VYPR

CVEs

384,778 total · page 426 of 7,696

  • CVE-2026-76886HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76885LowAug 19, 2026
    risk 0.20cvss 3.1epss 0.00

    Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76884LowAug 19, 2026
    risk 0.20cvss 3.1epss 0.00

    ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76883MedAug 19, 2026
    risk 0.31cvss 4.7epss 0.00

    Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76882MedAug 19, 2026
    risk 0.31cvss 4.7epss 0.00

    Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76881MedAug 19, 2026
    risk 0.31cvss 4.7epss 0.00

    CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76880HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76879HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

  • CVE-2026-76761HigAug 19, 2026
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the component Management API. Such manipulation of the argument exec leads to os command injection. It is possible to launch the attack…

  • CVE-2026-76760HigAug 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go. The manipulation of the argument exec results in code injection. The attack may be performed from remote. The exploit has been…

  • CVE-2026-19563Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-19562Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-19561Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-18862Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-18502Aug 19, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-76878HigAug 19, 2026
    risk 0.55cvss —epss 0.01

    In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks for the presence of the all_projects key rather than its value; a true value enforces the administrator-only policy, but a false…

  • CVE-2026-76850CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py reads peer-to-peer cache-free requests with recv_pyobj(), which deserializes the received bytes with pickle.loads(), and the…

  • CVE-2026-76832HigAug 19, 2026
    risk 0.50cvss 8.8epss 0.01

    Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by supplying parent-directory traversal sequences in the file_name argument passed to read_file, save_to_file, or…

  • CVE-2026-76591HigAug 19, 2026
    risk 0.48cvss 7.4epss 0.02

    A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi of the component ssi. Performing a manipulation results in command injection. The attack is possible to be carried out remotely.…

  • CVE-2026-76590CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cgi of the component ssi. Such manipulation of the argument cameo.wan.wan_pppoe_password_00 leads to stack-based buffer overflow.…

  • CVE-2026-76589CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the argument ssid results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been made public and…

  • CVE-2026-76405MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because…

  • CVE-2026-76404CriAug 19, 2026
    risk 0.59cvss 9.1epss 0.01

    In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating system. The vulnerability is possible because of missing input validation in the app's credential management component, which…

  • CVE-2026-76403HigAug 19, 2026
    risk 0.48cvss 7.4epss 0.00

    In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk…

  • CVE-2026-76402HigAug 19, 2026
    risk 0.53cvss 8.2epss 0.00

    In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the…

  • CVE-2026-76401MedAug 19, 2026
    risk 0.38cvss 5.9epss 0.00

    In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker…

  • CVE-2026-76400MedAug 19, 2026
    risk 0.38cvss 5.9epss 0.00

    In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the…

  • CVE-2026-76399HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Search Processing Language (SPL) using the permissions of the search owner, which could allow access to all relevant data and affect…

  • CVE-2026-76398MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI…

  • CVE-2026-76397HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, including data associated with other users. The vulnerability is possible because Splunk AI Toolkit does not preserve the trusted…

  • CVE-2026-76396HigAug 19, 2026
    risk 0.49cvss 7.5epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and deserialize a model file through the apply search command. The improper access control is possible because Splunk AI Toolkit does…

  • CVE-2026-76395HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.01

    In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a model file containing crafted sparse matrix data. The deserialization of untrusted data is possible because a model codec in Splunk…

  • CVE-2026-76394HigAug 19, 2026
    risk 0.54cvss 8.3epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configure containers, and read or modify connection and configuration data through the Representational State Transfer (REST) API. The…

  • CVE-2026-76393MedAug 19, 2026
    risk 0.38cvss 5.9epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurrent upload request for the same model name, causing the resulting model lookup entry to reference attacker-controlled content. The…

  • CVE-2026-76392MedAug 19, 2026
    risk 0.35cvss 5.4epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentials for connected container services. The use of hard-coded credentials is possible because Splunk AI Toolkit generates or stores…

  • CVE-2026-76391HigAug 19, 2026
    risk 0.54cvss 8.3epss 0.00

    In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileges, access all relevant data, affect system integrity, and read or delete search jobs belonging to other users through Agent Run…

  • CVE-2026-76390MedAug 19, 2026
    risk 0.34cvss 5.3epss 0.00

    In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification through Splunk Web static file paths. The exposed specification could allow for reconnaissance of the add-on Representational…

  • CVE-2026-76389HigAug 19, 2026
    risk 0.57cvss 8.8epss 0.00

    In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability could send a crafted request to the Talos intelligence enrichment Representational State Transfer (REST) API endpoint and cause the…

  • CVE-2026-76388HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Behavior Analytics (UEBA) search macros that scheduled searches run with administrator permissions, allowing for access to all…

  • CVE-2026-76387HigAug 19, 2026
    risk 0.53cvss 8.1epss 0.00

    In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capability could inject Search Processing Language (SPL) through Analyst Queue search filters, allowing for access to all relevant data…

  • CVE-2026-76386MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 3.2.2 of the Zoom app for Splunk SOAR, a user who holds a role with permission to run actions could expose meeting and personal meeting ID passwords by invoking one of the create meeting, update meeting, or update user settings actions, because the affected…

  • CVE-2026-76385MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.1.4 of the Venafi app for Splunk SOAR, a user who holds a role with permission to run actions could expose keystore and private-key passwords by invoking the get certificate action, because the action's keystore_password and password parameters are not masked…

  • CVE-2026-76384MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.2.1 of the Splunk Attack Analyzer Connector for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking either the detonate file or detonate url action, because the action's archive_password…

  • CVE-2026-76383MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 1.0.5 of the RSA SecurID Authentication Manager app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive token serial by invoking either the enable token or revoke token action, because the action's token_serial…

  • CVE-2026-76382MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 3.8.5 of the Phantom app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive archive password by invoking the deflate item action, because the action's password parameter is not masked and is shown in cleartext in…

  • CVE-2026-76381MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 1.5.2 of the MS Graph for Active Directory app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is…

  • CVE-2026-76380MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password…

  • CVE-2026-76379MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in…

  • CVE-2026-76378MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked…

  • CVE-2026-76377MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext…