VYPR

CVEs

384,359 total · page 413 of 7,688

  • CVE-2026-18289HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab OriginPro OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that…

  • CVE-2026-18288HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab OriginPro OPJU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in…

  • CVE-2026-18287HigAug 20, 2026
    risk 0.44cvss 7.8epss 0.00

    Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2026-18286HigAug 20, 2026
    risk 0.44cvss 7.8epss 0.00

    Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the…

  • CVE-2026-18285HigAug 20, 2026
    risk 0.44cvss 7.8epss 0.01

    Aeon load_rehab_pile_dataset Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Aeon. User interaction is required to exploit this vulnerability in that the…

  • CVE-2026-18284HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.01

    Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to execute…

  • CVE-2026-18283LowAug 20, 2026
    risk 0.16cvss 2.4epss 0.00

    Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific…

  • CVE-2026-18282HigAug 20, 2026
    risk 0.52cvss 8.0epss 0.00

    Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability…

  • CVE-2026-18281HigAug 20, 2026
    risk 0.52cvss 8.0epss 0.00

    Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to…

  • CVE-2026-18280LowAug 20, 2026
    risk 0.25cvss 3.9epss 0.00

    Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The…

  • CVE-2026-18279HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The…

  • CVE-2026-18278LowAug 20, 2026
    risk 0.23cvss 3.5epss 0.00

    Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to…

  • CVE-2026-18274HigAug 20, 2026
    risk 0.47cvss 7.2epss 0.01

    Heimdall Data Database Proxy uploadJar Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Heimdall Data Database Proxy. Authentication is required to exploit this…

  • CVE-2026-18273MedAug 20, 2026
    risk 0.43cvss 6.6epss 0.00

    Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to…

  • CVE-2026-18272MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.01

    Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The…

  • CVE-2026-18271MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.00

    Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this…

  • CVE-2026-18270HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute…

  • CVE-2026-18269MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.00

    Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this…

  • CVE-2026-18268HigAug 20, 2026
    risk 0.46cvss 7.0epss 0.01

    Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged…

  • CVE-2026-18267MedAug 20, 2026
    risk 0.44cvss 6.8epss 0.00

    Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. …

  • CVE-2026-18265CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw…

  • CVE-2026-18264HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of NoMachine. Authentication is required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2026-18263HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute…

  • CVE-2026-18262HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute…

  • CVE-2026-15686HigAug 20, 2026
    risk 0.47cvss 7.2epss 0.01

    Adminer multi_query Incorrect Check of Function Return Value Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adminer. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2026-15679HigAug 20, 2026
    risk 0.44cvss 7.8epss 0.00

    Hugging Face PyTorch Image Models checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face PyTorch Image Models. User interaction is required…

  • CVE-2026-13121HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute…

  • CVE-2026-77004HigAug 20, 2026
    risk 0.48cvss 7.4epss 0.02

    A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?method=SET&section=ptest_sn. Executing a manipulation of the argument sn can lead to command injection. The attack can be launched remotely. The exploit has been…

  • CVE-2026-76999MedAug 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be…

  • CVE-2026-76998HigAug 20, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/ajax.php?action=delete_category. Such manipulation of the argument ID leads to sql injection. It is possible to…

  • CVE-2026-76997MedAug 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=save_category. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack…

  • CVE-2026-75140HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.01

    jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies…

  • CVE-2026-63044MedAug 20, 2026
    risk 0.35cvss 5.4epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager server to make outbound HTTP requests or TCP connections to arbitrary internal hosts and ports. This issue affects Apache InLong:…

  • CVE-2026-63043HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it. [1] …

  • CVE-2026-63042HigAug 20, 2026
    risk 0.53cvss 8.1epss 0.01

    Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to…

  • CVE-2026-63040HigAug 20, 2026
    risk 0.53cvss 8.1epss 0.01

    Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised…

  • CVE-2026-63039CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into the SQL statement, enabling SQL injection. This issue affects Apache InLong: from 2.0.0 before 2.4.0. …

  • CVE-2026-63038CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject arbitrary SQL code through the dbName, tableName, schemaName, and username parameters.  This issue affects Apache InLong: from…

  • CVE-2026-63037CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL injection in the ORDER BY clause against the Manager backend database. This issue affects Apache InLong: from 2.0.0 before 2.4.0. …

  • CVE-2026-63016MedAug 20, 2026
    risk 0.34cvss 5.3epss 0.01

    Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or…

  • CVE-2026-63015MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.01

    Uncontrolled Resource Consumption vulnerability in Apache InLong. Non-template responsible persons can view template information. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve…

  • CVE-2026-19611HigAug 20, 2026
    risk 0.48cvss 7.4epss 0.01

    A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts…

  • CVE-2026-76996HigAug 20, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit…

  • CVE-2026-76995MedAug 20, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /admin/ajax.php?action=save_menu. The manipulation of the argument img leads to unrestricted upload. The attack is possible to be…

  • CVE-2026-76993MedAug 20, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executing a manipulation of the argument Traceback can lead to injection. The attack can be executed remotely. A high complexity level is…

  • CVE-2026-76991MedAug 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Performing a manipulation of the argument delid results in sql injection. Remote exploitation of the attack is possible. The exploit…

  • CVE-2026-73220HigAug 20, 2026
    risk 0.48cvss —epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide renderer in cvat-ui/src/audio/components/annotation-page/audio-workspace/top-bar/audio-right-group.tsx passes attacker-controlled…

  • CVE-2026-63490HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.01

    Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateLoader resolves attacker-influenced Spring MVC view names through Spring ResourceLoader without the path-containment validation…

  • CVE-2026-61898HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-controlled LANGUAGE entry in ~/.pam_environment as trusted input. The value is interpolated unescaped into a GNU sed replacement…

  • CVE-2026-61897HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It changes the effective UID/GID to the target user but leaves the real UID as 0 (root). A shell spawned by a helper script inherits…