VYPR

CVEs

383,419 total · page 348 of 7,669

  • CVE-2026-75413HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    DocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do interface and download any file via the parameter targetPath.

  • CVE-2026-75411CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy script execution. While the `SecurityCheck` class employs a blacklist mechanism to intercept dangerous calls, the dynamic nature of Groovy allows this…

  • CVE-2026-75364MedAug 26, 2026
    risk 0.44cvss 6.8epss 0.00

    Comfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitize the display_name parameter. User-controlled input is concatenated via sprintf() into the unquoted shell command `/etc/rrd/graphinterface…

  • CVE-2026-75363MedAug 26, 2026
    risk 0.44cvss 6.8epss 0.00

    An issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, and the parameters timestr, display_n.

  • CVE-2026-62326MedAug 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout,…

  • CVE-2026-62249MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints,…

  • CVE-2026-61792HigAug 26, 2026
    risk 0.43cvss 7.7epss 0.01

    Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths…

  • CVE-2026-61790MedAug 26, 2026
    risk 0.22cvss 4.4epss 0.00

    Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for…

  • CVE-2026-55228HigAug 26, 2026
    risk 0.46cvss 8.1epss 0.00

    Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the…

  • CVE-2026-55227MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user…

  • CVE-2026-52473MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder.

  • CVE-2026-52103CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.

  • CVE-2026-39275MedAug 26, 2026
    risk 0.33cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components

  • CVE-2026-15973HigAug 26, 2026
    risk 0.55cvss —epss 0.00

    LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the Survey Menu Entries administration page. An authenticated user with the global settings:read permission can create a survey menu entry containing attacker-controlled data. The value is…

  • CVE-2025-61480HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via spoofed TCP FIN packets without validating the sequence or acknowledgment numbers.

  • CVE-2025-61479HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via the SPC Connect Pro software accepts replayed application-layer payloads injected into an active TCP session.

  • CVE-2025-61478HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker to cause a denial of service via Spoofed SYN packets.

  • CVE-2025-51679CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected behavior.

  • CVE-2025-51675HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR changes can lead to a Denial of Service (DoS).

  • CVE-2026-79939MedAug 26, 2026
    risk 0.38cvss 5.8epss 0.00

    Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contain an UNIX Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Script injection.

  • CVE-2026-79938HigAug 26, 2026
    risk 0.49cvss 7.6epss 0.00

    Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an Improper Authentication vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

  • CVE-2026-77652HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    A heap-based buffer overflow vulnerability exists in the Dia diagram editor WPG file format importer. In plug-ins/wpg/wpg-import.c, the WPG import renderer allocates a fixed palette with: ren->pPal = g_new0(WPGColorRGB, 256); When handling a WPG_COLORMAP record, the…

  • CVE-2026-77508LowAug 26, 2026
    risk 0.16cvss 3.5epss 0.00

    Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted…

  • CVE-2026-75601MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Static Web Server (SWS) is a production-ready web server suitable for static web files or assets. Through 2.43.0, instances with both basic-auth and metrics features enabled process the /metrics endpoint before the basic-auth check in src/handler.rs, allowing an unauthenticated…

  • CVE-2026-75334CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql parameter is stored in the t_report_sql_resource table through the ReportController.save() interface and directly embedded into Hibernate native queries without…

  • CVE-2026-75327CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arbitrary file upload vulnerability:

  • CVE-2026-74774MedAug 26, 2026
    risk 0.38cvss 5.9epss 0.00

    Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2026-74771MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.

  • CVE-2026-74770HigAug 26, 2026
    risk 0.57cvss 8.8epss 0.02

    Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code…

  • CVE-2026-71172MedAug 26, 2026
    risk 0.28cvss 4.3epss 0.00

    Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.

  • CVE-2026-71054MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE. Successful attacks of this…

  • CVE-2026-68863HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    Dell PowerProtect One, versions 20.1.0.0 and below, contain a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

  • CVE-2026-68861HigAug 26, 2026
    risk 0.57cvss 8.8epss 0.02

    Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote…

  • CVE-2026-68000CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular…

  • CVE-2026-67275MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning.

  • CVE-2026-66003HigAug 26, 2026
    risk 0.39cvss —epss 0.00

    Frappe is a full-stack web application framework written in Python and JavaScript. Prior to version 15.115.0, an access control bypass in the REST API allows a user to read data from Linked DocTypes that they are not authorized to access. When a document references another…

  • CVE-2026-60004CriKEVAug 26, 2026
    risk 0.71cvss 9.8epss 0.24

    Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

  • CVE-2026-56547LowAug 26, 2026
    risk 0.23cvss 3.5epss 0.00

    The Apple profile generated for the Apple built-in Mail, Calendar and Contacts account to synchronize with HCL Traveler requires the Logon Name and Mail Address to be embedded in them.  The values cannot be changed later on, so the Apple profile generation page asks for those…

  • CVE-2026-54245HigAug 26, 2026
    risk 0.42cvss —epss 0.01

    Fleet is an open-source device management platform built on osquery. In versions prior to 4.86.2, the Okta conditional access integration in Fleet Premium is vulnerable to SQL injection through a host-supplied value that is used in a database query without proper…

  • CVE-2026-49809MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-47848MedAug 26, 2026
    risk 0.40cvss 6.1epss 0.00

    In specific scenarios involving WebSocket handshake redirects to a different origin, the Reactor Netty WebSocket client may leak credentials. In order for this to happen, the HTTP client must have been explicitly configured to follow redirects. Reactor Netty 1.3.0 - 1.3.6…

  • CVE-2026-47844MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    In specific scenarios, the Reactor Netty HTTP Server may leak exception details across unrelated requests. In order for this to happen, the server must be configured with Brave Tracing. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

  • CVE-2026-47843LowAug 26, 2026
    risk 0.24cvss 3.7epss 0.00

    In specific scenarios involving multiple clients with different DNS resolver configurations, Reactor Netty may incorrectly reuse a previously configured DNS resolver. Reactor Netty 1.3.0 - 1.3.6 Reactor Netty 1.1.0 - 1.2.18 Reactor Netty 1.0.52 and earlier

  • CVE-2026-47842MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as the encryption mode encrypt data with AES/CBC using a null (all-zero) initialization vector. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6 Spring Security…

  • CVE-2026-47834MedAug 26, 2026
    risk 0.31cvss 4.8epss 0.00

    Spring Data JPA's Sort validation can be bypassed when parameters containing crafted payload are accepted from untrusted sources. Spring Data JPA 4.1.0 Spring Data JPA 4.0.0 - 4.0.6 Spring Data JPA 3.5.0 - 3.5.13 Spring Data JPA 3.0.0 - 3.4.15

  • CVE-2026-46371MedAug 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-privilege Observer role to extract sensitive…

  • CVE-2026-46370MedAug 26, 2026
    risk 0.35cvss 6.5epss 0.00

    Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege Observer role to extract host enrollment…

  • CVE-2026-46369HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.01

    Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative to Transaction::is_valid_at, allowing a…

  • CVE-2026-26449HigAug 26, 2026
    risk 0.49cvss 7.5epss 0.00

    In Stomper 5e2741e when a client sends a SEND frame missing the destination header field, the server triggers a null pointer dereference (or access to invalid memory) while processing the frame, causing the process to crash.

  • CVE-2026-26448CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection, and subsequently another client (or a later connection) sends SEND frames to a destination previously subscribed on that connection, the broker may…