VYPR

CVEs

37,811 total · page 31 of 757

  • CVE-2026-78080CriSep 3, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used in queries without validation, allowing SQLi vectors.

  • CVE-2026-78069CriSep 3, 2026
    risk 0.62cvss —epss 0.00

    Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6 - `J2StoreControllerApps`'s `appTask` delegation path instantiates app-plugin controllers with no ACL check anywhere in the code. It…

  • CVE-2026-76178CriSep 3, 2026
    risk 0.60cvss —epss 0.00

    A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports/?function=notification. A user with administrator privileges can input malicious HTML content which is subsequently stored and displayed without proper…

  • CVE-2026-76174CriSep 3, 2026
    risk 0.61cvss —epss 0.01

    Unrestricted file upload vulnerability in the CSV file upload functionality of the Ocsreports admin_info endpoint. The application validates files solely based on the name provided by the client, without properly checking their content or securely restricting the permitted file…

  • CVE-2026-19117CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

  • CVE-2026-66786CriSep 2, 2026
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and…

  • CVE-2026-53671CriSep 2, 2026
    risk 0.53cvss —epss 0.01

    PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, the abstract transformer in prevail treats writes through a T_CTX-typed base register as a silent no-op: do_mem_store in src/crab/ebpf_transformer.cpp only models…

  • CVE-2026-53670CriSep 2, 2026
    risk 0.53cvss —epss 0.01

    PREVAIL is a Polynomial-Runtime EBPF Verifier using an Abstract Interpretation Layer. Prior to version 0.2.4, in the Prevail eBPF verifier, EbpfTransformer::add() silently skips offset-variable updates when the destination register carries a non-singleton typeset (two or more…

  • CVE-2026-53649CriSep 2, 2026
    risk 0.55cvss 9.6epss 0.00

    Joro is a web exploitation framework. Prior to version 1.1.1, Joro's default proxy mode exposes a local API on 127.0.0.1:9090 that performs no authentication and applies a wildcard CORS policy. Because plugin uploads use the CORS-safelisted multipart/form-data content type,…

  • CVE-2026-20279CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered…

  • CVE-2026-20274CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.01

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered…

  • CVE-2026-20212CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3…

  • CVE-2026-53611CriSep 2, 2026
    risk 0.57cvss 9.8epss 0.02

    Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to…

  • CVE-2026-82955CriSep 2, 2026
    risk 0.52cvss —epss 0.00

    In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart…

  • CVE-2026-77009CriSep 2, 2026
    risk 0.64cvss 9.9epss 0.01

    The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.

  • CVE-2026-4357CriSep 2, 2026
    risk 0.65cvss 10.0epss 0.01

    The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

  • CVE-2025-9314CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

  • CVE-2026-73475CriSep 2, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.

  • CVE-2026-76595criSep 2, 2026
    risk 0.59cvss —epss —

    advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)

  • CVE-2026-84803CriSep 2, 2026
    risk 0.52cvss 9.0epss 0.00

    SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in asset serving due to an incomplete extension blocklist that misses script-capable file types. Attackers can upload files with extensions like .xht, .ehtml, .xsl, .xbl, or .rdf that resolve to executable…

  • CVE-2026-84795CriSep 2, 2026
    risk 0.57cvss 9.8epss 0.01

    Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when public registration and disabled…

  • CVE-2026-81294CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

  • CVE-2026-81286CriSep 2, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.

  • CVE-2026-78657CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.01

    The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated…

  • CVE-2026-9055CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.01

    The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which…

  • CVE-2026-84699CriSep 2, 2026
    risk 0.59cvss 9.1epss 0.01

    Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

  • CVE-2026-84354CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84353CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-84352CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-84333CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84325CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

  • CVE-2026-84324CriSep 2, 2026
    risk 0.59cvss 9.0epss 0.00

    Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

  • CVE-2026-84480CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's…

  • CVE-2026-84479CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.01

    WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp")…

  • CVE-2026-84639CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84637CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading…

  • CVE-2026-84372CriSep 1, 2026
    risk 0.57cvss 9.8epss 0.01

    Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by…

  • CVE-2026-83548CriKEVSep 1, 2026
    risk 0.77cvss 10.0epss 0.09

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and…

  • CVE-2026-75604CriSep 1, 2026
    risk 0.55cvss 9.0epss 0.02

    Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before…

  • CVE-2023-54391CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.03

    Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary…

  • CVE-2026-73749CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could…

  • CVE-2026-76658CriSep 1, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a…

  • CVE-2026-76657CriSep 1, 2026
    risk 0.65cvss 10.0epss 0.01

    Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges…

  • CVE-2026-73701CriSep 1, 2026
    risk 0.59cvss 9.0epss 0.01

    An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker's control are met. Successful exploitation of this vulnerability could allow…

  • CVE-2026-73700CriSep 1, 2026
    risk 0.59cvss 9.0epss 0.00

    A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit could…

  • CVE-2026-19766CriSep 1, 2026
    risk 0.62cvss 9.6epss 0.00

    An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a privileged user on the underlying operating system, leading…

  • CVE-2026-52111CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in fast-note-sync-service <=2.13.7 allows a remote attacker to escalate privileges via the admin configuration endpoint exposes authTokenKey

  • CVE-2026-19593CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree status when a user opened a workspace. If the workspace contains a repository with preserved attacker-controlled .git/config, the attr.tree setting and a configured clean or process…

  • CVE-2026-79687CriSep 1, 2026
    risk 0.59cvss 9.0epss 0.00

    Dell PowerStore SDNAS contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access.

  • CVE-2026-51770CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the sendToMasterQosConfig function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to forward attacker-controlled QoS settings to the master via sending a crafted MQTT message to the cs_broker component..