VYPR

CVEs

383,041 total · page 319 of 7,661

  • CVE-2026-82265MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing unauthenticated attackers to access sensitive information. Attackers can read environment variables, bean configurations, and storage credentials via actuator…

  • CVE-2026-82264MedAug 28, 2026
    risk 0.37cvss 6.8epss 0.01

    Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry paths deserialized from snapshot files. Attackers can craft malicious snapshot entries with directory traversal sequences to write files outside the restore…

  • CVE-2026-82263MedAug 28, 2026
    risk 0.37cvss 6.8epss 0.00

    Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint that fails to validate the issuer URL parameter. Tenant administrators with Management API credentials can supply arbitrary internal URLs to trigger HTTP GET…

  • CVE-2026-82262MedAug 28, 2026
    risk 0.37cvss 6.8epss 0.00

    Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that accepts arbitrary URLs without host validation. Tenant administrators with Management API tokens can make the server issue HTTP POST requests to internal URLs…

  • CVE-2026-82021HigAug 28, 2026
    risk 0.47cvss 8.3epss 0.00

    Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA. An…

  • CVE-2026-82020MedAug 28, 2026
    risk 0.37cvss 6.8epss 0.00

    Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can influence ingested message content to overwrite the credential store by bypassing sensitive-path guards that excluded the auth.json file. Attackers can craft…

  • CVE-2026-81849HigAug 28, 2026
    risk 0.50cvss 8.8epss 0.01

    Improper limitation of a pathname to a restricted directory in the aws:downloadContent plugin in amazon-ssm-agent before 3.3.4515.0 might allow an authenticated remote user whose ssm:SendCommand permission is restricted to the AWS-DownloadContent document, to write arbitrary…

  • CVE-2026-77939MedAug 28, 2026
    risk 0.42cvss 6.5epss 0.01

    Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attackers with a valid API token to read arbitrary files by passing unsanitized user-supplied input to the Symfony ExpressionLanguage engine via the POST…

  • CVE-2026-77586HigAug 28, 2026
    risk 0.52cvss 8.0epss 0.00

    In MongoDB Connector for BI, MongoDB object names such as collection, field, and index names are placed into the quoted identifiers of the DDL text returned by SHOW CREATE statements without escaping the identifier delimiter. A user with permission to write to a sampled MongoDB…

  • CVE-2026-77218MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The web_login_first_post handler copies the usrPass POST parameter into a fixed-size stack buffer without length validation, the…

  • CVE-2026-77217MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains authenticated stack buffer overflow and null pointer dereference vulnerabilities in /cgi-bin/dispatcher.cgi. The web_radiusSrv*_post family of handlers copies the radKey, radKey_0, radDftParamKey, radName, and radIp…

  • CVE-2026-77184MedAug 28, 2026
    risk 0.34cvss 5.2epss 0.00

    In MongoDB Connector for BI, the description text of a collection's JSON schema validator is incorporated into the comment text of the DDL returned by SHOW CREATE statements without complete escaping of backslash characters. A user with permission to modify a collection's schema…

  • CVE-2026-76798MedAug 28, 2026
    risk 0.41cvss 6.3epss 0.00

    The MongoSQL Transition Readiness Tool writes query text and user names read from BI Connector log files into its generated HTML report without encoding them for that output context. A user able to issue queries through the BI Connector can influence log content so that markup…

  • CVE-2026-76797MedAug 28, 2026
    risk 0.41cvss 6.3epss 0.00

    The MongoSQL Transition Readiness Tool writes database and collection names into its generated CSV reports without neutralizing leading characters that spreadsheet applications treat as formulas. A user with write privileges on the cluster can choose a namespace name that is…

  • CVE-2026-76794MedAug 28, 2026
    risk 0.30cvss 4.6epss 0.00

    MongoSQL Transition Readiness Tool does not sufficiently encode database metadata before including it in generated HTML. A MongoDB user with write access can introduce crafted metadata that may cause script code to run when another user generates and opens the report,…

  • CVE-2026-75486HigAug 28, 2026
    risk 0.45cvss 8.0epss 0.02

    Synk Sweater Comb before 3.8.8 contains a command injection vulnerability that allows an attacker who controls the .vervet.yaml configuration file to execute arbitrary OS commands by injecting malicious input into the linters..optic-ci.original branch name field. The…

  • CVE-2026-75126MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains multiple authenticated stack buffer overflow vulnerabilities in /cgi-bin/dispatcher.cgi. The following handlers copy attacker-controlled POST parameters into fixed-size stack buffers without length validation:…

  • CVE-2026-75125MedAug 28, 2026
    risk 0.32cvss 4.9epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated null pointer dereference vulnerability in /cgi-bin/dispatcher.cgi. The web_poe_alive_rmtip_post handler dereferences the rmtIP parameter without verifying its presence. A remote authenticated attacker…

  • CVE-2026-75124HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing…

  • CVE-2026-75123HigAug 28, 2026
    risk 0.47cvss 7.2epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_smtp_test_post handler incorporates a caller-supplied SMTP server value directly into a shell command without sanitization. A…

  • CVE-2026-75122HigAug 28, 2026
    risk 0.47cvss 7.2epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/httpuploadcert.cgi. The certificate password field in a certificate upload request is incorporated into a shell command without sanitization of shell…

  • CVE-2026-75121HigAug 28, 2026
    risk 0.47cvss 7.2epss 0.01

    PLANET GS-4210-16P2S V3 firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-bin/dispatcher.cgi. The web_vlan_membership_edit_dialog_post handler incorporates the memberTags POST parameter into a shell command without sanitization. A…

  • CVE-2026-72984HigAug 28, 2026
    risk 0.57cvss 8.8epss 0.01

    Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70331MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-70309MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-66798MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-66324MedAug 28, 2026
    risk 0.42cvss 6.5epss 0.01

    External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-66323MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62904MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-58616MedAug 28, 2026
    risk 0.29cvss 4.4epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

  • CVE-2026-56100HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.01

    SpringBlade versions from 2.7.3 up to but not including 5.0.0 contain a privilege escalation vulnerability that allows authenticated attackers to create system administrator accounts by sending crafted POST requests to an unprotected internal Feign user-creation endpoint exposed…

  • CVE-2026-55834MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.00

    Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to services. From 2.6.0 until 2.9.0, frontend/src/routes/authorize/+page.ts reads the redirect_uri query parameter and frontend/src/routes/authorize/+page.svelte uses the raw callbackURL in…

  • CVE-2026-55673HigAug 28, 2026
    risk 0.39cvss —epss 0.01

    PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to 7.2.2, UnixLocalCommandExecutor and WindowsLocalCommandExecutor concatenate command arguments and environment variables into strings interpreted through bash -c or cmd /c without…

  • CVE-2026-55634CriAug 28, 2026
    risk 0.57cvss 9.9epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an…

  • CVE-2026-55584HigAug 28, 2026
    risk 0.45cvss 7.5epss 0.02

    phpSysInfo is a customizable PHP script that displays system information. Prior to 3.4.6, the PSI_ALLOWED access-control check in read_config.php trusts attacker-controlled X-Forwarded-For and Client-IP HTTP headers before REMOTE_ADDR. A remote unauthenticated attacker can…

  • CVE-2026-55569MedAug 28, 2026
    risk 0.36cvss 6.6epss 0.00

    aqua is a declarative command-line version manager written in Go. Prior to 2.60.1, pkg/unarchive/archives.go in the handler.HandleFile method calls os.Symlink with archives.FileInfo.LinkTarget without verifying that the target remains under the extraction destination. A later…

  • CVE-2026-55566MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs processes attacker-controlled data from the /ext URL route in yamcs-web/src/main/webapp/projects/webapp/src/app/core/routes/extension.matcher.ts, extension.component.ts, and app.component.ts without checking…

  • CVE-2026-55565CriAug 28, 2026
    risk 0.57cvss 9.9epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by…

  • CVE-2026-55559CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context…

  • CVE-2026-55552HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    Yamcs is a mission control framework. Prior to 5.11.13, Yamcs StaticFileHandler.locateFile resolves an unauthenticated request path without using Path.normalize and Path.toAbsolutePath to confirm that the absolute path remains within the configured staticRoots. A path containing…

  • CVE-2026-55549MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.01

    Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from GET /auth/authorize into yamcs-core/src/main/resources/auth/templates/authorize.html without adequate HTML escaping by yamcs-core/src/main/java/org/yamcs/http/a…

  • CVE-2026-55547MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits SystemPrivilege.ControlAccess checks from IamApi.listRoles, IamApi.getRole, and IamApi.listPrivileges in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java. Any authenticated account can call GET…

  • CVE-2026-55545MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce the privileges required by equivalent REST endpoints. PacketsApi.subscribePackets exposes the packets WebSocket topic without ObjectPrivilegeType.ReadPacket,…

  • CVE-2026-55521HigAug 28, 2026
    risk 0.50cvss 8.8epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs omits authorization checks in IndexesApi.listPacketIndex, IndexesApi.listEventIndex, Cop1Api.disable, Cop1Api.resume, Cop1Api.initialize, Cop1Api.updateConfig, and TimeApi.setTime. An authenticated…

  • CVE-2026-55520HigAug 28, 2026
    risk 0.39cvss —epss 0.01

    Protego is a pure-Python robots.txt parser with support for modern conventions. Prior to 0.6.2, protego._urlpattern._URLPattern._prepare_pattern_for_regex translates every asterisk in an Allow or Disallow directive into a lazy regular-expression wildcard, so a directive…

  • CVE-2026-55511CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and…

  • CVE-2026-55509HigAug 28, 2026
    risk 0.50cvss —epss 0.01

    WsgiDAV is a generic and extendable WebDAV server based on WSGI. Prior to 4.3.5, the sample MySQLBrowserProvider in wsgidav/samples/mysql_dav_provider.py concatenates the record key parsed from a request URL directly into SQL WHERE clauses. The affected…

  • CVE-2026-55485HigAug 28, 2026
    risk 0.50cvss 8.8epss 0.01

    Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured…

  • CVE-2026-55484HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the…

  • CVE-2026-55425MedAug 28, 2026
    risk 0.26cvss 5.0epss 0.00

    Graylog is a free and open log management platform. From 7.1.0 until 7.1.4 and 7.2.0-alpha.2, the System Catalog entity titles endpoint in graylog2-server/src/main/java/org/graylog2/rest/resources/system/contentpacks/titles/EntityTitleServiceImpl.java allows an authenticated…