VYPR

CVEs

378,628 total · page 337 of 7,573

  • CVE-2026-69160MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use strings.HasPrefix(requested_path, user.BasePath) without enforcing a directory separator boundary. An authenticated user with…

  • CVE-2026-68927LowAug 18, 2026
    risk 0.13cvss 3.0epss 0.00

    MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before appending a separately supplied android:port…

  • CVE-2026-68924MedAug 18, 2026
    risk 0.25cvss 4.9epss 0.01

    MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but does not continue to the next member, so an…

  • CVE-2026-68923MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware only in the deprecated MIDDLEWARE_CLASSES setting and omits it from the active MIDDLEWARE tuple, allowing a remote attacker to make…

  • CVE-2026-68922MedAug 18, 2026
    risk 0.29cvss 5.5epss 0.00

    MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource directory without rejecting traversal or…

  • CVE-2026-67921CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-67920HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.01

    An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components

  • CVE-2026-67846HigAug 18, 2026
    risk 0.44cvss 7.8epss 0.00

    Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the v3 and v4 NBDTLB implementations. The raw mstatus.SUM value participates in the read and write permission logic without an…

  • CVE-2026-67262HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read from or write to LUNs that the host is not authorized to access, bypassing per-initiator LUN access controls and leading to…

  • CVE-2026-66780MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses excessive permissions. This allows a compromised cluster to alter network configurations, specifically by overwriting other clusters'…

  • CVE-2026-63643MedAug 18, 2026
    risk 0.34cvss —epss 0.00

    MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js accepts an attacker-controlled URL, authentication data, and selfSignedCert setting through the unauthenticated Socket.IO namespace…

  • CVE-2026-63642MedAug 18, 2026
    risk 0.34cvss —epss 0.00

    MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the CHECK_ARTICLE_URL notification through the unauthenticated Socket.IO namespace /newsfeed and performs fetch(url, { method: "HEAD"…

  • CVE-2026-63641LowAug 18, 2026
    risk 0.08cvss —epss 0.00

    MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace…

  • CVE-2026-63640MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder in js/server_functions.js before invoking…

  • CVE-2026-61696MedAug 18, 2026
    risk 0.34cvss 6.3epss 0.00

    Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitted through feedback_message[message] is stored without sanitization and rendered in app/views/admin/feedback_messages/_feedback_mes…

  • CVE-2026-54570MedAug 18, 2026
    risk 0.38cvss 6.9epss 0.00

    AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElement.cs is not treated as an HTML integration point when its encoding attribute is text/html or…

  • CVE-2026-54552HigAug 18, 2026
    risk 0.44cvss 7.9epss 0.00

    sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. When sh runs from an elevated process and launches a command with _uid set to an unprivileged user, the child changes its UID but…

  • CVE-2026-53533MedAug 18, 2026
    risk 0.38cvss —epss 0.00

    aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-supplied addresses without rejecting embedded CR or LF bytes. Data after the line break is framed as additional standalone SMTP…

  • CVE-2026-52610CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction…

  • CVE-2026-52609MedAug 18, 2026
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web browser of a user by including a malicious payload in the reportico_criteria parameter in conjunction with the execute_mode=CRITERIA…

  • CVE-2026-52608CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.

  • CVE-2026-52607MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.01

    A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by specifying the filename in the target_format parameter in conjunction with the execute_mode=EXECUTE parameter of the run.php…

  • CVE-2026-50167MedAug 18, 2026
    risk 0.27cvss —epss 0.00

    Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrieving webhook and identity resources did not enforce ownership checks for authenticated API requests. An attacker with a valid API…

  • CVE-2026-50161CriAug 18, 2026
    risk 0.53cvss —epss 0.00

    libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length…

  • CVE-2026-50143HigAug 18, 2026
    risk 0.46cvss 8.1epss 0.00

    The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.10.11, getActorMCPServerURL in src/mcp/actors.ts concatenates the trusted Actor standby URL with the…

  • CVE-2026-49452MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url()…

  • CVE-2026-48508HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_principal.Permission.__init__() with zero Need objects when ADMIN_ONLY_AUTHORITY_CREATION and LEMUR_STRICT_ROLE_ENFORCEMENT are…

  • CVE-2026-44472HigAug 18, 2026
    risk 0.46cvss 8.1epss 0.00

    Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data with the newly activated account. An attacker…

  • CVE-2026-32657HigAug 18, 2026
    risk 0.47cvss 7.3epss 0.00

    Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, Dell Unity Version 5.4, Dell PowerFlex Manager Version 4.5.4, Dell PowerFlex Intelligent Catalog Versions 46.377.00 and 46.382.00…

  • CVE-2026-18392Aug 18, 2026
    risk 0.00cvss —epss —

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2021-43717CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously.

  • CVE-2021-43716CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.

  • CVE-2026-75924HigAug 18, 2026
    risk 0.57cvss 8.7epss 0.00

    A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Additionally, it can approve arbitrary Certificate Signing Requests (CSRs), which could lead to…

  • CVE-2026-75897HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow remote attackers to cause a denial of service via a crafted HTTP request.

  • CVE-2026-73372MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.

  • CVE-2026-73336MedAug 18, 2026
    risk 0.42cvss 6.4epss 0.00

    Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.

  • CVE-2026-72531MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.

  • CVE-2026-71573HigAug 18, 2026
    risk 0.54cvss 8.3epss 0.00

    Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

  • CVE-2026-71572MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.

  • CVE-2026-70415HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.01

    Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in NFS/RPC. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to command execution and denial of service.

  • CVE-2026-69220HigAug 18, 2026
    risk 0.50cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call…

  • CVE-2026-69219HigAug 18, 2026
    risk 0.50cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java uses ValueReader.readBytes to accept a wire-declared contentLength below…

  • CVE-2026-67271CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user…

  • CVE-2026-66783MedAug 18, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster administrator, or any user with permissions to modify the Submariner Custom Resource (CR), to specify an unvalidated image path.…

  • CVE-2026-66782MedAug 18, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token within the Submariner Custom Resource (CR) specification. An attacker with access to the cluster's etcd database or through `kubectl…

  • CVE-2026-66781MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-shared key (PSK) in an unencrypted format. This key, which is critical for securing communication between Kubernetes clusters, can be…

  • CVE-2026-63337HigAug 18, 2026
    risk 0.42cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.tools.jsonrpc.ProcedureDescription receives a javaReturnType value in an untrusted system.describe response and passes it through…

  • CVE-2026-63336MedAug 18, 2026
    risk 0.26cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure…

  • CVE-2026-63335MedAug 18, 2026
    risk 0.34cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header…

  • CVE-2026-61634NonAug 18, 2026
    risk 0.00cvss —epss 0.00

    The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java…