VYPR

CVEs

376,725 total · page 45 of 7,535

  • CVE-2026-52826MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/{rate}, /en/admin/customer/{id}/rate/{rate}, and /en/admin/activity/{id}/rate/{rate} independently resolve the authorized parent identifier and the…

  • CVE-2026-52825MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/teams/{id}/activities/{activityId} verify that a teamlead may edit the Team but do not verify access_user for the referenced User or view access for the…

  • CVE-2026-52824CriSep 15, 2026
    risk 0.52cvss epss 0.02

    Kimai is an open-source time tracking application. Prior to 2.58.0, the official Docker image sets APP_SECRET to the public value change_this_to_something_unique in Dockerfile, and .docker/entrypoint.sh neither replaces nor rejects that value before Symfony uses it as…

  • CVE-2026-52823MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}/stop and GET /api/timesheets/{id}/restart, which reuse an authenticated browser session and perform state-changing operations through GET requests without a…

  • CVE-2026-52822MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/timesheets/{id}/duplicate, and the web duplicate workflow can derive a new record from an owned historical timesheet after the user's access to its project or…

  • CVE-2026-52821MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{project} and /en/admin/project/create/{customer} require only the generic create_activity or create_project capability and do not verify edit access to the…

  • CVE-2026-52820MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets accept a user-controlled project identifier through TimesheetApiEditForm and FormTrait, and ProjectRepository::getQueryBuilderForFormType() places that…

  • CVE-2026-52819MedSep 15, 2026
    risk 0.34cvss epss 0.00

    Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user and users[] target identifiers from a caller with view_other_timesheet but does not apply access_user or verify that a ROLE_TEAMLEAD requester leads a team…

  • CVE-2026-1759MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escalation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

  • CVE-2026-1758HigSep 15, 2026
    risk 0.54cvss 8.3epss 0.00

    Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue affects GateManager: 11.5;0, 11.4.625515072:0. Fixed in Version 11.6 or 11.4.626194074 and above

  • CVE-2026-91859MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because CakeErrorController extends AppController, exception rendering runs the application startup path a second time. As a result, __accessMonitor() calls…

  • CVE-2026-91857MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affected actions are:  - EventReportsController::purgeUnusedPictures()  - NoticelistsController::enableNoticelist() …

  • CVE-2026-62379CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PLL endpoint accepts a CustomCallback XML element whose className value selects an arbitrary Java class for AuthXMLUtils to load and instantiate without…

  • CVE-2026-62280MedSep 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoint's display=wap consent page reflects request-derived values through ConsentRequiredResource and wap/authorize.ftl without HTML escaping. An attacker can…

  • CVE-2026-62263CriSep 15, 2026
    risk 0.53cvss epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, WebAuthnAuthentication.deserialize applies an ObjectInputFilter that allows every serialized object at depth greater than 1 and therefore constrains only an AuthenticatorImpl root object. A…

  • CVE-2026-59341MedSep 15, 2026
    risk 0.27cvss 4.2epss 0.00

    A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to…

  • CVE-2026-53660HigSep 15, 2026
    risk 0.41cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the default configuration initializes the iPlanetDirectoryPro SSO cookie with HttpOnly disabled and without a protective SameSite default, and OAuth and OpenID Connect consent flows reuse that…

  • CVE-2026-48717CriSep 15, 2026
    risk 0.52cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, AuthorizationCodeGrantTypeHandler requires a code_verifier only when the realm-wide codeVerifierEnforced setting is enabled, even when an authorization code stores a code_challenge. Because that…

  • CVE-2026-47426HigSep 15, 2026
    risk 0.42cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the private_key_jwt client authentication path uses ClientJwksResolverCache without reliably binding a cached jwks_uri resolver and verified assertion to the expected clientID in…

  • CVE-2026-47424HigSep 15, 2026
    risk 0.42cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, GroovySandboxValueFilter permits an authenticated server-side script author to escape the scripting sandbox despite the default class allow and deny lists. A user such as a sub-realm RealmAdmin…

  • CVE-2026-46623HigSep 15, 2026
    risk 0.41cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local account with profile attributes that can include userPassword and inetUserStatus, rewriting the password to the username and reactivating…

  • CVE-2026-46619CriSep 15, 2026
    risk 0.53cvss epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, MSISDNValidation in the MSISDN authentication module concatenates the request-supplied MSISDN value into an LDAP search filter without escaping, while the default empty trusted-gateway list allows…

  • CVE-2026-46498HigSep 15, 2026
    risk 0.42cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, OAuthTokenStore reads caller-supplied token identifiers from the shared Core Token Store (CTS) without an OAuth-only namespace, and OAuthAdapter accepts a row whose BLOB claims to contain an OAuth…

  • CVE-2026-45794HigSep 15, 2026
    risk 0.43cvss epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the anonymous Push Notification SNS callback handled by SnsMessageResource falls back to a CTS predicate blob after a messageId expires from the in-memory dispatcher, treats top-level blob keys as…

  • CVE-2026-45052CriSep 15, 2026
    risk 0.53cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the Liberty Web Services SOAP receiver permits unauthenticated remote requests to write persistent entries through SOAPReceiver and DiscoveryService into a user's Liberty Discovery store and the…

  • CVE-2026-45051CriSep 15, 2026
    risk 0.53cvss epss 0.01

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, WebAuthnAuthentication loads a serialized AuthenticatorImpl object graph from the configured userAttribute through loadAuthenticators without an ObjectInputFilter. Exploitation requires the…

  • CVE-2026-45048HigSep 15, 2026
    risk 0.48cvss 8.5epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, SessionRequestHandler in the session management endpoint does not enforce ownership or privilege checks when a low-privileged authenticated user queries session information in deployments using…

  • CVE-2026-44793HigSep 15, 2026
    risk 0.38cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, certain federation endpoints in a non-default clustered configuration inconsistently encode user-supplied parameters rendered into HTML in the SAML2 cluster cookie-hash redirect path. An…

  • CVE-2026-44203HigSep 15, 2026
    risk 0.47cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth 2.0 and OpenID Connect authorization endpoint does not sufficiently encode user-supplied parameters before FormPostResponse.ftl and checkSession.ftl render them into HTML for the…

  • CVE-2026-44202MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListener operation allows an authenticated user to register an arbitrary notification URL without requiring an administrative or application client token.…

  • CVE-2026-41573HigSep 15, 2026
    risk 0.39cvss epss 0.00

    Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, IdentityResourceV1.queryCollection() passes the _queryId parameter from /json/{realm}/users to CrestQuery with escapeQueryId disabled, bypassing protection added for CVE-2021-29156. The unescaped…

  • CVE-2026-19515HigSep 15, 2026
    risk 0.45cvss 7.0epss 0.00

    The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing Micro Integrator projects opened from untrusted sources. This allows a crafted project to inject and execute arbitrary operating system commands through the unit…

  • CVE-2025-5802MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    The self-registration flow accepts user-supplied input for usernames without adequately preventing the disclosure of username existence. When a user attempts to register with an existing username, the system responds with an error message that explicitly indicates the username…

  • CVE-2025-13166LowSep 15, 2026
    risk 0.17cvss 3.7epss 0.00

    The SMS OTP flow fails to adequately handle error messages, allowing an attacker to infer the existence of registered user accounts based on the responses received during the OTP initiation process. This weakness can be exploited by an attacker to discover valid usernames…

  • CVE-2026-91851MedSep 15, 2026
    risk 0.27cvss epss 0.00

    Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. DashboardsController::listTemplates() allowed a template when either:  - its restrict_to_permission_flag matched one of the current user’s permission…

  • CVE-2026-91846HigSep 15, 2026
    risk 0.39cvss epss 0.00

    Affected versions of MISP allow a collection element to be created from a bare UUID without consistently checking whether the acting user is allowed to access the referenced object. The commit explains that collection elements themselves only store UUIDs, while the collection…

  • CVE-2026-91826MedSep 15, 2026
    risk 0.22cvss 4.4epss 0.00

    Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to memory corruption when rendering crafted vector animations. This issue affects rLottie: 480a2ad0c5d2e45458c545b8213279e9e8b71e39.

  • CVE-2026-91825HigSep 15, 2026
    risk 0.39cvss epss 0.00

    Affected versions of MISP fail to authorize a submitted sharing group in a specific event-edit path. The vulnerable logic checked whether the acting user could use a sharing_group_id only when the request explicitly supplied distribution = 4. If the attacker instead omitted…

  • CVE-2026-91782LowSep 15, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a…

  • CVE-2026-91781LowSep 15, 2026
    risk 0.21cvss 3.3epss 0.00

    A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed…

  • CVE-2026-91780LowSep 15, 2026
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to…

  • CVE-2026-91779LowSep 15, 2026
    risk 0.21cvss 3.3epss 0.00

    A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from…

  • CVE-2026-87730Sep 15, 2026
    risk 0.00cvss epss

    Rejected reason: this is rejected

  • CVE-2026-80217HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.00

    Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4, which may allow a user who can log in via SSH and access the enable mode on the product to execute arbitrary OS commands.

  • CVE-2026-77853HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 and FF-RFI078I4. A user who can log in to the product's M-Plane (NETCONF) may execute arbitrary OS commands.

  • CVE-2026-76159HigSep 15, 2026
    risk 0.46cvss epss 0.00

    Incorrect Permission Assignment for Critical Resource in the configuration loader of Duplicati for Windows versions before v2.4.0.0 allows a local low-privileged attacker to escalate privileges to NT AUTHORITY\SYSTEM via an attacker-controlled preload.json file.

  • CVE-2026-75092HigSep 15, 2026
    risk 0.40cvss 7.3epss 0.00

    A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the…

  • CVE-2026-91819MedSep 15, 2026
    risk 0.38cvss epss 0.00

    Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-security validation. CakePHP honors a _method field or X-HTTP-Method-Override header by rewriting the effective request method. For override values outside the…

  • CVE-2026-91778HigSep 15, 2026
    risk 0.47cvss epss 0.00

    In affected versions of Octopus Server, users with certain scoped permission sets could execute arbitrary scripts on a worker (including the Octopus Server built-in worker). Incorrect permission validation during script execution would allow the script to execute without the…

  • CVE-2026-91091MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of the file scenegraph/base_scenegraph.c of the component Node Insertion. Such manipulation leads to memory corruption. The attack can be launched remotely. The…