VYPR

CVEs

382,987 total · page 312 of 7,660

  • CVE-2026-82621HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This impacts the function AdminDao.doGet of the file code/src/service/AdminDao.java of the component Administrative Servlet. Executing a…

  • CVE-2026-82620MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in Soarkey StudentManagement and 学生信息管理系统 up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. This affects the function CourseDao.course_ranking of the file code/src/dao/CourseDao.java. Performing a manipulation of the argument cno…

  • CVE-2026-82619MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was identified in Systerel S2OPC up to 1.7.3. The impacted element is the function monitored_item_event_filter_treatment_bs__init_event_filter_ctx_and_result of the file src/ClientServer/services/bgenc/subscription_mgr.c. Such manipulation of the argument…

  • CVE-2026-82618MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in Systerel S2OPC up to 1.7.3. The affected element is the function set_range_matrix_on_string_array of the file src/Common/opcua_types/sopc_builtintypes.c of the component String Array Range Writing. This manipulation causes out-of-bounds read.…

  • CVE-2026-82616CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has…

  • CVE-2026-82615HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function Customer::find_phone of the file /passwordrecover.php of the component Password Recovery Interface. The manipulation of the argument phonenumber leads to sql…

  • CVE-2026-82614HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in itsourcecode Online Medicine Delivery System 1.0. This vulnerability affects the function loadResultList of the file /index.php?q=product of the component Product Category Filter Interface. Executing a manipulation of the argument Category can lead to…

  • CVE-2026-82727LowAug 31, 2026
    risk 0.08cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_phoenix writes the entire raw submitted param map into an exception message, so secrets submitted alongside a union form field leak into logs, crash reports and the dev error page. …

  • CVE-2026-82726MedAug 31, 2026
    risk 0.34cvss —epss 0.01

    Permissive Regular Expression vulnerability in ash-project ash_phoenix lets a remote client select the tenant an Ash application uses, or degrade the request, by sending a crafted Host header. AshPhoenix.Helpers.get_subdomain/2 stripped the root domain with String.replace(host,…

  • CVE-2026-82725LowAug 31, 2026
    risk 0.08cvss —epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_phoenix lets an attacker who controls filter form parameters filter across relationships the resource author marked non-public, turning the returned rows into a boolean oracle over private related…

  • CVE-2026-82724HigAug 31, 2026
    risk 0.42cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_phoenix invokes the SubdomainHook authorization callback with a nil tenant, so tenant-scoped access checks never see the tenant they are meant to enforce. AshPhoenix.LiveView.SubdomainHook.on_mount/4 attached a…

  • CVE-2026-82613HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in itsourcecode Online Medicine Delivery System 1.0. This affects the function loadResultList of the file /index.php?q=product of the component Product Search Interface. Performing a manipulation of the argument Search results in sql injection. The…

  • CVE-2026-82612HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in itsourcecode Online Medicine Delivery System 1.0. Affected by this issue is the function loadResultList of the file /index.php?q=single-item of the component Product Detail Page. Such manipulation of the argument ID leads to sql…

  • CVE-2026-82611HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function Customer::cusAuthentication of the file /login.php of the component Customer Login Interface. This manipulation of the argument U_USERNAME causes…

  • CVE-2026-82610HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. Affected is the function Employee::employeeAuthentication of the file /rider/login.php of the component Login Interface. The manipulation of the argument emp_email results in sql injection.…

  • CVE-2026-82609MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly…

  • CVE-2026-82722HigAug 31, 2026
    risk 0.47cvss —epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust the BEAM atom table and crash the entire node. Two LiveView event handlers interned atoms from unvalidated client input:…

  • CVE-2026-82681LowAug 31, 2026
    risk 0.06cvss —epss 0.00

    Improper Encoding or Escaping of Output vulnerability in ash-project ash_admin lets an attacker who controls a record's string primary key rewrite the target of AshAdmin's row-action links. The Table, DataTable, and Show components built row-action URLs by raw string…

  • CVE-2026-82673HigAug 31, 2026
    risk 0.47cvss —epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability in ash-project ash_admin allows writing attacker-controlled bytes to arbitrary paths on the server. AshAdmin.Components.Resource.Form.consume_file_uploads/1 builds the destination as…

  • CVE-2026-82608HigAug 31, 2026
    risk 0.41cvss 7.4epss 0.00

    A vulnerability was determined in Kamailio up to 5.5.0/6.0.7. This affects the function get_4bytes of the file src/modules/ims_registrar_scscf/cxdx_avp.c of the component AVP Handler. Executing a manipulation can lead to out-of-bounds read. The attack may be performed from…

  • CVE-2026-82607HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Cozmoslabs Profile Builder Plugin up to 3.16.1 on WordPress. The impacted element is the function wppb_ajax_simple_avatar of the file /wp-admin/admin-ajax.php of the component Avatar Simple Upload AJAX Handler. Performing a manipulation results in…

  • CVE-2026-82605MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix…

  • CVE-2026-81853LowAug 31, 2026
    risk 0.08cvss —epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_admin turns a record-lookup URL into an equality oracle over sensitive attributes. AshAdmin.Helpers.decode_primary_key/2 decodes the composite-primary-key form (Base64 plus ETF) and returns the…

  • CVE-2026-81852LowAug 31, 2026
    risk 0.07cvss —epss 0.01

    Use of Insufficiently Random Values vulnerability in ash-project ash_admin ships a hardcoded, publicly known CSP nonce, defeating nonce-based Content-Security-Policy protection. When mounted without :csp_nonce_assign_key, AshAdmin.Router.ash_admin/2 defaulted the img, style,…

  • CVE-2026-77850HigAug 31, 2026
    risk 0.48cvss —epss 0.00

    Stored Cross-site Scripting vulnerability in ash-project ash_admin executes attacker-supplied record content as script in an administrator's browser. The relationship typeahead components AshAdmin.Components.Resource.RelationshipField and AshAdmin.Components.Resource.ManagedRela…

  • CVE-2026-75757HigAug 31, 2026
    risk 0.47cvss —epss 0.01

    Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain rebind an admin's session to a different actor, tenant, or authorization mode. AshAdmin's client JavaScript read its state…

  • CVE-2026-82604MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.01

    A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this…

  • CVE-2026-82603MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was detected in SeaCMS up to 13.6. This issue affects some unknown processing of the file /member.php?action=del_pl of the component Comment Cache. The manipulation of the argument itype/vid results in path traversal. The attack may be launched remotely. The…

  • CVE-2026-82602MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in SeaCMS up to 13.6. This vulnerability affects unknown code of the file /ass.php. The manipulation leads to authorization bypass. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.

  • CVE-2026-82601MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in SeaCMS up to 13.6. This affects an unknown part of the file /err.php. Executing a manipulation of the argument errtxt can lead to cross site scripting. The attack can be launched remotely. The exploit has been made available to the public and…

  • CVE-2026-82600HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in SeaCMS up to 13.6. Affected by this issue is some unknown functionality of the file /zyapi.php?ac=videolist. Performing a manipulation of the argument ids results in sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-82580MedAug 31, 2026
    risk 0.27cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses internal error text to chat users. In AshAi.ToolLoop and AshAi.Tools, an exception raised while executing a tool was serialized verbatim with Exception.message/1 into the…

  • CVE-2026-82579MedAug 31, 2026
    risk 0.32cvss —epss 0.00

    Loop with Unreachable Exit Condition (Infinite Loop) vulnerability in ash-project ash_ai allows an attacker who can influence a model's output to hang the tool loop and drive unbounded, repeated model requests. AshAi.ToolLoop classifies a model response of :tool_calls, then…

  • CVE-2026-82564HigAug 31, 2026
    risk 0.39cvss —epss 0.01

    Authorization Bypass Through User-Controlled Key vulnerability in ash-project ash_ai allows a caller of an identity-configured tool to update or destroy records it never identified, including every row in the table. In AshAi.Tool.Execution, identity_filter/3 built the…

  • CVE-2026-75760HigAug 31, 2026
    risk 0.39cvss —epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash_ai discloses provider request state and credentials in a user-facing validation error. In AshAi.Changes.Vectorize, when the embedding provider call fails the change added a changeset…

  • CVE-2026-82599MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was identified in SeaCMS up to 13.6. Affected by this vulnerability is the function unlink of the file /member.php?action=chgpwdsubmit of the component Avatar Upload. Such manipulation of the argument oldpic leads to path traversal. It is possible to launch the…

  • CVE-2026-82598HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was determined in SeaCMS up to 13.6. Affected is the function parseIf of the file search.php of the component Template Engine. This manipulation of the argument searchtype causes code injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-82597HigAug 31, 2026
    risk 0.48cvss 7.4epss 0.02

    A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ussd leads to command injection. The attack can be initiated remotely. The exploit is publicly available…

  • CVE-2026-81315HigAug 31, 2026
    risk 0.41cvss —epss 0.00

    Origin Validation Error vulnerability in ash-project ash_ai allows a malicious web page to bypass the MCP server's DNS-rebinding protection and issue cross-site requests to a user's local MCP server with that user's actor. In AshAi.Mcp.Server, with the default allowed_origins:…

  • CVE-2026-77956HigAug 31, 2026
    risk 0.51cvss —epss 0.00

    Improper Control of Generation of Code (Code Injection) vulnerability in ash-project ash_ai allows a remote, unauthenticated client to execute arbitrary Elixir code. AshAi.Actions.Prompt evaluates prompt content through EEx.eval_string/2. The documented prompt: fn input,…

  • CVE-2026-82596LowAug 31, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. Executing a manipulation can lead to memory…

  • CVE-2026-82595HigAug 31, 2026
    risk 0.48cvss 7.4epss 0.04

    A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the file /boafrm/formSysCmd of the component System Command Execution. Performing a manipulation of the argument sysCmd results in command injection. It is possible…

  • CVE-2026-82594MedAug 31, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in LogNet grpc-spring-boot-starter up to 5.2.0. Affected is an unknown function of the component Annotation Processing. Such manipulation leads to improper authorization. The attack may be performed from remote. A high complexity level is…

  • CVE-2026-82593CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible…

  • CVE-2026-82592CriAug 30, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be…

  • CVE-2026-82591MedAug 30, 2026
    risk 0.27cvss 5.3epss 0.00

    A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer…

  • CVE-2026-82590MedAug 30, 2026
    risk 0.21cvss 4.3epss 0.01

    A weakness has been identified in Open5GS up to 2.7.7. The affected element is the function smf_nudm_sdm_handle_get of the file src/smf/nudm-handler.c of the component SMF. Executing a manipulation of the argument preemptCap can lead to reachable assertion. The attack may be…

  • CVE-2026-82589MedAug 30, 2026
    risk 0.21cvss 4.3epss 0.01

    A security flaw has been discovered in Open5GS up to 2.7.7. Impacted is the function amf_namf_comm_handle_n1_n2_message_transfer of the file src/amf/namf-handler.c of the component N1-N2 Message Handler. Performing a manipulation of the argument…

  • CVE-2026-82588MedAug 30, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was identified in Open5GS up to 2.7.7. This issue affects some unknown processing of the file src/amf/namf-handler.c of the component Transfer Endpoint. Such manipulation leads to null pointer dereference. The attack can be launched remotely. Upgrading to version…

  • CVE-2026-56718HigAug 30, 2026
    risk 0.49cvss 7.5epss 0.01

    AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI.…