VYPR

CVEs

37,816 total · page 46 of 757

  • CVE-2026-20357CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.01

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-20318CriAug 19, 2026
    risk 0.62cvss 9.6epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-20317CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.01

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-20315CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-20231CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-20030CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.01

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-62668CriAug 19, 2026
    risk 0.54cvss —epss 0.00

    Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.6, the Grav API plugin WebhookController.php accepts webhook URLs after only FILTER_VALIDATE_URL syntax validation, and WebhookDispatcher.php initializes cURL…

  • CVE-2026-75954CriAug 19, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated into SQL. 6.2.3 quotes keywords and allow-lists the sort clause.

  • CVE-2026-75949CriAug 19, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a client-controlled root (_path_type could point at the component site/admin trees), did not enforce path containment, and used a weak…

  • CVE-2026-71960CriAug 19, 2026
    risk 0.59cvss 9.1epss 0.01

    Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authentication plugin that allows unauthenticated attackers to forge valid JWT tokens by extracting the secret from the firmware image.…

  • CVE-2026-53451CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the unauthenticated save-waterfall-snapshot Socket.IO command passes attacker-controlled snapshotName input from…

  • CVE-2026-52889CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.01

    Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Value to Craft's Twig rendering layer during…

  • CVE-2026-47187CriAug 19, 2026
    risk 0.53cvss 9.3epss 0.01

    SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets or relative targets containing parent-directory components that SSHFS passes through FUSE for resolution by the client kernel…

  • CVE-2026-45272CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler in webserver/handlers/admin.py accepts SOCIAL_AUTH key names without validating quotes or newline characters, and…

  • CVE-2026-16816CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16656CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.

  • CVE-2026-15068CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-15065CriAug 19, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.

  • CVE-2026-76244CriAug 19, 2026
    risk 0.59cvss —epss 0.00

    stigmem-node contains an insecure default configuration vulnerability that allows federation traffic to traverse networks without mTLS protection when non-loopback endpoints are enabled. Operators who explicitly disabled mTLS while binding federation to non-loopback addresses…

  • CVE-2026-76243CriAug 19, 2026
    risk 0.60cvss —epss 0.01

    stigmem versions before 0.9.0a2 allow unauthenticated access when authentication is disabled on non-loopback deployments. Attackers can perform read, write, and federation operations with anonymous identity when nodes are exposed outside local development environments.

  • CVE-2026-76242CriAug 19, 2026
    risk 0.59cvss —epss 0.00

    stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval step. On nodes that accept federation peer registration over a network where initial registration can be intercepted or…

  • CVE-2026-74804CriAug 19, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is interpolated into the query as a.type = "..." and the type_filter array as a.type IN ("..."), with no quoting or escaping.

  • CVE-2026-74803CriAug 19, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-supplied Content-Type falls within the image MIME group.

  • CVE-2026-51366CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    SQL Injection vulnerability in Bottinelli Informatica Vedo Suite v.1.2.5 allows a remote attacker to execute arbitrary code via the api_vedo/chat endpoint and the utente_chat parameter

  • CVE-2026-16019CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.

  • CVE-2026-73391CriAug 19, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

  • CVE-2026-73390CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

  • CVE-2026-73389CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

  • CVE-2026-73388CriAug 19, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

  • CVE-2026-73364CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

  • CVE-2026-73347CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

  • CVE-2026-73185CriAug 19, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

  • CVE-2026-73183CriAug 19, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

  • CVE-2026-67364CriAug 19, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission handler is executed via eval(). The [URL parameter = X] shortcode is substituted with the raw, unescaped value of a query parameter, letting…

  • CVE-2026-66613CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

  • CVE-2026-19490CriKEVAug 19, 2026
    risk 0.76cvss 9.8epss 0.23

    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

  • CVE-2026-72889CriAug 19, 2026
    risk 0.57cvss 9.8epss 0.00

    Net::OAuth versions before 0.33 for Perl allow the sender to choose the signature algorithm in verify. verify resolves the signature method class from the signature_method parameter of the incoming message. signature_method is required on every request, so the algorithm used to…

  • CVE-2026-58082CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    The ISO-2022 encoding module used a stack buffer sized to MB_LEN_MAX (6 bytes) for intermediate character output. Some ISO-2022 variants can require up to 10 bytes per character, in which case conversions can trigger a stack buffer overflow of up to four bytes. An application…

  • CVE-2026-58081CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be…

  • CVE-2026-18937CriAug 19, 2026
    risk 0.59cvss 9.0epss 0.01

    The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalinks, allowing unauthenticated users to overwrite arbitrary PHP global variables, and to execute arbitrary code on the server when a…

  • CVE-2026-18776CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users to change the email address of arbitrary users, including administrators, and subsequently take over their account via the password…

  • CVE-2026-18051CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.01

    The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever…

  • CVE-2026-18031CriAug 19, 2026
    risk 0.64cvss 9.8epss 0.01

    The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated with the referenced order, allowing unauthenticated attackers to log in as any registered user, including an administrator.

  • CVE-2026-76008CriAug 19, 2026
    risk 0.65cvss 10.0epss 0.01

    A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI Parameter Parsing. This manipulation of the argument width/height causes stack-based buffer overflow. The attack can be initiated…

  • CVE-2026-76004CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/aspApBasicConfigUrcp of the component HTTP Handler. The manipulation of the argument pvid leads to stack-based…

  • CVE-2026-76003CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing a manipulation of the argument timestart can lead to stack-based buffer overflow. The attack may be performed from remote. The…

  • CVE-2026-11751CriAug 19, 2026
    risk 0.59cvss —epss 0.00

    A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allowing man-in-the-middle attacks against xDS-managed upstream connections.

  • CVE-2026-75976CriAug 19, 2026
    risk 0.64cvss 9.9epss 0.01

    A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM. This manipulation of the argument wan_l2tp_password causes stack-based buffer overflow. The attack can be initiated remotely. The…

  • CVE-2026-21580CriAug 18, 2026
    risk 0.60cvss —epss 0.01

    This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence…

  • CVE-2026-76036CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.01

    Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)