VYPR

CVEs

383,674 total · page 360 of 7,674

  • CVE-2026-57170HigAug 26, 2026
    risk 0.44cvss 7.8epss 0.00

    Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown…

  • CVE-2026-54467HigAug 26, 2026
    risk 0.46cvss 7.0epss 0.00

    On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

  • CVE-2026-52776HigAug 26, 2026
    risk 0.49cvss —epss 0.00

    Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach…

  • CVE-2026-29988HigAug 26, 2026
    risk 0.49cvss 7.6epss 0.00

    A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D…

  • CVE-2026-19632CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.09

    The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated…

  • CVE-2026-74749modAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: rseq: Prevent hard lockup on granted time slice extension

  • CVE-2026-80529modAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: don't swallow dquot recovery verification errors

  • CVE-2026-80532lowAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: fix another iunlink infinite loop bug in online fsck

  • CVE-2026-80533lowAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair

  • CVE-2026-80535lowAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: don't double-lock when deleting a self-referential directory

  • CVE-2026-80138CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary…

  • CVE-2026-79912HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.02

    A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.…

  • CVE-2026-79911CriAug 25, 2026
    risk 0.65cvss 10.0epss 0.01

    A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer…

  • CVE-2026-70665MedAug 25, 2026
    risk 0.20cvss 4.2epss 0.00

    Doorkeeper OpenID Connect implements an OpenID Connect authentication provider for Rails applications on top of Doorkeeper. Prior to 1.10.4, the Dynamic Client Registration (DCR) endpoint persists client-supplied scopes without validating them against the server's configured…

  • CVE-2026-55805MedAug 25, 2026
    risk 0.28cvss 5.4epss 0.00

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from…

  • CVE-2026-54757HigAug 25, 2026
    risk 0.44cvss 7.8epss 0.00

    Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs…

  • CVE-2026-44476MedAug 25, 2026
    risk 0.34cvss —epss 0.01

    Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically registered client's client_id, which is public information, can authenticate as that client at the token endpoint and obtain an access token without providing its…

  • CVE-2026-41707HigAug 25, 2026
    risk 0.48cvss 7.4epss 0.00

    Authentication Bypass by Capture-replay vulnerability in Spring Spring Security allows Spring Security's DPoPProofJwtDecoderFactory contains a cache-based replay attack vulnerability. The internal cache storing JWT ID claims has a strict size limit, allowing attackers to evict…

  • CVE-2026-18985HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Edit in-place field allows Forceful Browsing. This issue affects Edit in-place field versions: from 0.0.0 to 2.1.1.

  • CVE-2026-18261MedAug 25, 2026
    risk 0.37cvss 5.7epss 0.00

    Vulnerability in Drupal Powerful Surveys. This issue affects Powerful Surveys versions: *.*.

  • CVE-2026-18260MedAug 25, 2026
    risk 0.30cvss 5.7epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Disable Login Page allows Brute Force. This issue affects Disable Login Page versions: from 0.0.0 to 1.1.4.

  • CVE-2026-18259HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.00

    Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.

  • CVE-2026-16646MedAug 25, 2026
    risk 0.37cvss 5.7epss 0.00

    Vulnerability in Drupal PanKM. This issue affects PanKM versions: *.*.

  • CVE-2026-16645CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.

  • CVE-2026-16644CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

  • CVE-2026-16643MedAug 25, 2026
    risk 0.37cvss 5.7epss 0.00

    Vulnerability in Drupal Lunr exposed filters. This issue affects Lunr exposed filters versions: *.*.

  • CVE-2026-16642MedAug 25, 2026
    risk 0.37cvss 5.7epss 0.00

    Vulnerability in Drupal Email Login OTP. This issue affects Email Login OTP versions: *.*.

  • CVE-2026-16641CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

  • CVE-2026-16640MedAug 25, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.

  • CVE-2026-16639CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

  • CVE-2026-16638MedAug 25, 2026
    risk 0.33cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Media Folders allows Stored XSS. This issue affects Media Folders versions: from 0.0.0 to 1.0.8.

  • CVE-2026-15917MedAug 25, 2026
    risk 0.24cvss 4.7epss 0.00

    Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.2.*.

  • CVE-2026-15916MedAug 25, 2026
    risk 0.20cvss 4.2epss 0.00

    Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.

  • CVE-2026-15088MedAug 25, 2026
    risk 0.37cvss 5.7epss 0.00

    Vulnerability in Drupal Development Environment. This issue affects Development Environment versions: *.*.

  • CVE-2026-80186HigAug 25, 2026
    risk 0.49cvss 7.6epss 0.01

    A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth…

  • CVE-2026-80185MedAug 25, 2026
    risk 0.37cvss 5.7epss 0.00

    BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can crash bluetoothd (local DoS): a crafted nested ServiceRecord can corrupt the SDP XML parser stack so scalar union data is treated as a sequence pointer, allowing a local caller to crash bluetoothd.

  • CVE-2026-80184HigAug 25, 2026
    risk 0.42cvss —epss 0.01

    In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, application credentials, trusts) could be submitted to the token-method authentication path for reauthentication to escape their intended project scope. When an…

  • CVE-2026-80182HigAug 25, 2026
    risk 0.42cvss —epss 0.01

    In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped authentication could create new long-lived credentials or authorize new delegations that persist independently of, and outlive, the credential used to obtain…

  • CVE-2026-79845HigAug 25, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in code-projects Simple Inventory System 1.0. This vulnerability affects unknown code of the file /InventoryManagement/edit.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-79804HigAug 25, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SililaWijesinghe Food Ordering System up to ba314e897e3365600461e5ea59432e39ceaa0fa5. Affected by this issue is some unknown functionality of the file /search.php. Performing a manipulation of the argument search_box results in sql injection. Remote…

  • CVE-2026-78655CriAug 25, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps the failure count as tries inside the…

  • CVE-2026-78619CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.01

    Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted code's digest alone, across every user's…

  • CVE-2026-73180MedAug 25, 2026
    risk 0.44cvss 6.8epss 0.00

    Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as…

  • CVE-2026-68763HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The…

  • CVE-2026-68569HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from…

  • CVE-2026-68525CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1…

  • CVE-2026-66422HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole(). This issue affects Apache Tomcat: from 11.0.0-M1 through…

  • CVE-2026-65927HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.01

    Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through…

  • CVE-2026-65905CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is…

  • CVE-2026-65637CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version…