VYPR

CVEs

118,595 total · page 437 of 2,372

  • CVE-2026-30958HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.01

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.21, an unauthenticated path traversal in the /workflow/docs/:componentName endpoint allows reading arbitrary files from the server filesystem. The componentName route parameter is concatenated…

  • CVE-2026-30945HigMar 10, 2026
    risk 0.39cvss 7.1epss 0.00

    StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the DELETE /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user with editor privileges or above to revoke API tokens belonging to any other user,…

  • CVE-2026-30944HigMar 10, 2026
    risk 0.50cvss 8.8epss 0.01

    StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least Editor) to generate API tokens for any other user, including owner and admin accounts.…

  • CVE-2026-30941HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.14 and 9.5.2-alpha.1, NoSQL injection vulnerability allows an unauthenticated attacker to inject MongoDB query operators via the token field in the password reset…

  • CVE-2026-30939HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.13 and 9.5.1-alpha.2, an unauthenticated attacker can crash the Parse Server process by calling a Cloud Function endpoint with a prototype property name as the…

  • CVE-2026-30934HigMar 10, 2026
    risk 0.51cvss 8.9epss 0.00

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/ without context-aware escaping. The server…

  • CVE-2026-30933HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.01

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in…

  • CVE-2026-30928HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.02

    Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.1, the /api/4/config REST API endpoint returns the entire parsed Glances configuration file (glances.conf) via self.config.as_dict() with no filtering of sensitive values. The configuration file…

  • CVE-2026-2724HigMar 10, 2026
    risk 0.40cvss 7.2epss 0.00

    The Unlimited Elements for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form entry fields in all versions up to, and including, 2.0.5. This is due to insufficient input sanitization and output escaping on form submission data displayed in…

  • CVE-2026-2339HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication for Critical Function vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Remote Code Inclusion, Privilege Abuse, Command Injection. This issue affects Liderahenk: before 3.5.1.

  • CVE-2026-2273HigMar 10, 2026
    risk 0.53cvss 8.2epss 0.00

    CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity…

  • CVE-2026-26738HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in Uderzo Software SpaceSniffer v.2.0.5.18 allows a remote attacker to execute arbitrary code via a crafted .sns snapshot file.

  • CVE-2026-26148HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.00

    External initialization of trusted variables or data stores in Azure Entra ID allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-26144HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-26141HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26134HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Integer overflow or wraparound in Microsoft Office allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26132HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.02

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26131HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect default permissions in .NET allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26130HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.03

    Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network.

  • CVE-2026-26128HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.01

    Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26127HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.02

    Out-of-bounds read in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-26121HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-26118HigMar 10, 2026
    risk 0.50cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-26117HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

  • CVE-2026-26116HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-26115HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-26114HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.03

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-26113HigMar 10, 2026
    risk 0.55cvss 8.4epss 0.01

    Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-26112HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-26111HigMar 10, 2026
    risk 0.52cvss 8.0epss 0.01

    Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

  • CVE-2026-26110HigMar 10, 2026
    risk 0.55cvss 8.4epss 0.00

    Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.

  • CVE-2026-26109HigMar 10, 2026
    risk 0.55cvss 8.4epss 0.00

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-26108HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-26107HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.

  • CVE-2026-26106HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper input validation in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-26105HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-25836HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.02

    An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or…

  • CVE-2026-25573HigMar 10, 2026
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full…

  • CVE-2026-25570HigMar 10, 2026
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service.

  • CVE-2026-25569HigMar 10, 2026
    risk 0.48cvss 7.4epss 0.00

    A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code…

  • CVE-2026-25190HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.01

    Untrusted search path in Windows GDI allows an unauthorized attacker to execute code locally.

  • CVE-2026-25189HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25188HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Heap-based buffer overflow in Windows Telephony Service allows an unauthorized attacker to elevate privileges over an adjacent network.

  • CVE-2026-25187HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.03

    Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25181HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Out-of-bounds read in Windows GDI+ allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-25179HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper validation of specified type of input in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25178HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25177HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper restriction of names for files and other resources in Active Directory Domain Services allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-25176HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25175HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges locally.