VYPR

CVEs

118,439 total · page 459 of 2,369

  • CVE-2026-27196HigFeb 21, 2026
    risk 0.46cvss 8.1epss 0.00

    Statmatic is a Laravel and Git powered content management system (CMS). Versions 5.73.8 and below in addition to 6.0.0-alpha.1 through 6.3.1 have a Stored XSS vulnerability in html fieldtypes which allows authenticated users with field management permissions to inject malicious…

  • CVE-2026-27192HigFeb 21, 2026
    risk 0.46cvss 8.1epss 0.00

    Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses startsWith() for comparison, allowing attackers to bypass the check by registering a domain that shares a common prefix…

  • CVE-2026-27203HigFeb 21, 2026
    risk 0.47cvss 8.3epss 0.00

    eBay API MCP Server is an open source local MCP server providing AI assistants with comprehensive access to eBay's Sell APIs. All versions are vulnerable to Environment Variable Injection through the updateEnvFile function. The ebay_set_user_tokens tool allows updating the .env…

  • CVE-2026-27202HigFeb 21, 2026
    risk 0.49cvss 7.5epss 0.01

    GetSimple CMS is a content management system. All versions of GetSimple CMS have a flaw in the Uploaded Files feature that allows for arbitrary file reads. This issue has not been fixed at the time of publication.

  • CVE-2026-27170HigFeb 21, 2026
    risk 0.46cvss 7.1epss 0.00

    OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. In versions 1.1.2-alpha and below, URL ingest allows overly permissive server-side fetch behavior and can be coerced into requesting unsafe targets. Potential access/probing…

  • CVE-2026-27169HigFeb 21, 2026
    risk 0.58cvss 8.9epss 0.00

    OpenSift is an AI study tool that sifts through large datasets using semantic search and generative AI. Versions 1.1.2-alpha and below render untrusted user/model content in chat tool UI surfaces using unsafe HTML interpolation patterns, leading to XSS. Stored content can…

  • CVE-2026-27168HigFeb 21, 2026
    risk 0.57cvss 8.8epss 0.00

    SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. All versions are vulnerable to Heap-based Buffer Overflow through the XWD parser's use of the bytes_per_line value. The value os read directly from the file as…

  • CVE-2026-27161HigFeb 21, 2026
    risk 0.49cvss 7.5epss 0.00

    GetSimple CMS is a content management system. All versions of GetSimple CMS rely on .htaccess files to restrict access to sensitive directories such as /data/ and /backups/. If Apache AllowOverride is disabled (common in hardened or shared hosting environments), these…

  • CVE-2026-27134HigFeb 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly…

  • CVE-2026-2635HigFeb 20, 2026
    risk 0.41cvss 7.3epss 0.01

    MLflow Use of Default Password Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…

  • CVE-2026-2492HigFeb 20, 2026
    risk 0.44cvss 7.8epss 0.00

    TensorFlow HDF5 Library Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of TensorFlow. An attacker must first obtain the ability to execute low-privileged code…

  • CVE-2026-2048HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.01

    GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-2047HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.01

    GIMP ICNS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-2045HigFeb 20, 2026
    risk 0.48cvss 7.3epss 0.05

    GIMP XWD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-2044HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    GIMP PGM File Parsing Uninitialized Memory Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-2043HigFeb 20, 2026
    risk 0.63cvss 8.8epss 0.73

    Nagios Host esensors_websensor_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The…

  • CVE-2026-2042HigFeb 20, 2026
    risk 0.58cvss 8.8epss 0.06

    Nagios Host monitoringwizard Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific flaw exists…

  • CVE-2026-2041HigFeb 20, 2026
    risk 0.63cvss 8.8epss 0.73

    Nagios Host zabbixagent_configwizard_func Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Nagios Host. Authentication is required to exploit this vulnerability. The specific…

  • CVE-2026-2040HigFeb 20, 2026
    risk 0.47cvss 7.3epss 0.00

    PDF-XChange Editor TrackerUpdate Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of PDF-XChange Editor. An attacker must first obtain the ability to execute…

  • CVE-2026-2037HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    GFI Archiver MArc.Core Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the…

  • CVE-2026-2036HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    GFI Archiver MArc.Store Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Although authentication is required to exploit this vulnerability, the…

  • CVE-2026-2034HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer Pro. User interaction is required to exploit this vulnerability in…

  • CVE-2026-2033HigFeb 20, 2026
    risk 0.41cvss 7.3epss 0.02

    MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of MLflow Tracking Server. Authentication is not required to exploit this…

  • CVE-2019-25451HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.00

    phpMoAdmin 1.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized database operations by crafting malicious requests. Attackers can trick authenticated users into submitting GET requests to moadmin.php with parameters like action,…

  • CVE-2019-25438HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    LabCollector 5.423 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the login parameter of login.php or the…

  • CVE-2019-25435HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the…

  • CVE-2019-25434HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotAuditor 5.3.1.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting excessive data in the registration name field. Attackers can enter a large string of characters (5000 bytes or more) in the name field…

  • CVE-2019-25432HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Part-DB 0.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to login by injecting SQL syntax into authentication parameters. Attackers can submit a single quote followed by 'or' in the login form to bypass credential validation and gain…

  • CVE-2019-25431HigFeb 20, 2026
    risk 0.53cvss 8.2epss 0.00

    delpino73 Blue-Smiley-Organizer 1.32 contains an SQL injection vulnerability in the datetime parameter that allows unauthenticated attackers to manipulate database queries. Attackers can inject SQL code through POST requests to extract sensitive data using boolean-based blind…

  • CVE-2018-25158HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.00

    Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions,…

  • CVE-2026-0797HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    GIMP ICO File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-0777HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Xmind Attachment Insufficient UI Warning Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Xmind. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-2857HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in D-Link DWR-M960 1.01.07. Affected by this issue is the function sub_423E00 of the file /boafrm/formPortFw of the component Port Forwarding Configuration Endpoint. This manipulation of the argument submit-url causes stack-based buffer overflow.…

  • CVE-2026-2856HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in D-Link DWR-M960 1.01.07. Affected by this vulnerability is the function sub_424AFC of the file /boafrm/formFilter of the component Filter Configuration Endpoint. The manipulation of the argument submit-url results in stack-based buffer overflow. The…

  • CVE-2026-27190HigFeb 20, 2026
    risk 0.46cvss 8.1epss 0.02

    Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability is fixed in 2.6.8.

  • CVE-2026-24892HigFeb 20, 2026
    risk 0.00cvss 7.5epss 0.01

    openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. openITCOCKPIT Community Edition 5.3.1 and earlier contains an unsafe PHP deserialization pattern in the processing of changelog entries. Serialized…

  • CVE-2026-2855HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in D-Link DWR-M960 1.01.07. Affected is the function sub_4648F0 of the file /boafrm/formDdns of the component DDNS Settings Handler. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack may be initiated…

  • CVE-2026-2854HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in D-Link DWR-M960 1.01.07. This impacts the function sub_4611CC of the file /boafrm/formNtp of the component NTP Configuration Endpoint. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. The attack can be launched…

  • CVE-2026-2853HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in D-Link DWR-M960 1.01.07. This affects the function sub_462E14 of the file /boafrm/formSysLog of the component System Log Configuration Endpoint. Performing a manipulation of the argument submit-url results in stack-based buffer overflow. The…

  • CVE-2026-2473HigFeb 20, 2026
    risk 0.50cvss epss 0.00

    Predictable bucket naming in Vertex AI Experiments in Google Cloud Vertex AI from version 1.21.0 up to (but not including) 1.133.0 on Google Cloud Platform allows an unauthenticated remote attacker to achieve cross-tenant remote code execution, model theft, and poisoning via…

  • CVE-2026-2472HigFeb 20, 2026
    risk 0.46cvss 8.1epss 0.01

    Stored Cross-Site Scripting (XSS) in the _genai/_evals_visualization component of Google Cloud Vertex AI SDK (google-cloud-aiplatform) versions from 1.98.0 up to (but not including) 1.131.0 allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's…

  • CVE-2026-27115HigFeb 20, 2026
    risk 0.00cvss 7.1epss 0.00

    ADB Explorer is a fluent UI for ADB on Windows. Versions 0.9.26020 and below have an unvalidated command-line argument that allows any user to trigger recursive deletion of arbitrary directories on the Windows filesystem. ADB Explorer accepts an optional path argument to set a…

  • CVE-2026-24891HigFeb 20, 2026
    risk 0.49cvss 7.5epss 0.00

    openITCOCKPIT is an open source monitoring tool built for different monitoring engines like Nagios, Naemon and Prometheus. Versions 5.3.1 and below contain an unsafe deserialization sink in the Gearman worker implementation. The worker function registered as oitc_gearman calls…

  • CVE-2026-2848HigFeb 20, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection.…

  • CVE-2026-2818HigFeb 20, 2026
    risk 0.53cvss 8.2epss 0.00

    A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.

  • CVE-2026-26746HigFeb 20, 2026
    risk 0.57cvss 8.8epss 0.01

    OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to…

  • CVE-2026-26724HigFeb 20, 2026
    risk 0.49cvss 7.6epss 0.00

    Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the selectgroup and gn parameters on the /?Function=Groups endpoint.

  • CVE-2026-26723HigFeb 20, 2026
    risk 0.53cvss 8.2epss 0.00

    Cross Site Scripting vulnerability in Key Systems Inc Global Facilities Management Software v. 20230721a allows a remote attacker to execute arbitrary code via the function parameter.

  • CVE-2026-26721HigFeb 20, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensitive information via the sid query parameter.

  • CVE-2026-26102HigFeb 20, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource in Owl opds 2.2.0.4 allows File Manipulation via a crafted network request.