing a manipulation of the argument Value can lead to sql injection. The attack may be…

  • CVE-2026-79687CriSep 1, 2026
    risk 0.59cvss 9.0epss 0.00

    Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.

  • CVE-2026-79682HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    Dell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

  • CVE-2026-61779HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61778HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61777HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61776HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61775HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61774HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61773HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61772HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61771HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61770HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61769HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61768HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61767HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61766HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61765HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61764HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61763HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61762HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61761HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61760HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61759HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61758HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61757HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61756HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61755HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61754HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61753HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.01

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61752HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61751HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-61750HigSep 1, 2026
    risk 0.44cvss 7.8epss 0.00

    NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-58567HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    Dell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

  • CVE-2026-51770CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..