VYPR

CVEs

384,326 total · page 410 of 7,687

  • CVE-2026-75910MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.01

    Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's…

  • CVE-2026-72861MedAug 20, 2026
    risk 0.38cvss 5.8epss 0.00

    The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await…

  • CVE-2026-63723Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-9033MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.00

    An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.  …

  • CVE-2026-8717Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-77148CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched…

  • CVE-2026-75526MedAug 20, 2026
    risk 0.22cvss 4.4epss 0.00

    django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values to ContentRenderer.render_exception when…

  • CVE-2026-75514MedAug 20, 2026
    risk 0.31cvss 5.9epss 0.01

    BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix…

  • CVE-2026-72854MedAug 20, 2026
    risk 0.34cvss 5.3epss 0.00

    msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubling loop guards its own multiplication…

  • CVE-2026-72852HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) * n * size * size and l.outputs…

  • CVE-2026-6822Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-6260Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-66788LowAug 20, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to…

  • CVE-2026-66787MedAug 20, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating…

  • CVE-2026-66785LowAug 20, 2026
    risk 0.16cvss 2.5epss 0.00

    A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided…

  • CVE-2026-66002MedAug 20, 2026
    risk 0.38cvss —epss 0.01

    Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest class in frappe/website/doctype/personal_data_download_request/personal_data_download_request.py return distinguishable response…

  • CVE-2026-66001HigAug 20, 2026
    risk 0.48cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py allow the OAuth2 consent flow to proceed without restricting approve to POST, without a csrf_token in…

  • CVE-2026-64777MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.00

    A malicious builder peer may be able to request an in-context file by name from the host and receive the contents of whatever the name resolves to, even when it resolves outside the build context. This vulnerability is addressed in container version 1.2.0.

  • CVE-2026-63654MedAug 20, 2026
    risk 0.38cvss —epss 0.00

    Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoint in frappe/model/workflow.py accepts safe HTTP methods for state-changing workflow approvals because the endpoint is not…

  • CVE-2026-63003MedAug 20, 2026
    risk 0.35cvss 6.5epss 0.00

    django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an object-level authorization check on the source page. In cms/admin/forms.py, DuplicatePageForm.source accepts any Page, the…

  • CVE-2026-62315HigAug 20, 2026
    risk 0.39cvss —epss 0.00

    Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary supplied through the fieldname parameter against forbidden standard and child-table fields before parsing the dictionary into…

  • CVE-2026-61663MedAug 20, 2026
    risk 0.21cvss 4.3epss 0.00

    django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, render_object_structure fails to authorize non-PageContent objects that use PlaceholderRelationField. An active staff user without cms.use_structure or…

  • CVE-2026-54624MedAug 20, 2026
    risk 0.35cvss 6.5epss 0.00

    django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure in cms/views.py renders cms/toolbar/structure.html for a PageContent object without calling user_can_view_page(). Any staff account…

  • CVE-2026-54622MedAug 20, 2026
    risk 0.35cvss 6.5epss 0.00

    django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint in cms/admin/placeholderadmin.py authorizes only the destination clipboard. The _copy_plugin_to_clipboard and…

  • CVE-2026-53993Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-53587HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 performs a fixed-size strncmp in set_data in…

  • CVE-2026-53586MedAug 20, 2026
    risk 0.35cvss 6.5epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, the built-in HTTP transport in src/libgit2/transports/http.c follows an offsite…

  • CVE-2026-53585MedAug 20, 2026
    risk 0.27cvss 5.3epss 0.01

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, git_delta_apply in src/libgit2/delta.c trusts the attacker-controlled res_sz value…

  • CVE-2026-53584MedAug 20, 2026
    risk 0.21cvss 4.3epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, libgit2 does not reject traversal components in a submodule path loaded from…

  • CVE-2026-53583MedAug 20, 2026
    risk 0.35cvss 6.5epss 0.00

    libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality into your application. Prior to 1.8.6 and 1.9.5, verify_server_cert in src/libgit2/streams/openssl.c uses an inverted !!memcmp…

  • CVE-2026-53569MedAug 20, 2026
    risk 0.27cvss —epss 0.00

    Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/desk/like.py and frappe/desk/doctype/note/note.py do not enforce read permission before modifying _liked_by metadata or a Note seen…

  • CVE-2026-50190HigAug 20, 2026
    risk 0.49cvss —epss 0.00

    Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkListController.php`. The `permalink` handler concatenates the raw `$bookmark->getTitle()` into the `pagetitle` template variable and…

  • CVE-2026-49996LowAug 20, 2026
    risk 0.17cvss 3.7epss 0.00

    SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin…

  • CVE-2026-46537Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-46536Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-46535Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-46534Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-46533Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-43678MedAug 20, 2026
    risk 0.27cvss 5.3epss 0.00

    An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a completed WebSocket handshake, dropping all active connections until the process restarts. This vulnerability is addressed in…

  • CVE-2026-19683HigAug 20, 2026
    risk 0.48cvss 7.4epss 0.00

    A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authentication credentials are transmitted over an unencrypted channel. An attacker who can observe or manipulate traffic between an…

  • CVE-2026-19586CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.06

    A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide…

  • CVE-2026-15743MedAug 20, 2026
    risk 0.37cvss 5.7epss 0.00

    Catalyst::Plugin::Static::Simple versions through 0.38 for Perl mark responses as publicly cacheable. The _serve_static method always sets the Cache-Control header to "public", with no means of overriding it. This advises proxies that the content may be stored in a shared…

  • CVE-2026-63202higAug 20, 2026
    risk 0.45cvss —epss —

    # BinaryHttpParser: Unauthenticated CPU-exhaustion DoS via infinite loop in field-section decoding - **ID:** BHTTP-LOOP-001 - **Severity:** High - **CVSS v3.1:** 7.5 — `CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H` - **CWE:** CWE-835 (Loop with Unreachable Exit Condition) —…

  • CVE-2026-61827higAug 20, 2026
    risk 0.45cvss —epss —

    We don't enforce any limits for the encoded variable lengths that are used for fields. As the remote peer controls these it's easy for the remote peer to have us buffer data forever and so ultimately OOM.

  • CVE-2026-63124higAug 20, 2026
    risk 0.45cvss —epss —

    ## Summary `io.netty.incubator:netty-incubator-codec-bhttp` can enter a non-terminating parse loop when a known-length Binary HTTP field section ends exactly after a complete field line. A remote peer that can send Binary HTTP input to a Netty pipeline using `BinaryHttpParser`…

  • CVE-2026-61799Aug 20, 2026
    risk 0.00cvss —epss —

    ## Summary `io.netty.incubator:netty-incubator-codec-bhttp` uses attacker-controlled Binary HTTP variable-length integers as `long` values but accumulates them into `int` offsets. Large valid varint lengths wrap the internal offset negative, leading to unchecked…

  • CVE-2026-61798higAug 20, 2026
    risk 0.45cvss —epss —

    ## Summary `io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl` exposes raw HPKE private key bytes in string representations and error messages. `BoringSSLAsymmetricCipherKeyPair.toString()` includes the private-key parameter object, and…

  • CVE-2026-54162Aug 20, 2026
    risk 0.00cvss —epss —

    ## Summary Ember's interactive TUI renders fields taken from the monitored Caddy server's access logs — most notably the request URI — straight to the operator's terminal without neutralising terminal escape or control sequences (CWE-150). Those log fields are populated…

  • CVE-2026-77036MedAug 20, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenConfigController. The manipulation results in improper authorization. The attack can be launched remotely. The exploit has been…

  • CVE-2026-77031HigAug 20, 2026
    risk 0.48cvss 7.4epss 0.03

    A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName. The manipulation of the argument fileNameMit leads to command injection. The attack can be initiated remotely. The exploit has…