VYPR

CVEs

378,628 total · page 453 of 7,573

  • CVE-2026-71285HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted JavaScript expression inside a block rendered on every public status page. A siteId value such as , once saved by an…

  • CVE-2026-71284HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's filename (tar_file_names[0]) and builds a shell command via string formatting. Because os.system invokes a shell and no quoting…

  • CVE-2026-71283MedAug 5, 2026
    risk 0.32cvss 4.9epss 0.00

    Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile.extractall(temp_path) on an admin-uploaded tar archive with no filter argument and no per-member path validation. Requires the admin role…

  • CVE-2026-71282MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpolates the user-supplied tag KEY directly into a raw SQL fragment via Rust's format! macro , while only the tag VALUE is safely parameter-bound via Diesel's…

  • CVE-2026-71281HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py line ~101) call torch.load on config-specified cache/covariance files without weights_only=True, bypassing peft's own safe-loading…

  • CVE-2026-71280HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext or destination-IP validation (no IsLoopback, IsPrivate, IsUnspecified, or IsLinkLocalUnicast checks).

  • CVE-2026-71279HigAug 5, 2026
    risk 0.52cvss 8.0epss 0.00

    Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT message (topic zigbee2mqtt/bridge/request/extension/save) into the extensions base path using path.join(basePath, name) with no sanitization. The extension handler…

  • CVE-2026-71278CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication.

  • CVE-2026-71277CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization…

  • CVE-2026-71276HigAug 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and interpolates it directly into raw SQL queries via fmt.Sprintf in both the PostgreSQL reader (readers/postgres/messages.go: ) and…

  • CVE-2026-71275MedAug 5, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, "OTA requested for %s!", tmpA) with no HTML encoding, allowing a crafted URL such as…

  • CVE-2026-71274HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HTML sanitization. CHANNEL_GetLabel returns these labels unsanitized, and they are rendered via hprintf255 at 15+ locations in…

  • CVE-2026-71273MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the parameter is absent from the request, an else-branch silently clears the device's web admin password to an empty string.

  • CVE-2026-71272HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and validates the resulting IPs against reserved ranges, but then dials net.JoinHostPort(host, port) using the original hostname rather…

  • CVE-2026-71271HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 and never calls ip.IsUnspecified — unlike the correctly implemented sibling function isInternalIP in…

  • CVE-2026-71270HigAug 5, 2026
    risk 0.56cvss 8.6epss 0.00

    Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SSRF protections that were added to three sibling conversion endpoints (html/pdf, file/pdf, markdown/pdf).

  • CVE-2026-71269Aug 5, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-71268CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory. A path-validation function,…

  • CVE-2026-71267CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy.

  • CVE-2026-71266HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same…

  • CVE-2026-71265HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across three separate code branches…

  • CVE-2026-71264HigAug 5, 2026
    risk 0.53cvss 8.2epss 0.00

    WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated…

  • CVE-2026-71263CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit.

  • CVE-2026-71262CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its…

  • CVE-2026-71261HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk, a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to size_t before dividing by DRWAV_CUE_POINT_BYTES; on…

  • CVE-2026-71260MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON "state" field correctly masked as…

  • CVE-2026-71259HigAug 5, 2026
    risk 0.56cvss 8.6epss 0.00

    ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's…

  • CVE-2026-71227MedAug 5, 2026
    risk 0.26cvss 5.1epss 0.00

    A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This…

  • CVE-2026-71226HigAug 5, 2026
    risk 0.40cvss 7.3epss 0.00

    Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

  • CVE-2026-71225MedAug 5, 2026
    risk 0.35cvss 6.5epss 0.00

    A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A…

  • CVE-2026-16022HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command…

  • CVE-2026-0516MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

  • CVE-2026-71256CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_device_identification_res in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The…

  • CVE-2026-71255HigAug 5, 2026
    risk 0.56cvss 8.6epss 0.00

    nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the…

  • CVE-2026-71254CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's…

  • CVE-2026-64582HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: …

  • CVE-2026-61891HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to…

  • CVE-2026-46581HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the…

  • CVE-2026-18933HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no…

  • CVE-2026-71252HigAug 5, 2026
    risk 0.53cvss 8.2epss 0.00

    toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access…

  • CVE-2026-71251MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the requesting portal customer's own…

  • CVE-2026-71250MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that allows any resolved address in 127.0.0.0/8, permitting an authenticated user (with webhooks enabled, which is off by default) to…

  • CVE-2026-71249MedAug 5, 2026
    risk 0.40cvss 6.1epss 0.00

    299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var) echoes…

  • CVE-2026-71248CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload…

  • CVE-2026-71247MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2…

  • CVE-2026-71246MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https, without checking…

  • CVE-2026-71245Aug 5, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

  • CVE-2026-71244MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server,…

  • CVE-2026-71243HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = "mkdir -p " + path.join(info.destination, info.name) + "; " - and executes the resulting string through a shell via ssh2-exec…

  • CVE-2026-71242HigAug 5, 2026
    risk 0.54cvss 8.3epss 0.00

    Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of one company can…