VYPR

CVEs

37,811 total · page 38 of 757

  • CVE-2026-74746CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last nf_flow_table_iterate() only treats original-direction tuple nodes as owning entries. Publishing the original node first lets GC observe and free a flow…

  • CVE-2026-74744CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom from phy_dev ipvlan devices inherit hard_header_len from phy_dev during ipvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the…

  • CVE-2026-74743CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroom from lowerdev macvlan devices inherit hard_header_len from lowerdev during macvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the…

  • CVE-2026-74737CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG On the packet reception path, the ID of the MAC Port on which the packet was received, is embedded in the RX DMA Descriptor's metadata.…

  • CVE-2026-54523CriAug 26, 2026
    risk 0.55cvss 9.6epss 0.00

    Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to invoke generator.apply(namespace,…

  • CVE-2026-75896CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords. This issue affects Liderahenk: before 3.5.5.

  • CVE-2026-12717CriAug 26, 2026
    risk 0.61cvss —epss 0.00

    An Improper Input Validation vulnerability in CData JDBC driver integration in Google Cloud BigQuery Data Transfer Service versions prior to 2026-05-01 on Google Cloud Platform allows an authenticated attacker to achieve remote code execution in the connector container and…

  • CVE-2026-80203CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses isSuperAdmin() on the acting account rather than verifying whether the…

  • CVE-2026-77557CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device.

  • CVE-2026-77554CriAug 26, 2026
    risk 0.65cvss 10.0epss 0.02

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device.

  • CVE-2026-77553CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.00

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.

  • CVE-2026-77552CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.02

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Enterprise Audio/Video Bridge to execute a Command Injection on the device.

  • CVE-2026-77551CriAug 26, 2026
    risk 0.59cvss 9.0epss 0.00

    A malicious actor with access to the network and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Connect Display Cast Pro to escalate privileges on the device.

  • CVE-2026-77550CriAug 26, 2026
    risk 0.65cvss 10.0epss 0.01

    A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

  • CVE-2026-77549CriAug 26, 2026
    risk 0.59cvss 9.0epss 0.01

    A malicious actor with access to the network and under certain conditions could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances.

  • CVE-2026-77548CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.01

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

  • CVE-2026-77547CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.01

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

  • CVE-2026-77546CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.01

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

  • CVE-2026-77532CriAug 26, 2026
    risk 0.62cvss 9.6epss 0.00

    A malicious actor with access to an adjacent network could exploit a Buffer Overflow vulnerability found in a DHCPv6-enabled EdgeMAX EdgeSwitch to initiate a Remote Code Execution on such device.

  • CVE-2026-18080CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 1.17.8 via the save_attachments() function. This is due to missing file extension validation and missing…

  • CVE-2026-80349CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream proxies may be trusted and without limiting the number of forwarded hops, so the request address Koa reports…

  • CVE-2026-77545CriAug 26, 2026
    risk 0.59cvss 9.0epss 0.00

    A malicious actor with access to the network, low privileges and under certain conditions could exploit an Active Debug Code vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

  • CVE-2026-77543CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.01

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.

  • CVE-2026-77542CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.01

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.

  • CVE-2026-77541CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.

  • CVE-2026-77540CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.01

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.

  • CVE-2026-77539CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.01

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS Server to execute a Command Injection on the host device.

  • CVE-2026-77537CriAug 26, 2026
    risk 0.65cvss 10.0epss 0.02

    A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

  • CVE-2026-77536CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.00

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

  • CVE-2026-77535CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.01

    A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Command Injection on an adopted device.

  • CVE-2026-77534CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.00

    A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

  • CVE-2026-59683CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.01

    The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of CVE-2026-59682). This allows either a full system compromise from local or remote (if the daemon is running as root) or a full account takeover (if the daemon…

  • CVE-2026-59682CriAug 26, 2026
    risk 0.52cvss 9.1epss 0.01

    Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This issue affects OpenRGB through 1.0rc3.

  • CVE-2026-80235CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

  • CVE-2026-77533CriAug 26, 2026
    risk 0.64cvss 9.9epss 0.01

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device.

  • CVE-2026-18664CriAug 26, 2026
    risk 0.59cvss 9.1epss 0.00

    When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant to be denied access could be allowed. An…

  • CVE-2026-18431CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.01

    The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses…

  • CVE-2026-15203CriAug 26, 2026
    risk 0.60cvss —epss 0.00

    Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via…

  • CVE-2026-19632CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.09

    The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated…

  • CVE-2026-80138CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary…

  • CVE-2026-79911CriAug 25, 2026
    risk 0.65cvss 10.0epss 0.01

    A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer…

  • CVE-2026-16645CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Missing Authorization vulnerability in Drupal PhotoSwipe - Responsive JavaScript Modal Image Gallery allows Forceful Browsing. This issue affects PhotoSwipe - Responsive JavaScript Modal Image Gallery versions: from 0.0.0 to 3.2.0.

  • CVE-2026-16644CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Drupal Webform REST allows Forceful Browsing. This issue affects Webform REST versions: from 0.0.0 to 4.1.0.

  • CVE-2026-16641CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

  • CVE-2026-16639CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.00

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On allows Authentication Bypass. This issue affects Internationalization Single Sign-On versions: from 0.0.0 to 1.8.0.

  • CVE-2026-78655CriAug 25, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk::Plugin::TOTP versions before 0.05 for Perl allow the second-factor attempt limit to be reset by replaying an earlier session cookie because the challenge route counts failures in the session. The POST handler on challenge_path keeps the failure count as tries inside the…

  • CVE-2026-78619CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.01

    Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge because totp_use_recovery compares user identifiers numerically. The helper searches the recovery model for the submitted code's digest alone, across every user's…

  • CVE-2026-68525CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.00

    Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1…

  • CVE-2026-65905CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is…

  • CVE-2026-65637CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version…