VYPR

CVEs

37,811 total · page 34 of 757

  • CVE-2026-82870CriAug 31, 2026
    risk 0.62cvss 9.6epss 0.00

    ToolJet before v3.16.208 fails to validate organizationId ownership in database write and destroy routes, allowing any builder-role user to create, alter, or drop tables in other organizations' databases. Attackers can exploit missing organization-resolving guards to permanently…

  • CVE-2026-82860CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.01

    @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.

  • CVE-2026-82859CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.01

    hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.

  • CVE-2026-82858CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.00

    @hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe…

  • CVE-2026-82857CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.01

    hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent…

  • CVE-2026-82856CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.01

    @hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject conditions from security guardrails.

  • CVE-2026-82855CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.01

    @hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones,…

  • CVE-2026-82854CriAug 31, 2026
    risk 0.57cvss 9.8epss 0.02

    Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is concatenated into the SMTP MAIL FROM…

  • CVE-2026-19410CriAug 31, 2026
    risk 0.61cvss —epss 0.00

    An Incorrect Authorization vulnerability in GitHub Trigger Comment Control in Google Cloud Build prior to 2026-06-24 on Google Cloud Platform allows a remote attacker to execute unreviewed code in the build environment using webhook suppression. This vulnerability was patched…

  • CVE-2026-58574CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal system information from the appliance…

  • CVE-2026-82616CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack can be executed remotely. The exploit has…

  • CVE-2026-82593CriAug 31, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based buffer overflow. The attack is possible…

  • CVE-2026-82592CriAug 30, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-based buffer overflow. The attack can be…

  • CVE-2026-82542CriAug 30, 2026
    risk 0.65cvss 10.0epss 0.01

    A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to…

  • CVE-2026-82539CriAug 30, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched…

  • CVE-2026-15980CriAug 30, 2026
    risk 0.64cvss 9.8epss 0.00

    The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for…

  • CVE-2026-15369CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce…

  • CVE-2026-82460CriAug 29, 2026
    risk 0.57cvss 9.8epss 0.01

    Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured…

  • CVE-2026-82456CriAug 29, 2026
    risk 0.58cvss 10.0epss 0.02

    argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to…

  • CVE-2026-82454CriAug 29, 2026
    risk 0.52cvss 9.1epss 0.00

    The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to…

  • CVE-2026-82452CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.01

    rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly…

  • CVE-2026-82448CriAug 29, 2026
    risk 0.57cvss 9.8epss 0.01

    Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then…

  • CVE-2026-14494CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.01

    The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form…

  • CVE-2026-77012CriAug 29, 2026
    risk 0.60cvss 9.3epss 0.00

    The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated…

  • CVE-2026-16947CriAug 29, 2026
    risk 0.59cvss 9.1epss 0.00

    The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to…

  • CVE-2026-16259CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every…

  • CVE-2026-10522CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site…

  • CVE-2026-51663CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51661CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-3627CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2026-19295CriAug 28, 2026
    risk 0.57cvss 9.9epss 0.03

    IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege…

  • CVE-2026-19286CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

  • CVE-2026-18527CriAug 28, 2026
    risk 0.64cvss 9.9epss 0.00

    IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another…

  • CVE-2026-82329CriKEVAug 28, 2026
    risk 0.76cvss 9.8epss 0.14

    JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

  • CVE-2026-82277CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.01

    Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout,…

  • CVE-2026-82266CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.01

    Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and…

  • CVE-2026-55634CriAug 28, 2026
    risk 0.57cvss 9.9epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an…

  • CVE-2026-55565CriAug 28, 2026
    risk 0.57cvss 9.9epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs LikeExpression.fillCode_getValueReturn in yamcs-core/src/main/java/org/yamcs/yarch/streamsql/LikeExpression.java inserts an unescaped LIKE pattern into Java source compiled by…

  • CVE-2026-55559CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances and PATCH /api/instances/{instance} into YAML through VarStatement.append in yamcs-core/src/main/java/org/yamcs/templating/VarStatement.java without YAML-context…

  • CVE-2026-55511CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs allows a user with SystemPrivilege.ControlArchiving to create a double-quoted StreamSQL column name that is interpolated into generated Java source by Expression.fillCode_InputDefVars and…

  • CVE-2026-55378CriAug 28, 2026
    risk 0.53cvss —epss 0.01

    JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow in .github/workflows/pr_checker.yml places github.head_ref and github.event.pull_request.head.repo.full_name into BRANCH_NAME and SOURCE_REPO and interpolates…

  • CVE-2026-55248CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.00

    plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior to 5.0.8, 6.0.4, and 7.0.2, a member who can add an RSS portlet can set its feed URL to a very large response, causing src/plone/app/portlets/portlets/rss.py to download and retain…

  • CVE-2026-55247CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.00

    plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events,…

  • CVE-2026-55220CriAug 28, 2026
    risk 0.54cvss —epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource() in models/DataObject/ClassDefinition/Data/Hotspotimage.php passes the field __hotspots…

  • CVE-2026-55068CriAug 28, 2026
    risk 0.53cvss —epss 0.01

    free5GC is an open-source implementation of the 5G core network. In 4.2.2 and earlier, the NRF RegisterNFInstance handler at PUT /nnrf-nfm/v1/nf-instances/{nfInstanceID} accepts NF Profiles without enforcing UUID format, nfStatus enum values, heartBeatTimer ranges, mandatory…

  • CVE-2026-54755CriAug 28, 2026
    risk 0.55cvss 9.6epss 0.01

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those…

  • CVE-2026-54754CriAug 28, 2026
    risk 0.55cvss 9.6epss 0.00

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage live at purchase time. An asset…

  • CVE-2026-54745CriAug 28, 2026
    risk 0.58cvss 10.0epss 0.01

    Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in…

  • CVE-2026-51660CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain IP and port filtering rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51657CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getSyslogCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain syslog-related configuration via sending a crafted POST request to /cgi-bin/cstecgi.cgi.