VYPR

CVEs

383,399 total · page 346 of 7,668

  • CVE-2023-27508Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-27503Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-23544Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22446Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22445Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22437Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22434Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22433Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22430Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22426Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22423Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22420Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22364Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22352Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22343Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22328Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2023-22289Aug 27, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2026-81491HigAug 27, 2026
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The…

  • CVE-2026-16895MedAug 27, 2026
    risk 0.26cvss —epss 0.00

    A logic vulnerability (fail-open condition) has been identified within the Metasploit Framework's JSON-RPC web service interface. When an exception occurs during the database health check (db.check) and the environment variable MSF_WS_JSON_RPC_API_TOKEN is not explicitly set,…

  • CVE-2026-81486MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was detected in bsmi021 mcp-file-context-server 1.0.0. Affected by this issue is the function read_context of the file src/index.ts of the component Path Resolution. Performing a manipulation of the argument path results in path traversal. It is possible to…

  • CVE-2026-81485MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.01

    A security vulnerability has been detected in danielpopamd linkedin-ads-mcp 1.0.0. Affected by this vulnerability is the function fs.readFileSync of the file src/tools/campaign-management.ts of the component Media Upload. Such manipulation of the argument filePath leads to path…

  • CVE-2026-19398MedAug 27, 2026
    risk 0.44cvss —epss 0.00

    An out-of-bounds write in the SmiFlash SMM module of ASUS FA507NU and FA507NV BIOS allows a local  administrator to cause a system crash (BSOD) or BIOS corruption via a crafted software SMI (SW SMI) request with an oversized length value.Refer to the '  Security Update for…

  • CVE-2026-81421HigAug 27, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack…

  • CVE-2026-80183HigAug 27, 2026
    risk 0.46cvss —epss 0.00

    In OpenStack Keystone before 29.0.3, any authenticated user holding role:reader on any project can list every project-scoped role assignment under any domain by passing a domain ID as scope.project.id with include_subtree to the GET /v3/role_assignments endpoint. The domain's…

  • CVE-2026-47874MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    The vulnerability occurs when a client sends HTTP/1.1 pipelined requests over a single connection, causing the Reactor Netty HTTP server to consume an excessive amount of memory. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

  • CVE-2026-47863MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.7.19 and earlier

  • CVE-2026-47862MedAug 27, 2026
    risk 0.28cvss 5.4epss 0.00

    An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring…

  • CVE-2026-47861MedAug 27, 2026
    risk 0.41cvss 6.3epss 0.00

    An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Spring Integration 7.1.0 Spring…

  • CVE-2026-47860MedAug 27, 2026
    risk 0.42cvss 6.5epss 0.00

    An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the consumer JVM with a single ~1 MB message. Spring AMQP 4.1.0 Spring AMQP 4.0.0 - 4.0.4 Spring AMQP 3.2.0 - 3.2.12 Spring AMQP 2.4.18 and earlier

  • CVE-2026-47859MedAug 27, 2026
    risk 0.28cvss 5.4epss 0.00

    RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound. Spring Integration…

  • CVE-2026-47857MedAug 27, 2026
    risk 0.38cvss 5.9epss 0.00

    In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a Denial of Service (DoS) condition. Reactor Core 3.8.0 - 3.8.6 Reactor Core 3.5.0 - 3.7.19 Reactor Core 3.4.41 and earlier

  • CVE-2026-47856MedAug 27, 2026
    risk 0.34cvss 6.3epss 0.00

    Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5…

  • CVE-2026-47852HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A local attacker on a multi-user host can pre-create the deterministic cache path and plant a malicious ONNX model file. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

  • CVE-2026-47851HigAug 27, 2026
    risk 0.49cvss 7.5epss 0.00

    Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9

  • CVE-2026-47850MedAug 27, 2026
    risk 0.28cvss 4.3epss 0.00

    Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15…

  • CVE-2026-47845MedAug 27, 2026
    risk 0.34cvss 5.3epss 0.00

    In specific scenarios, Reactor Netty HTTP Server may incorrectly evaluate the remote IP address when HAProxy Protocol is enabled. In order for this to happen, the application must be configured to use HAProxy Protocol. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18…

  • CVE-2026-81203HigAug 26, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2026-80158MedAug 26, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the…

  • CVE-2026-75340CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is vulnerable to Server-side request forgery (SSRF).

  • CVE-2026-75338CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fetching APIs /api/config/item, /api/config/file, /api/config/list and /api/config/simple/list are exposed without authentication. The LoginInterceptor explicitly…

  • CVE-2026-75336CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.json.

  • CVE-2026-75332CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().

  • CVE-2026-75330CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerable to SQL injection. The module parameter is directly concatenated into the SQL IN clause through StringUtils.split() and string concatenation without being…

  • CVE-2026-69129MedAug 26, 2026
    risk 0.31cvss —epss 0.00

    KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated user with cluster management permissions to operate on clusters outside the scope they…

  • CVE-2026-65956CriAug 26, 2026
    risk 0.58cvss —epss 0.01

    KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached…

  • CVE-2026-47666HigAug 26, 2026
    risk 0.42cvss 7.6epss 0.00

    Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through custom font family names, which are interpolated into a @font-face CSS rule and injected into the page as HTML without…

  • CVE-2026-47665HigAug 26, 2026
    risk 0.50cvss 8.7epss 0.00

    Penpot is an open-source design and prototyping platform. In versions up to and including 2.14.3, Penpot is vulnerable to stored cross-site scripting through file comments, whose content is stored as raw text and rendered into the page with innerHTML without any sanitization.…

  • CVE-2026-21808MedAug 26, 2026
    risk 0.27cvss 4.1epss 0.00

    HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker with internal application logic and architectural details.

  • CVE-2026-21807LowAug 26, 2026
    risk 0.25cvss 3.9epss 0.00

    HCL BigFix Quantum Risk Analyzer binary lacks several critical, industry-standard hardening protections that could allow an attacker to cause a stack-based buffer overflow.

  • CVE-2026-18823Aug 26, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.