VYPR

CVEs

383,871 total · page 382 of 7,678

  • CVE-2026-71919HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerability is caused by insufficient filtering of the config, act, pathN, and valueN fields before command execution. A remote attacker can trigger this vulnerability…

  • CVE-2026-71918HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulnerability is caused by insufficient filtering of the option, key, pw_encode, pathN, and valueN fields before command execution. A remote attacker can trigger…

  • CVE-2026-71917HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerability is caused by insufficient validation of the host field before command execution. A remote attacker can trigger this vulnerability via crafted input to…

  • CVE-2026-71916HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerability is caused by incomplete filtering of dangerous characters such as backticks, newline characters, and single quotes in the parameter field. A remote…

  • CVE-2026-71915HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerability is caused by insufficient filtering of the usescript, usefile, and option fields before command execution. A remote attacker can trigger this vulnerability…

  • CVE-2026-71914CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.03

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote attacker can trigger this vulnerability…

  • CVE-2026-71913HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vulnerability is caused by insufficient filtering before the restorekey field is concatenated into a shell command. A remote attacker can trigger this…

  • CVE-2026-71912HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the apautotest function. The vulnerability is caused by missing length checks during memory copy operations involving the CMD6 field. A remote attacker can trigger this vulnerability via crafted input,…

  • CVE-2026-71911HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.01

    Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this…

  • CVE-2026-71910HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71909HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute…

  • CVE-2026-71908HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vulnerability is caused by insufficient sanitization of the meshdevice_index and meshdevice_ip fields before command execution. A remote attacker can trigger this…

  • CVE-2026-71907HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability is caused by insufficient filtering of the selectSlaves field before command execution. A remote attacker can trigger this vulnerability via crafted input to…

  • CVE-2026-71906HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is caused by insufficient validation of the lanIp and lanNetmask fields before command execution. A remote attacker can trigger this vulnerability via crafted…

  • CVE-2026-71905HigAug 24, 2026
    risk 0.40cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this…

  • CVE-2026-71904HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can…

  • CVE-2026-34491MedAug 24, 2026
    risk 0.40cvss —epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.

  • CVE-2026-16348HigAug 24, 2026
    risk 0.55cvss —epss 0.02

    An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.  Successful exploitation may enable…

  • CVE-2026-13213MedAug 24, 2026
    risk 0.27cvss 5.3epss 0.00

    The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set unconditionally via BT_CONN_CB_DEFINE, so security_changed() runs for every connection that establishes security even before the application has called…

  • CVE-2026-78465HigAug 24, 2026
    risk 0.46cvss 7.0epss 0.00

    A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside…

  • CVE-2026-78329CriAug 24, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.11.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. UndertowEndpoint defaulted its headerFilterStrategy field to the base…

  • CVE-2026-77915CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers to self-register accounts with full Administrator privileges due to a duplicate bare Auth::routes() call in routes/web.php that re-enables the POST /register…

  • CVE-2026-77914MedAug 24, 2026
    risk 0.42cvss 6.5epss 0.01

    rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitrary files by supplying crafted filenames containing directory traversal sequences to the export download endpoint. Attackers can manipulate the filename…

  • CVE-2026-76831Aug 24, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-76830Aug 24, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-76829Aug 24, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-75099MedAug 24, 2026
    risk 0.34cvss 5.3epss 0.01

    Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through 1.19.1. Users are recommended to upgrade to version 1.20.0, which fixes the issue.

  • CVE-2026-71300CriAug 24, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-atmosphere-websocket producer selects which connected…

  • CVE-2026-66908HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.01

    Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authenticationEnabled…

  • CVE-2026-66907HigAug 24, 2026
    risk 0.42cvss 7.5epss 0.01

    Relative path traversal vulnerability in Apache Camel Google Storage component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-google-storage consumer downloads Google Cloud Storage objects to the…

  • CVE-2026-66906CriAug 24, 2026
    risk 0.52cvss 9.1epss 0.01

    Relative path traversal vulnerability in Apache Camel Azure Storage Blob component. This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-blob component can download an Azure Storage blob to…

  • CVE-2026-63621MedAug 24, 2026
    risk 0.27cvss 5.3epss 0.01

    Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache Camel Knative component The Knative consumer in camel-knative maps inbound CloudEvent attributes onto Camel message headers. In…

  • CVE-2026-60093MedAug 24, 2026
    risk 0.29cvss 5.5epss 0.00

    Relative path traversal vulnerability in Apache Camel Azure-Storage Datalake component This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-azure-storage-datalake component can download an Azure Data…

  • CVE-2026-59230MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.01

    Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0. The camel-mail component ships a MimeMultipart data format that can unmarshal a MIME multipart…

  • CVE-2026-19685HigAug 24, 2026
    risk 0.46cvss 7.1epss 0.00

    NetworkManager did not apply the private_user restriction to the 802-1x.ca-path and phase2-ca-path directory-valued connection properties. This incomplete fix for CVE-2025-9615 allows an unprivileged local user to point a private WPA-Enterprise (802.1X) connection profile's CA…

  • CVE-2026-18349HigAug 24, 2026
    risk 0.47cvss —epss 0.00

    Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injection. This issue affects SAMA5D4.

  • CVE-2026-15469HigAug 24, 2026
    risk 0.50cvss —epss 0.00

    The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.  A shared RSA-512 mesh group private key is present in the affected firmware and is used by the mesh protocol for node…

  • CVE-2025-36940HigAug 24, 2026
    risk 0.57cvss 8.8epss 0.00

    Use-After-Free vulnerability in a zircon kernel pager proxy (Fuchsia), which could lead to a Privilege Escalation from Userspace to Kernel (AP)

  • CVE-2025-36939MedAug 24, 2026
    risk 0.37cvss 5.7epss 0.00

    Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread network could send specially crafted packets to cause a denial of service. These issues include triggerable assertion failures and a stack-based buffer overflow.

  • CVE-2026-78416HigAug 24, 2026
    risk 0.50cvss —epss 0.01

    Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration…

  • CVE-2026-76071CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can…

  • CVE-2026-76070CriAug 24, 2026
    risk 0.64cvss 9.8epss 0.01

    Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can…

  • CVE-2026-71366HigAug 24, 2026
    risk 0.50cvss 7.7epss 0.01

    A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against…

  • CVE-2026-71364HigAug 24, 2026
    risk 0.47cvss 7.2epss 0.02

    A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without performing path normalization, boundary validation, or…

  • CVE-2026-67204MedAug 24, 2026
    risk 0.35cvss 5.4epss 0.00

    BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-update or image-delete permissions to manipulate other users' avatars by exploiting missing content-type restrictions in the Image Gallery API endpoints.…

  • CVE-2026-21752HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.00

    HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.

  • CVE-2026-13343MedAug 24, 2026
    risk 0.27cvss 5.3epss 0.00

    The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (uint32_t data[4]). The builders make_endpoint_info() and make_function_block_info() populate only the first two words (res.data[0] and res.data[1]) and, before…

  • CVE-2026-13212HigAug 24, 2026
    risk 0.50cvss 8.8epss 0.00

    The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used->ring[idx].id is used directly as an index into vq->recv_cbs[] and vq->desc[],…

  • CVE-2026-12556HigAug 24, 2026
    risk 0.50cvss —epss 0.00

    Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.

  • CVE-2026-12555HigAug 24, 2026
    risk 0.50cvss —epss 0.00

    Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. These potential vulnerabilities may lead to escalation of privilege. HP is releasing updates to mitigate these potential vulnerabilities.