VYPR

CVEs

35,069 total · page 3 of 702

  • CVE-2026-48765CriAug 11, 2026
    risk 0.57cvss 9.9epss 0.00

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an…

  • CVE-2026-73034CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can…

  • CVE-2026-73032CriAug 11, 2026
    risk 0.55cvss 9.6epss 0.00

    PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt…

  • CVE-2026-66145CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

  • CVE-2026-45618CriAug 11, 2026
    risk 0.58cvss 10.0epss 0.01

    LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

  • CVE-2026-16230CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the…

  • CVE-2026-73211CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables,…

  • CVE-2026-73090CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.00

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a…

  • CVE-2026-71398CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not…

  • CVE-2026-71362CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

  • CVE-2026-69102CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers…

  • CVE-2026-48381CriAug 11, 2026
    risk 0.59cvss 9.0epss 0.00

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to…

  • CVE-2026-47705CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which…

  • CVE-2026-27302CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not…

  • CVE-2026-71384CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application…

  • CVE-2026-70306CriAug 11, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-69223CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • CVE-2026-65791CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62893CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62878CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62815CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

  • CVE-2026-59124CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

  • CVE-2026-50516CriAug 11, 2026
    risk 0.61cvss 9.4epss 0.01

    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-48362CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.02

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute…

  • CVE-2026-12571CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

  • CVE-2026-73080CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.00

    SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs…

  • CVE-2026-73069CriAug 11, 2026
    risk 0.52cvss 9.1epss 0.00

    Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id…

  • CVE-2025-31114CriAug 11, 2026
    risk 0.54cvss epss 0.01

    Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the…

  • CVE-2026-72920CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser,…

  • CVE-2026-47702CriAug 11, 2026
    risk 0.52cvss epss 0.00

    TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or…

  • CVE-2026-17061CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.

  • CVE-2026-51584CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.00

    An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's…

  • CVE-2026-48056CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.00

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with…

  • CVE-2026-48046CriAug 11, 2026
    risk 0.60cvss epss 0.00

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary,…

  • CVE-2026-46670CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.02

    YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a default YesWiki install to inject arbitrary SQL into an `INSERT` statement and read…

  • CVE-2026-72748CriAug 11, 2026
    risk 0.52cvss 9.1epss 0.01

    AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust…

  • CVE-2026-58115CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to…

  • CVE-2026-18972CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    An authenticated attacker can spoof another GUI user's identity by sending their request with the custom header \"Grpc-Metadata-USER\". This can lead to an account takeover attack from a user with low privileges to administrator.

  • CVE-2026-72603CriAug 11, 2026
    risk 0.64cvss 9.9epss 0.02

    An OS command injection vulnerability in wg-easy 15.3.0 allows users with the clients.create permission to execute arbitrary commands as root by injecting newline-delimited WireGuard PostUp directives into the client name field. The client name is written to the WireGuard…

  • CVE-2026-72599CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An SQL injection vulnerability in e107 2.4.0 allows unauthenticated remote attackers to execute arbitrary SQL via the news item page ID parameter. The parameter is concatenated without escaping into a SQL WHERE clause. An unauthenticated attacker can read, modify, or delete all…

  • CVE-2026-72550CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statements via the photo-view order parameter. The parameter is concatenated unescaped into a SHOW COLUMNS query via a bare PDO::query()…

  • CVE-2026-13738CriAug 11, 2026
    risk 0.60cvss epss 0.01

    CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents,…

  • CVE-2026-13737CriAug 11, 2026
    risk 0.60cvss epss 0.00

    CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale…

  • CVE-2026-58231CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components,…

  • CVE-2026-10579CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to…

  • CVE-2026-19516CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance,…

  • CVE-2026-13716CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

  • CVE-2026-19425CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2026-44758CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute…

  • CVE-2026-34265CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact…