VYPR

CVEs

383,869 total · page 377 of 7,678

  • CVE-2026-53561HigAug 25, 2026
    risk 0.41cvss 7.4epss 0.00

    An improper authentication vulnerability in HiveServer2 SAML bearer-token validation in Apache Hive 4.0.0 through 4.2.0 (and later unreleased branches) on deployments using HTTP transport with hive.server2.authentication=SAML allows an unauthenticated network attacker to…

  • CVE-2026-49845CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation…

  • CVE-2026-21758LowAug 25, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL Hive is affected by an information disclosure vulnerability, which could lead to an attacker gathering sensitive information about the host environment.

  • CVE-2026-21754MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthorized lateral movement, container breakout, and sensitive data exposure within internal communications.

  • CVE-2026-21753MedAug 25, 2026
    risk 0.27cvss 4.2epss 0.00

    HCL Hive is affected by weak software supply chain governance, which could lead to the inclusion of vulnerable, unmaintained, or malicious third-party dependencies within the application environment.

  • CVE-2026-12600HigAug 25, 2026
    risk 0.57cvss —epss 0.00

    Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork developed by Innodata Labs. When an application processes an untrusted PDF file containing specially crafted JPXDecode images, a remote attacker can cause…

  • CVE-2026-78576Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-78572Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-78570Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-76128MedAug 25, 2026
    risk 0.35cvss 6.4epss 0.00

    The eCommerce Product Catalog plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.5.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-75038MedAug 25, 2026
    risk 0.33cvss 6.1epss 0.00

    UNIX symbolic link (symlink) following vulnerability in ilya-zlobintsev/LACT allows for local denial-of-service. This issue affects LACT: through 0.10.0.

  • CVE-2026-75037HigAug 25, 2026
    risk 0.39cvss 7.0epss 0.00

    Polkit Authentication Based on UnixProcessSubject / Peer PID in LACT on Linux allows an Authentication Bypass. This issue affects LACT through 0.10.0. Fixed by commit d0478fe42c2219454e272f96b1cbd29ab37ee566.

  • CVE-2026-49050HigAug 25, 2026
    risk 0.50cvss 8.8epss 0.01

    General user can mint admin access tokens via /access-tokens This issue affects Apache DolphinScheduler: before 3.4.2. Users are recommended to upgrade to version 3.4.2, which fixes the issue.

  • CVE-2026-16231HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.00

    hbs is an Express view engine that wraps Handlebars. Its registerAsyncHelper API bypasses Handlebars' automatic HTML escaping: an async helper returns an opaque placeholder during the first render pass, so the double-brace expression escapes only the placeholder, and after…

  • CVE-2026-12878HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.

  • CVE-2026-78568Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-78566Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-78563Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-78562Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-77146HigAug 25, 2026
    risk 0.54cvss —epss 0.00

    The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-existent, disabled, or deleted users), allowing an unauthenticated attacker to set a new password for and re-enable an arbitrary existing frontend user account.…

  • CVE-2026-77145HigAug 25, 2026
    risk 0.46cvss —epss 0.00

    The permission check for the frontend management update flow verified a different event than the one the request went on to modify. A user with frontend event management access could therefore modify events belonging to other organizers.

  • CVE-2026-77144HigAug 25, 2026
    risk 0.46cvss —epss 0.00

    The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the request supplied no organizer of its own. The accompanying permission check confirmed only that the submitting user held any organizer role. A user with…

  • CVE-2026-77143HigAug 25, 2026
    risk 0.57cvss —epss 0.00

    The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modified. As a result, a visitor who knows the identifier of a topic from the public forum can submit a modified update request for that topic directly and…

  • CVE-2026-77142HigAug 25, 2026
    risk 0.57cvss —epss 0.00

    The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for company records a visitor does not own, but the corresponding write operation does not repeat this ownership check on the server side. As a result, a visitor…

  • CVE-2026-77141HigAug 25, 2026
    risk 0.57cvss —epss 0.00

    The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and activate actions, but performs no ownership check in any of them. An unauthenticated visitor who knows the UID of a club record can send a direct request to…

  • CVE-2026-77140HigAug 25, 2026
    risk 0.57cvss —epss 0.00

    The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in the action that persists the change. An unauthenticated visitor who knows the UID of a visible employee record can send a direct POST request to the update…

  • CVE-2026-77139MedAug 25, 2026
    risk 0.39cvss —epss 0.00

    The extension fails to validate a client-supplied template element key before using it to build file paths for saving and deleting Mask template files. An authenticated backend user with access to the Mask module can supply a key containing path traversal sequences to create or…

  • CVE-2026-77138CriAug 25, 2026
    risk 0.61cvss —epss 0.01

    The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserialize(). A remote, unauthenticated attacker can supply a crafted serialized payload to trigger PHP Object Injection, leading to Remote Code Execution on the…

  • CVE-2026-77137HigAug 25, 2026
    risk 0.50cvss —epss 0.00

    The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged backend user can inject arbitrary SQL through a URL parameter within the "Forms Export" backend module. Exploitation requires a low-privileged backend user and…

  • CVE-2026-77136CriAug 25, 2026
    risk 0.55cvss —epss 0.01

    The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that…

  • CVE-2026-77135HigAug 25, 2026
    risk 0.53cvss —epss 0.00

    The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target, allowing any visitor with access to the Detail or List plugin to retrieve another frontend user's profile data, including name, email, date of birth and…

  • CVE-2026-77134HigAug 25, 2026
    risk 0.54cvss —epss 0.00

    The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a regular user confirmation hash, obtainable by any visitor through the public resend-confirmation action, is sufficient to self-approve a pending account awaiting…

  • CVE-2026-77133MedAug 25, 2026
    risk 0.39cvss —epss 0.00

    The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the profile edit plugin uses its default field configuration, allowing self-service privilege escalation into arbitrary frontend groups.

  • CVE-2026-77131MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encrypting it. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

  • CVE-2026-77130MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control of a valid API key to authenticate with an expired token. Exploitation requires the attacker to already be in control of the SYSSY project's API key.

  • CVE-2026-77129HigAug 25, 2026
    risk 0.50cvss —epss 0.00

    The extension passes an editor-configurable email subject string directly into a Fluid template source without restriction. A backend user with edit access to the event plugin or Backend Module can supply Fluid ViewHelper syntax in this field to disclose sensitive data or…

  • CVE-2026-77128MedAug 25, 2026
    risk 0.41cvss —epss 0.01

    The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user can pass a demand-override parameter to view hidden or time-restricted events, unless the disableOverrideDemand plugin setting is active. Exploitation of this…

  • CVE-2026-77127MedAug 25, 2026
    risk 0.39cvss —epss 0.00

    The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to see or edit. An authenticated, low-privileged backend user can supply arbitrary table, field and record parameters, and trigger an error response that discloses…

  • CVE-2026-63587HigAug 25, 2026
    risk 0.56cvss 8.6epss 0.00

    The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization…

  • CVE-2026-63586CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.01

    The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string executed via the system() function. By…

  • CVE-2026-56096MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syntax such as wildcards, field selectors and range queries. A remote, unauthenticated attacker can use this syntax to enumerate indexed field names and extract…

  • CVE-2026-56095HigAug 25, 2026
    risk 0.43cvss —epss 0.00

    The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() function when transferring multi-value data for the SOLR_CLASSIFICATION, SOLR_MULTIVALUE and SOLR_RELATION content object types, rather than a safe format. If…

  • CVE-2026-56094MedAug 25, 2026
    risk 0.41cvss —epss 0.00

    The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the system's own siteHash filter is applied, and the query builder does not overwrite an already-registered named filter. In a shared Solr core serving multiple TYPO3…

  • CVE-2026-56093MedAug 25, 2026
    risk 0.34cvss —epss 0.00

    The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user access filter, unlike the regular search path. A visitor who can obtain or guess a valid Solr document id can retrieve documents through this lookup without…

  • CVE-2026-56092HigAug 25, 2026
    risk 0.49cvss —epss 0.00

    The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requests, and this forged state was persisted into the shared rootline cache, allowing anonymous visitors to bypass extendToSubpages-inherited access restrictions…

  • CVE-2026-17548MedAug 25, 2026
    risk 0.27cvss —epss 0.00

    Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who knows the ID of a background job to view that job's status and results.

  • CVE-2026-78701MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentication and Security Layer (SASL) UNBIND process. By sending a specially crafted request, the attacker can cause a connection to stall, leading to resource…

  • CVE-2026-78322MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a…

  • CVE-2026-67578HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.01

    FA-50 all versions miss authentication for some configuration. An attacker with access to the vessel's internal network can manipulate the product's settings screen to alter some configuration parameters.

  • CVE-2026-66882LowAug 25, 2026
    risk 0.07cvss —epss 0.01

    Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows reflected cross-site scripting via the confirmation and magic link interaction forms. When a strategy is configured with require_interaction? set to true,…