VYPR

CVEs

384,413 total · page 422 of 7,689

  • CVE-2026-53548CriAug 19, 2026
    risk 0.55cvss 9.6epss 0.00

    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:id/password endpoint in src/backend/database/routes/host.ts accepts an authenticated user's numeric host ID and the field=password…

  • CVE-2026-53547HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/export endpoint creates a user export that includes the global settings table even though the rest of the export is user-scoped. The…

  • CVE-2026-53546CriAug 19, 2026
    risk 0.55cvss 9.6epss 0.00

    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket accepts a user-controlled hostConfig.id and src/backend/ssh/host-resolver.ts resolves that host without requiring ownership or…

  • CVE-2026-53545CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/disconnect/:tunnelName teardown path in src/backend/ssh/tunnel.ts interpolates endpointPort, sourcePort, endpointUsername, and…

  • CVE-2026-53542HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation endpoint in src/backend/ssh/file-manager.ts passes selected file basenames to tar without an end-of-options marker and without…

  • CVE-2026-4937MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.

  • CVE-2026-4936MedAug 19, 2026
    risk 0.33cvss 5.1epss 0.00

    IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service…

  • CVE-2026-18849MedAug 19, 2026
    risk 0.44cvss 6.8epss 0.00

    IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrator-level access to the BMC can, under specific conditions, execute arbitrary code, resulting in a confidentiality, integrity, and…

  • CVE-2026-18544HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of pod owner references.

  • CVE-2026-18102LowAug 19, 2026
    risk 0.23cvss 3.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to overwrite adjacent memory due to an integer underflow during bounds checking.

  • CVE-2026-17015MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.

  • CVE-2026-14978MedAug 19, 2026
    risk 0.36cvss 5.5epss 0.00

    HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in Terraform slug uploads due to improper handling of Unicode normalization during path matching.

  • CVE-2026-14514MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request due improper input validation.

  • CVE-2026-12634MedAug 19, 2026
    risk 0.27cvss 5.3epss 0.00

    The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into fixed 74-byte stack buffers and NUL-terminates them with buf[rc] = '\0', where rc is the return value of nvs_read(). Per its contract, nvs_read() returns…

  • CVE-2026-12633HigAug 19, 2026
    risk 0.46cvss 8.1epss 0.00

    The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6CO, RFC 6775) carried inside ICMPv6 Router Advertisements. In handle_ra_6co() the 8-bit context_len field is taken directly from the packet and was never bounded to the RFC…

  • CVE-2026-12522HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.00

    The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-context dynamic parameters (local address, subnet mask, gateway, and DNS servers) that the cellular network assigns to the device.…

  • CVE-2026-11617LowAug 19, 2026
    risk 0.20cvss 3.1epss 0.00

    Tanium addressed a compression bomb vulnerability in Findings.

  • CVE-2026-76647HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    Leantime JSON-RPC API through version 3.9.0 contains a missing authorization vulnerability in the JSON-RPC dispatcher in app/Domain/Api/Controllers/Jsonrpc.php. The dispatcher does not enforce authorization before invoking service-layer methods, allowing an authenticated user to…

  • CVE-2026-76574HigAug 19, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack…

  • CVE-2026-76572MedAug 19, 2026
    risk 0.24cvss 4.7epss 0.00

    A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading…

  • CVE-2026-75593HigAug 19, 2026
    risk 0.40cvss —epss 0.01

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory.…

  • CVE-2026-75112MedAug 19, 2026
    risk 0.45cvss —epss 0.00

    A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashing implementation, which could reduce the computational cost required for an attacker to perform offline brute-force attacks…

  • CVE-2026-74228Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-74227Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-74226Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-68901MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export, /api/boards/:boardId/export/csv, and /api/boards/:boardId/exportExcel handlers in models/export.js and models/exportExcel.js…

  • CVE-2026-68900HigAug 19, 2026
    risk 0.42cvss 7.6epss 0.00

    Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body through textContent, which decoded entity-encoded markup, and then interpolated titleText and allText into content.innerHTML in the…

  • CVE-2026-68899HigAug 19, 2026
    risk 0.50cvss 8.7epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based MIME detection, but detectMimeFromFile() silently returned undefined when that binary was unavailable and the validation fell back…

  • CVE-2026-68561HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpdateBoardSort in server/lib/utils.js, which authorized any board member whenever fieldNames included sort. Because Meteor combines…

  • CVE-2026-68560HigAug 19, 2026
    risk 0.43cvss —epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj.path into the administrator-configured externalCommandLine at its {file} placeholder and executed the result through asyncExec, which is promisify(exec) and…

  • CVE-2026-68559MedAug 19, 2026
    risk 0.35cvss 6.5epss 0.00

    Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the asynchronous exporterExcel.canExport(user) authorization guard from models/server/ExporterExcel.js without awaiting it. The…

  • CVE-2026-68558HigAug 19, 2026
    risk 0.48cvss 8.5epss 0.00

    Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked only the literal URL.hostname against regular expressions, so DNS names such as 169-254-169-254.nip.io passed that first-line…

  • CVE-2026-67189MedAug 19, 2026
    risk 0.40cvss 6.1epss 0.01

    pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML…

  • CVE-2026-63722CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by chaining an authentication bypass, CSRF validation bypass, and unsanitized command execution. Attackers can send a single HTTP…

  • CVE-2026-63188HigAug 19, 2026
    risk 0.50cvss —epss 0.01

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static asset requests through…

  • CVE-2026-63187MedAug 19, 2026
    risk 0.34cvss 6.3epss 0.00

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.40.1 until 1.41.0, Logto's .github/workflows/commitlint.yml directly interpolated github.event.pull_request.title into the Commitlint on PR title step's inline echo command before piping the title…

  • CVE-2026-62317HigAug 19, 2026
    risk 0.42cvss 7.5epss 0.01

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the attacker-controlled domain from email input to construct…

  • CVE-2026-61712LowAug 19, 2026
    risk 0.08cvss —epss 0.00

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving a username to a user identifier or…

  • CVE-2026-61711MedAug 19, 2026
    risk 0.27cvss —epss 0.00

    BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported…

  • CVE-2026-55090MedAug 19, 2026
    risk 0.27cvss —epss 0.01

    Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute escaping. A pad editor can place an…

  • CVE-2026-55089CriAug 19, 2026
    risk 0.57cvss 9.9epss 0.00

    Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in the authorization_code OAuth path by using requiredClaims with the admin claim. This check requires only that the claim exists,…

  • CVE-2026-55088MedAug 19, 2026
    risk 0.37cvss 6.8epss 0.00

    Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTransfer/{uuid}. Although the record includes…

  • CVE-2026-55087MedAug 19, 2026
    risk 0.33cvss 6.1epss 0.01

    Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admin without sanitization, Vary:…

  • CVE-2026-55086MedAug 19, 2026
    risk 0.20cvss 4.2epss 0.00

    Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared world-writable temporary directory, a local…

  • CVE-2026-55085CriAug 19, 2026
    risk 0.55cvss 9.6epss 0.00

    Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a numbered list directly into an unquoted ol start attribute before assigning the generated markup to node.innerHTML.…

  • CVE-2026-54742MedAug 19, 2026
    risk 0.26cvss —epss 0.01

    Lemmy is a link aggregator and forum for the fediverse. From 0.19.18 until 0.19.19 and 1.0.0-alpha.20, a community moderator can feature or unfeature posts in other communities through federated CollectionAdd and CollectionRemove activities using CollectionType::Featured. After…

  • CVE-2026-22306CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.00

    Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive information vulnerability in Ozols Grupa OZOLS on Windows caused by an abandoned auto-update domain. Affected component: the automatic…

  • CVE-2026-19509MedAug 19, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows an authenticated attacker to cause denial of service via a crafted `ssid_number` parameter.

  • CVE-2026-19508CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in the multipart form-data parser in `jst_post.c` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause memory corruption and denial of service, and potentially execute arbitrary code, via a crafted…

  • CVE-2026-19507HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    Uncontrolled resource consumption in `check.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26` allows a remote unauthenticated attacker to cause denial of service via excessively large password values.