VYPR

CVEs

37,811 total · page 36 of 757

  • CVE-2026-71187CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.01

    The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.

  • CVE-2026-69658CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.00

    MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level attackers. This may enable unauthorized device impersonation and disruption of messaging functions.

  • CVE-2026-68929CriAug 28, 2026
    risk 0.53cvss —epss 0.00

    FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints authorize requests using only the public shareId, with no authenticated identity or team-ownership check. As a result,…

  • CVE-2026-50152CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.00

    Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Monitor subscription handler fails to properly authorize access to the configuration-key store, allowing any CephX user with only  `mon…

  • CVE-2026-81934CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.00

    Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-data list if Redis is configured with TLS support. A remote, unauthenticated attacker may be able to execute arbitrary commands with the privileges of the Redis…

  • CVE-2026-74820CriAug 27, 2026
    risk 0.65cvss —epss 0.00

    ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and…

  • CVE-2026-6876CriAug 27, 2026
    risk 0.65cvss —epss 0.01

    ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the ServiceNow AI Platform, potentially leading to more access to the ServiceNow…

  • CVE-2026-59313CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework…

  • CVE-2026-59283CriAug 27, 2026
    risk 0.59cvss 9.1epss 0.01

    Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 -…

  • CVE-2026-54687CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.01

    n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1.node.ts exposes the db_path database file path as a node parameter that permits data expressions from upstream workflow input. A workflow author who maps…

  • CVE-2026-53579CriAug 27, 2026
    risk 0.53cvss —epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the book note type, whose content is stored without sanitization and later rendered as…

  • CVE-2026-53578CriAug 27, 2026
    risk 0.53cvss —epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter sanitizes HTML only for text notes and excludes the mindMap note type, whose JSON content is stored without sanitization, allowing an…

  • CVE-2026-48996CriAug 27, 2026
    risk 0.53cvss —epss 0.00

    Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on "Safe import" filter does not sanitize note titles, and the GeoMap note view interpolates a marker note's title into raw HTML that is rendered as innerHTML,…

  • CVE-2026-37006CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model Context Protocol configurations.

  • CVE-2026-37004CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.01

    BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote attackers to execute arbitrary OS commands via a crafted dotprompt_content parameter in the /prompts/test endpoint due to use of an unsandboxed jinja2.Environment.

  • CVE-2026-37003CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.01

    Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized, LLM-generated arguments directly to execution sinks including exec(), runpy.run_path(), and subprocess.run(). An…

  • CVE-2026-35869CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC450M V4.0.0. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command…

  • CVE-2026-35868CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link Router AC2100_AZ3 V1.0.4. This flaw occurs due to insufficient validation and sanitization of user-supplied input before it is passed to a system-level command…

  • CVE-2026-19092CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.02

    The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.

  • CVE-2026-18886CriAug 27, 2026
    risk 0.65cvss —epss 0.05

    ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in…

  • CVE-2026-18885CriAug 27, 2026
    risk 0.65cvss —epss 0.07

    ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify,…

  • CVE-2026-81826CriAug 27, 2026
    risk 0.52cvss —epss 0.00

    Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This means that if an attacker already possesses a valid session—for example, from prior access or a stolen session token—the victim changing their password…

  • CVE-2026-81735CriAug 27, 2026
    risk 0.58cvss 10.0epss 0.01

    startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was…

  • CVE-2026-81707CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.01

    openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal…

  • CVE-2026-81702CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.00

    openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed…

  • CVE-2026-81701CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.00

    openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification. Attackers can place malicious unsigned plugins following documented…

  • CVE-2026-81700CriAug 27, 2026
    risk 0.57cvss 9.8epss 0.00

    openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG, EXPKEYSIG, or gpg exit codes. Attackers holding…

  • CVE-2026-81098CriAug 27, 2026
    risk 0.52cvss 9.1epss 0.01

    The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not…

  • CVE-2026-81096CriAug 27, 2026
    risk 0.58cvss 10.0epss 0.01

    ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected the submitted source for a denied list of attribute names and…

  • CVE-2026-81094CriAug 27, 2026
    risk 0.52cvss 9.1epss 0.01

    The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the all-interfaces address on a fixed port, and required a token only when…

  • CVE-2026-78251CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticated users to upload files without limits on file size, file count, or total storage consumed in **/blackbox/upgrade/**, as well as overwrite existing files in…

  • CVE-2026-75357CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili-bridge.js components.

  • CVE-2026-57499CriAug 27, 2026
    risk 0.59cvss 9.1epss 0.01

    Liman is open source server management software. Prior to 2.2.2 - 1103, an OS command injection vulnerability in the log rotation configuration endpoint allows an authenticated administrator to execute arbitrary operating system commands on the Liman server. The `ip_address`…

  • CVE-2026-26897CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in EcoOnline EHS (com.airsweb.v10) application for Android, version 0.2.499 allows a remote attacker to obtain sensitive information and execute arbitrary code via the AndroidManifest.xml component

  • CVE-2026-16279CriAug 27, 2026
    risk 0.60cvss 9.3epss 0.00

    An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.

  • CVE-2026-81675CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    The endpoint ‘/ws/apiprensa/getVideoUltimasSeccion’ contains an SQL injection vulnerability in the id_seccion parameter. The parameter is directly embedded in a complex SQL query that includes grouping and sorting operations. By injecting SQL syntax, an attacker can disrupt…

  • CVE-2026-81674CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results…

  • CVE-2026-81673CriAug 27, 2026
    risk 0.60cvss —epss 0.01

    The ‘/ws/apitribuna/setVisita’ endpoint is vulnerable to SQL injection through the id_video and id_ambito parameters. The application does not validate or sanitize these inputs before including them in SQL queries. This allows a remote attacker to inject SQL syntax and…

  • CVE-2026-81672CriAug 27, 2026
    risk 0.60cvss —epss 0.00

    SQL injection vulnerability in the ‘/ws/apiprensa/getVideoSubcanal’ endpoint due to improper handling of the id_video parameter. The application does not sanitize input before constructing SQL queries, which results in execution errors when malicious input is provided. The…

  • CVE-2026-74233CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.03

    Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and MT7620N firmware 19.1101, and WRC1…

  • CVE-2026-74232CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014,…

  • CVE-2026-78292CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

  • CVE-2026-78288CriAug 27, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Beautiful Taxonomy Filters <= 2.4.6 versions.

  • CVE-2026-78286CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

  • CVE-2026-78274CriAug 27, 2026
    risk 0.59cvss 9.1epss 0.01

    Editor Arbitrary File Upload in Fluent Boards Pro <= 2.0.11 versions.

  • CVE-2026-78260CriAug 27, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.

  • CVE-2026-59354CriAug 27, 2026
    risk 0.55cvss 9.6epss 0.00

    In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the registration endpoint performs insufficient validation of certain client metadata fields supplied by the registering client. An…

  • CVE-2026-32566CriAug 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

  • CVE-2026-32479CriAug 27, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Visitor Traffic Real Time Statistics Pro <= 11.17 versions.

  • CVE-2026-77991CriAug 27, 2026
    risk 0.61cvss —epss 0.01

    Joomla Extension - joomlaeventmanager.net - Privileged remote code execution in Joomla Event Manager < 5.0.1 - The administrator source model allows to write dangerous file type incl. PHP, leading to remote code execution.