VYPR

CVEs

37,816 total · page 43 of 757

  • CVE-2026-77086CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location…

  • CVE-2026-62440CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are…

  • CVE-2026-61398CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to…

  • CVE-2026-59085CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to…

  • CVE-2026-77264CriAug 21, 2026
    risk 0.64cvss 9.8epss 0.01

    The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic…

  • CVE-2026-76158CriAug 21, 2026
    risk 0.60cvss —epss 0.01

    External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

  • CVE-2026-76156CriAug 21, 2026
    risk 0.61cvss —epss 0.01

    OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.

  • CVE-2026-76155CriAug 21, 2026
    risk 0.60cvss —epss 0.00

    Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.

  • CVE-2026-77651CriAug 21, 2026
    risk 0.64cvss 9.8epss 0.01

    The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

  • CVE-2026-77650CriAug 21, 2026
    risk 0.64cvss 9.8epss 0.01

    The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

  • CVE-2026-77649CriAug 21, 2026
    risk 0.64cvss 9.8epss 0.01

    The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.

  • CVE-2026-77647CriAug 20, 2026
    risk 0.67cvss 9.8epss 0.02

    SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.

  • CVE-2026-77645CriAug 20, 2026
    risk 0.60cvss —epss 0.01

    A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.

  • CVE-2026-77644CriAug 20, 2026
    risk 0.60cvss —epss 0.00

    A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

  • CVE-2026-72843CriAug 20, 2026
    risk 0.57cvss 9.8epss 0.01

    The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware…

  • CVE-2026-69851CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-69836CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.02

    Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

  • CVE-2026-69555CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-69400CriAug 20, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-68789CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-68782CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-66309CriAug 20, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-65816CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-65801CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-65770CriAug 20, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.

  • CVE-2026-63509CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62834CriAug 20, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-55769CriAug 20, 2026
    risk 0.54cvss —epss 0.01

    CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened superuser connections without pinning search_path in fillDefaultParameters in pkg/management/postgres/pool/profiles.go. A role…

  • CVE-2026-18835CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-17422CriAug 20, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow.

  • CVE-2026-17160CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computation.

  • CVE-2026-17157CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow.

  • CVE-2026-17152CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

  • CVE-2026-17145CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management.

  • CVE-2026-17142CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication.

  • CVE-2026-17141CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

  • CVE-2026-17136CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.

  • CVE-2026-17122CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

  • CVE-2026-17118CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability.

  • CVE-2026-17040CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

  • CVE-2026-71485CriAug 20, 2026
    risk 0.52cvss 9.1epss 0.01

    Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The…

  • CVE-2026-67567CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates…

  • CVE-2026-43798CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.00

    A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.

  • CVE-2026-77148CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched…

  • CVE-2026-19586CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.06

    A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide…

  • CVE-2026-73257CriAug 20, 2026
    risk 0.52cvss 9.1epss 0.01

    Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing both Content-Length and Transfer-Encoding: chunked. The cl_count and te_count checks in the mg_http_parse() and http_cb() paths in…

  • CVE-2026-73256CriAug 20, 2026
    risk 0.52cvss 9.1epss 0.00

    Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deployment by sending a request with Transfer-Encoding: chunked and conflicting framing. The http_cb() function in src/http.c tests…

  • CVE-2026-73253CriAug 20, 2026
    risk 0.52cvss 9.1epss 0.00

    Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent domain can impersonate deeper subdomains to a client using the built-in TLS stack. The mg_tls_verify_cert_san() and…

  • CVE-2026-73251CriAug 20, 2026
    risk 0.52cvss 9.1epss 0.00

    Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configured with a multi-certificate CA bundle. In src/tls_builtin.c, the mg_tls_init() function stores the bundle in tls->ca_bundle_der…

  • CVE-2026-63385CriAug 20, 2026
    risk 0.53cvss —epss 0.01

    Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_internal decodes percent-encoded %00 bytes into literal NUL characters, which can cause downstream C string operations to truncate a…