VYPR

CVEs

37,811 total · page 30 of 757

  • CVE-2026-85506CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

  • CVE-2026-85504CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

  • CVE-2026-11613CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the…

  • CVE-2026-85148CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.

  • CVE-2026-85146CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application source code.

  • CVE-2026-75754CriSep 4, 2026
    risk 0.65cvss —epss 0.00

    Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The…

  • CVE-2026-67402CriSep 4, 2026
    risk 0.60cvss —epss 0.01

    An insecure Apache configuration in ConfigServer Security & Firewall maps /usr/bin as CGI programs through the Messenger v3 HTTPS virtual host. A remote unauthenticated attacker whose address is blocked can request a mapped executable and run arbitrary commands as the Apache…

  • CVE-2026-85440CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers can exploit the signed integer check in InflateTo() and…

  • CVE-2026-85438CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with…

  • CVE-2026-85437CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow…

  • CVE-2026-85435CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.00

    MOOS-IvP uFldNodeBroker through 24.8.1 fails to validate the source of TRY_SHORE_HOST messages on the vehicle bus, allowing any publisher to enroll attacker-controlled shore routes. Attackers can publish malicious shore route messages to receive bridged vehicle traffic including…

  • CVE-2026-85434CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.00

    MOOS-IvP uFldShoreBroker through 24.8.1 fails to verify node ping authenticity before creating outbound bridge routes. Attackers can publish NODE_BROKER_PING messages with crafted HostRecord data to redirect bridged variables to attacker-controlled addresses.

  • CVE-2026-85433CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS essential-moos pShare through 10.0.1 fails to properly authorize PSHARE_CMD messages, allowing any publisher to reconfigure network routes and listeners at runtime. Attackers can send crafted PSHARE_CMD messages with cmd=output or cmd=input parameters to open new listeners…

  • CVE-2026-85430CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.01

    MOOS essential-moos through 10.0.1 contains an authentication bypass vulnerability in pShare that accepts UDP datagrams from any source and republishes them with the attacker-claimed identity intact. Attackers can send crafted UDP datagrams to pShare input routes to inject…

  • CVE-2026-85428CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS core-moos through 10.4.0 contains an authentication bypass vulnerability in the optional MOOSDB HTTP server that allows unauthenticated clients to write variables. Attackers can send HTTP requests with variable names and values to the MOOSDB HTTP server port to modify MOOS…

  • CVE-2026-85426CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process user through unquoted redirection targets…

  • CVE-2026-85425CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitution syntax to execute arbitrary commands…

  • CVE-2026-85424CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MOOS core-moos through 10.4.0 lacks authentication in the wire protocol, allowing unauthenticated clients to connect with full publish, subscribe, and database clear privileges. Attackers can bypass the compile-time protocol string check and connect with arbitrary client names…

  • CVE-2026-83711CriSep 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-80098CriSep 3, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-70352CriSep 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62916CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.01

    Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-85224CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. The attack can be launched…

  • CVE-2026-85223CriSep 3, 2026
    risk 0.64cvss 9.9epss 0.03

    A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results in os command injection. The…

  • CVE-2026-85222CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.04

    A vulnerability has been found in D-Link DNS-340L 1.01B04. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/addon_center.cgi of the component Add-On Center. Such manipulation of the argument f_name/f_url/f_flag/f_login_user leads to os command…

  • CVE-2026-85061CriSep 3, 2026
    risk 0.58cvss 10.0epss 0.01

    MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collection, shifting indexes and skipping an…

  • CVE-2026-85050CriSep 3, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85047CriSep 3, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper input validation in Transactions Platform in Google Chrome on on iOS prior to 152.0.7977.82 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-85043CriSep 3, 2026
    risk 0.59cvss 9.1epss 0.00

    Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)

  • CVE-2026-85042CriSep 3, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-85394CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.00

    python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not…

  • CVE-2026-85391CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user IDs and access protected endpoints…

  • CVE-2026-82526CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL statements by manipulating the index name parameter in the vector index creation endpoint. The index name is interpolated directly into a CREATE INDEX…

  • CVE-2026-58400CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.01

    GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without disabling Java extension…

  • CVE-2026-84834CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

  • CVE-2026-84814CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

  • CVE-2026-84813CriSep 3, 2026
    risk 0.53cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

  • CVE-2026-84768CriSep 3, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

  • CVE-2026-84753CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

  • CVE-2026-84238CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

  • CVE-2026-85221CriSep 3, 2026
    risk 0.52cvss 9.1epss 0.00

    MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verification unless the calling…

  • CVE-2026-85216CriSep 3, 2026
    risk 0.57cvss 9.8epss 0.01

    MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but…

  • CVE-2026-85183CriSep 3, 2026
    risk 0.53cvss 9.3epss 0.00

    Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable…

  • CVE-2026-85181CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and create admin sessions with full…

  • CVE-2026-85109CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow. The attack may be launched remotely.…

  • CVE-2026-82180CriSep 3, 2026
    risk 0.62cvss —epss 0.00

    In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication policy, CertificateMqttFilter parses an X.509 certificate that the client sends inside the MQTT message payload (the authentication field of MqttRequestTemplate)…

  • CVE-2026-85165CriSep 3, 2026
    risk 0.57cvss 9.9epss 0.01

    n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects…

  • CVE-2026-85154CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.01

    WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it…

  • CVE-2026-85031CriSep 3, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.

  • CVE-2026-80726CriSep 3, 2026
    risk 0.53cvss 9.3epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page Explicitly clear role.invalid when deriving a child shadow page's role from its parent to harden against bugs elsewhere in KVM, as…