VYPR

CVEs

118,593 total · page 438 of 2,372

  • CVE-2026-25172HigMar 10, 2026
    risk 0.52cvss 8.0epss 0.01

    Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

  • CVE-2026-25171HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25170HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Hyper-V allows an authorized attacker to elevate privileges locally.

  • CVE-2026-25167HigMar 10, 2026
    risk 0.48cvss 7.4epss 0.00

    Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-25166HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.02

    Deserialization of untrusted data in Windows System Image Manager allows an authorized attacker to execute code locally.

  • CVE-2026-25165HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Null pointer dereference in Windows Performance Counters allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24296HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24295HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Device Association Service allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24294HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.05

    Improper authentication in Windows SMB Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24293HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.01

    Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24292HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Use after free in Connected Devices Platform Service (Cdpsvc) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24291HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.03

    Incorrect permission assignment for critical resource in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24290HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Windows Projected File System allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24289HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.04

    Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24287HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    External control of file name or path in Windows Kernel allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24285HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24283HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.00

    Heap-based buffer overflow in Windows File Server allows an authorized attacker to elevate privileges locally.

  • CVE-2026-24018HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.

  • CVE-2026-24017HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.01

    An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote…

  • CVE-2026-23674HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper resolution of path equivalence in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-23673HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds read in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23672HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability

  • CVE-2026-23671HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23669HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Use after free in RPC Runtime allows an authorized attacker to execute code over a network.

  • CVE-2026-23668HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.04

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23667HigMar 10, 2026
    risk 0.46cvss 7.0epss 0.00

    Use after free in Broadcast DVR allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23665HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Azure Linux Virtual Machines allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23664HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Improper restriction of communication channel to intended endpoints in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23662HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23661HigMar 10, 2026
    risk 0.49cvss 7.5epss 0.01

    Cleartext transmission of sensitive information in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-23660HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper access control in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.

  • CVE-2026-23654HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Dependency on vulnerable third-party component in GitHub Repo: zero-shot-scfoundation allows an unauthorized attacker to execute code over a network.

  • CVE-2026-23239HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: espintcp: Fix race condition in espintcp_close() This issue was discovered during a code audit. After cancel_work_sync() is called from espintcp_close(), espintcp_tx_work() can still be scheduled from paths…

  • CVE-2026-22627HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.00

    A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a…

  • CVE-2026-22572HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.01

    An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2…

  • CVE-2026-21262HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.02

    Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-20967HigMar 10, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-1261HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.00

    The MetForm Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Quiz feature in all versions up to, and including, 3.9.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

  • CVE-2025-68648HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.01

    A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7,…

  • CVE-2025-66178HigMar 10, 2026
    risk 0.47cvss 7.2epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may…

  • CVE-2025-56421HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.00

    SQL Injection vulnerability in LimeSurvey before v.6.15.4+250710 allows a remote attacker to obtain sensitive information from the database.

  • CVE-2025-54820HigMar 10, 2026
    risk 0.53cvss 8.1epss 0.01

    A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests,…

  • CVE-2025-13957HigMar 10, 2026
    risk 0.49cvss epss 0.01

    CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause information disclosure and remote code execution when SOCKS Proxy is enabled, and administrator credentials and PostgreSQL database credentials are known. SOCKS Proxy is disabled by default.

  • CVE-2025-11739HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.

  • CVE-2026-3585HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.00

    The The Events Calendar plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 6.15.17 via the 'ajax_create_import' function. This makes it possible for authenticated attackers, with Author-level access and above, to read the contents of…

  • CVE-2026-30925HigMar 10, 2026
    risk 0.42cvss 7.5epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.5.0-alpha.14 and 8.6.11, a malicious client can subscribe to a LiveQuery with a crafted $regex pattern that causes catastrophic backtracking, blocking the Node.js…

  • CVE-2026-30920HigMar 10, 2026
    risk 0.56cvss 8.6epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.19, OneUptime's GitHub App callback trusts attacker-controlled state and installation_id values and updates Project.gitHubAppInstallationId with isRoot: true without validating that the caller is…

  • CVE-2026-30919HigMar 10, 2026
    risk 0.49cvss 7.6epss 0.00

    facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source and includes that data in its subsequent HTTP responses in…

  • CVE-2026-30918HigMar 10, 2026
    risk 0.49cvss 7.6epss 0.00

    facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to…

  • CVE-2026-30917HigMar 10, 2026
    risk 0.57cvss epss 0.00

    Bucket is a MediaWiki extension to store and retrieve structured data on articles. Prior to 2.1.1, a stored XSS can be inserted into any Bucket table field that has a PAGE type, which will execute whenever a user views that table's corresponding Bucket namespace page. This…