VYPR

CVEs

383,871 total · page 381 of 7,678

  • CVE-2026-75371HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    An integer handling flaw in the cobs_decode function of SpaceDot AcubeSAT OBC software commit eaf90ec allows physically-proximate attackers with UART access to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-75370MedAug 24, 2026
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC software commit eaf90ec allows attackers to cause a Denial of Service (DoS) via supplying a crafted CAN message.

  • CVE-2026-71832MedAug 24, 2026
    risk 0.40cvss 6.2epss 0.00

    Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service

  • CVE-2026-71509MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and approver identity…

  • CVE-2026-71508MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite…

  • CVE-2026-71507MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without…

  • CVE-2026-71506HigAug 24, 2026
    risk 0.46cvss 8.1epss 0.01

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check.…

  • CVE-2026-71505HigAug 24, 2026
    risk 0.39cvss 7.1epss 0.00

    Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object…

  • CVE-2026-71504HigAug 24, 2026
    risk 0.46cvss 8.1epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions.…

  • CVE-2026-71503MedAug 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted.…

  • CVE-2026-40877HigAug 24, 2026
    risk 0.50cvss 8.7epss 0.01

    Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.

  • CVE-2026-39975CriAug 24, 2026
    risk 0.54cvss —epss 0.01

    Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has…

  • CVE-2026-30864HigAug 24, 2026
    risk 0.51cvss 8.9epss 0.00

    Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.

  • CVE-2026-13081Aug 24, 2026
    risk 0.00cvss —epss —

    Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities.

  • CVE-2026-13047Aug 24, 2026
    risk 0.00cvss —epss —

    Rejected reason: Red Hat is not the CNA for PHP. CVE was reserved in error; the appropriate CNA should assign CVE IDs for these vulnerabilities.

  • CVE-2025-26238HigAug 24, 2026
    risk 0.53cvss 8.1epss 0.00

    In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.

  • CVE-2025-26237HigAug 24, 2026
    risk 0.53cvss 8.1epss 0.00

    D-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run arbitrary commands.

  • CVE-2026-9254HigAug 24, 2026
    risk 0.57cvss —epss 0.03

    An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary…

  • CVE-2026-78475MedAug 24, 2026
    risk 0.40cvss 6.1epss 0.00

    A flaw was found in the file-pix (ESM) plugin in GIMP. When processing a specially crafted PIX image file, the plugin allocates a Variable-Length Array (VLA) on the stack without proper bounds checking, causing an unbounded stack allocation followed by a 21-byte stack over-read.…

  • CVE-2026-76838HigAug 24, 2026
    risk 0.48cvss 8.5epss 0.00

    Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backend/app/Validators/Rules/NoInternalUrlRule.php resolves the hostname with gethostbyname() and rejects private and reserved ranges, which any public hostname…

  • CVE-2026-76837MedAug 24, 2026
    risk 0.35cvss 6.4epss 0.00

    Baserow interpolates a user's display name into the rich-text mention markup without HTML encoding. PATCH /api/user/account/ stores the first_name value verbatim, and the mention renderer in web-frontend/modules/core/editor/mention.js builds its element with a template literal…

  • CVE-2026-76836HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.00

    AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in…

  • CVE-2026-76835CriAug 24, 2026
    risk 0.59cvss 9.1epss 0.00

    OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header…

  • CVE-2026-76073HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.01

    Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by…

  • CVE-2026-76072HigAug 24, 2026
    risk 0.48cvss 7.4epss 0.00

    The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the default policy in extensions/cli/src/permissions/defaultPolicies.ts grants the Bash tool the allow permission, and…

  • CVE-2026-71982Aug 24, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-71943HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71942HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the mail_mailalert function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker…

  • CVE-2026-71941HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the diag_logmail function. The vulnerability is caused by concatenating multiple smtpReceiver email addresses into a fixed-size buffer without checking the remaining buffer size. A remote attacker can…

  • CVE-2026-71940HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Edit ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71939HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the acl_general_setup Add ACE function. The vulnerability is caused by copying the name field into a fixed-size buffer without length validation. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71938HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerability via crafted input, causing…

  • CVE-2026-71937HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the poe_schedule_profile function. The vulnerability is caused by repeated concatenation of the start_date, start_time, duration_time, how_often, weekdays, monthly_date, and cycle_duration fields into…

  • CVE-2026-71936HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the sysreboot function. The vulnerability is caused by unsafe concatenation of split valueN data into a fixed-size buffer. A remote attacker can trigger this vulnerability via crafted input, causing a…

  • CVE-2026-71935HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the webBackupAction function. The vulnerability is caused by repeated string concatenation of the pathN, valueN, key, and option fields into fixed-size stack buffers without total length checks. A…

  • CVE-2026-71934HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the pingtrace function. The vulnerability is caused by missing length checks when the host, count, and interval fields are concatenated into a fixed-size buffer. A remote attacker can trigger this…

  • CVE-2026-71933CriAug 24, 2026
    risk 0.59cvss 9.1epss 0.01

    Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart…

  • CVE-2026-71932MedAug 24, 2026
    risk 0.32cvss 4.9epss 0.01

    Multiple DrayTek VigorSwitch models contain a directory traversal vulnerability in the getSyslogFile function. The vulnerability is caused by insufficient validation of the option field. A remote attacker can trigger this vulnerability via crafted input containing path traversal…

  • CVE-2026-71931HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerability is caused by insufficient filtering before the filename field is concatenated into a command. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71930HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71929HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71928HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71927HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71926HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerability is caused by insufficient sanitization of the username, password, and location fields before command execution. A remote attacker can trigger this…

  • CVE-2026-71925HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71924HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71923HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71922HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.01

    Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted…

  • CVE-2026-71921CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.03

    Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attacker can trigger this vulnerability via…

  • CVE-2026-71920MedAug 24, 2026
    risk 0.32cvss 4.9epss 0.01

    Multiple DrayTek VigorSwitch models contain a null pointer dereference vulnerability in the formlogout function. The vulnerability is caused by missing checks for an empty or absent Cookie header before string handling. A remote attacker can trigger this vulnerability via a…