VYPR

CVEs

37,816 total · page 42 of 757

  • CVE-2026-74597CriAug 22, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip6_err() clones an outer IPv6 ICMP error skb, pulls it to the quoted inner IPv6 packet, and then passes the clone to icmpv6_send(). The clone still carries the…

  • CVE-2026-74591CriAug 22, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index before retrying In __filemap_add_folio()'s split-a-conflict loop, xas_set_order() is applied repeatedly: each application modifies xas.xa_index, rounding it down…

  • CVE-2026-74588CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list it is queued on __sctp_outq_flush_rtx() moves a gap-acked chunk onto another transport's transmitted list without updating chunk->transport: if…

  • CVE-2026-74587CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk addip_last_asconf caches the outstanding outbound ASCONF chunk. The normal ASCONF-ACK completion path releases the chunk and clears the pointer. However,…

  • CVE-2026-74586CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sctp_process_asconf_param() stores a newly added peer transport in asoc->new_transport. After all parameters in the ASCONF chunk have been processed,…

  • CVE-2026-4703CriAug 22, 2026
    risk 0.57cvss 9.8epss 0.01

    The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.10.80 via deserialization of untrusted input from form submission meta values. This makes it possible for unauthenticated…

  • CVE-2026-77992CriAug 22, 2026
    risk 0.62cvss —epss 0.00

    Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any access checks.

  • CVE-2026-76607CriAug 22, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.

  • CVE-2026-76606CriAug 22, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.

  • CVE-2026-76605CriAug 22, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

  • CVE-2026-76604CriAug 22, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable to the execution of user provided codes.

  • CVE-2026-76602CriAug 22, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries without validation, allowing read SQLi vectors.

  • CVE-2026-76571CriAug 22, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed to a list filter is concatenated verbatim into the WHERE clause built by getFilterQuery(). An unauthenticated attacker can supply…

  • CVE-2026-75870CriAug 22, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret. The session keyword freezes its options onto the application as given: it does not require a secret, warn, or refuse to start when one is…

  • CVE-2026-75866CriAug 22, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client…

  • CVE-2026-77946CriAug 22, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument…

  • CVE-2026-78003CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from…

  • CVE-2026-12710CriAug 22, 2026
    risk 0.60cvss —epss 0.00

    A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.

  • CVE-2026-77002CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

  • CVE-2026-77001CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any…

  • CVE-2026-77000CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by…

  • CVE-2026-49849CriAug 21, 2026
    risk 0.52cvss 9.1epss 0.01

    xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code…

  • CVE-2026-77415CriAug 21, 2026
    risk 0.54cvss —epss 0.01

    JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose…

  • CVE-2026-77414CriAug 21, 2026
    risk 0.53cvss —epss 0.01

    JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the…

  • CVE-2026-77413CriAug 21, 2026
    risk 0.54cvss —epss 0.01

    JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression…

  • CVE-2026-76904CriAug 21, 2026
    risk 0.57cvss 9.8epss 0.02

    GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains`…

  • CVE-2026-62283CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 through 2.0.9 do not bind stream identifiers created by CreateStream in service/rpc/io_stream.go to their creating user, and `GET…

  • CVE-2026-61539CriAug 21, 2026
    risk 0.58cvss 10.0epss 0.01

    Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py.…

  • CVE-2026-59989CriAug 21, 2026
    risk 0.53cvss —epss 0.01

    Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the join filter by inserting the raw separator and array token values into generated PHP without passing them through expression().…

  • CVE-2026-77810CriAug 21, 2026
    risk 0.64cvss 9.9epss 0.01

    In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.

  • CVE-2026-62674CriAug 21, 2026
    risk 0.52cvss 9.0epss 0.01

    Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT permission for a session but does not reject a bound shared or template agent whose agent.session_id is None. An…

  • CVE-2026-74581CriAug 21, 2026
    risk 0.57cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(), but leaves res->rt6 pointing at the released rt6_info. If no later rule supplies a…

  • CVE-2026-69502CriAug 21, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-77812CriAug 21, 2026
    risk 0.61cvss —epss 0.00

    DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts to connect to the drone over Wi-Fi, or when the drone is switched to QuickTransfer mode, the DJI Fly application exchanges DUML…

  • CVE-2026-77087CriAug 21, 2026
    risk 0.55cvss 9.6epss 0.00

    Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebinding. An attacker can craft a malicious webpage that, when visited by a developer running Paperclip locally, uses DNS rebinding to…

  • CVE-2026-63343CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to an arbitrary host path allows an authenticated Incus user to read or overwrite any file on the host as root via the instance…

  • CVE-2026-63125CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC identity with `can_create_images` and `can_create_instances`) can execute arbitrary code as root on the host. A crafted image ships…

  • CVE-2026-62941CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction check (`AllowInstanceCreation`) runs BEFORE the source instance's configuration is merged into the request. Dangerous configuration…

  • CVE-2026-62940CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.00

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied configuration overrides (including security-critical keys like `security.privileged` and `raw.lxc`) are applied without any…

  • CVE-2026-62867CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in storage volume configuration leads to argument injection in the constructed filesystem creation command line. This allows a…

  • CVE-2026-48769CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious image server returns a crafted `Incus-Image-Hash` header. This can lead to arbitrary command execution as root on the server.…

  • CVE-2026-48755CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm leads to argument injection in the constructed command line. This leads to an arbitrary file write on the host, possibly leading to…

  • CVE-2026-48753CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and allows creation of arbitrary files on the host. This behavior could lead to arbitrary command execution. Version 7.1.0 fixes the…

  • CVE-2026-48752CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 patches the issue.

  • CVE-2026-48751CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block` setting; allowing for arbitrary command execution on the Incus server by abusing lowlevel hooks such as `raw.lxc` and `raw.qemu`.…

  • CVE-2026-48750CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoint stores the output of the command in the `exec-output` directory of the instance. If `exec-output` is a symlink, file named…

  • CVE-2026-48749CriAug 21, 2026
    risk 0.57cvss 9.9epss 0.01

    Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitrary files on the host; possibly leading to arbitrary command execution. Version 7.2.0 fixes the issue.

  • CVE-2026-77806CriAug 21, 2026
    risk 0.57cvss 9.8epss 0.04

    SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.

  • CVE-2026-77776CriAug 21, 2026
    risk 0.52cvss 9.1epss 0.01

    Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client…

  • CVE-2026-77683CriAug 21, 2026
    risk 0.64cvss 9.9epss 0.03

    A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched…