VYPR

CVEs

376,728 total · page 47 of 7,535

  • CVE-2026-91771HigSep 15, 2026
    risk 0.50cvss 8.8epss 0.01

    Weights & Biases wandb before 0.29.0 fails to validate the file name from server responses in the File.download function, allowing path traversal attacks. Attackers controlling the backend can supply file names with directory traversal sequences to write files outside the…

  • CVE-2026-91770MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated employees to read any colleague's HR records. Attackers can substitute arbitrary employee IDs in skill, education, certification, language, leave, attendance,…

  • CVE-2026-90851MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includes/checklogin.php. This manipulation of the argument ID causes improper access controls. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2026-90850LowSep 15, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionality of the file /admin/manage-students.php. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public…

  • CVE-2026-90849HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester College Notes Gallery Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /College/login.php. The manipulation of the argument User leads to sql injection. The attack may be…

  • CVE-2026-90848MedSep 15, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely.…

  • CVE-2026-91752HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    GNU libextractor before 1.15 contains a stack-based buffer overflow vulnerability in the process_star_office function that sizes a variable-length stack array from attacker-controlled OLE2 stream data. Attackers can craft malicious StarOffice documents that allocate up to 4 MB…

  • CVE-2026-91751HigSep 15, 2026
    risk 0.54cvss 8.3epss 0.00

    Flextype CMS through 1.0.0-alpha.3 fails to properly validate id and new_id parameters in the Entries REST API, allowing API token holders to read, create, or overwrite files outside the entries directory. Attackers can use traversal sequences in API requests to escape the…

  • CVE-2026-91750MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url endpoint when downloading documents from user-supplied URLs. Authenticated attackers can bypass initial SSRF validation by supplying a public URL that redirects…

  • CVE-2026-90847CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.02

    A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_set.cgi of the component System Setup. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-90846HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in PHPGurukul Daily Expense Tracker System 1.1. Impacted is an unknown function of the file /dets/forgot-password.php. The manipulation of the argument email/contactno leads to sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-90845LowSep 15, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the file /dets/includes/sidebar.php. Executing a manipulation of the argument FullName can lead to cross site scripting. The attack can be executed remotely. The…

  • CVE-2026-90844HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in PHPGurukul Daily Expense Tracker System 1.1. This vulnerability affects unknown code of the file /dets/index.php of the component Login. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is…

  • CVE-2026-90843HigSep 15, 2026
    risk 0.47cvss 8.3epss 0.01

    A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. This affects the function nmap_newscan of the file functions_nmap.py of the component New Nmap Scan Handler. Such manipulation of the argument target/params leads…

  • CVE-2026-85657MedSep 15, 2026
    risk 0.35cvss 5.4epss 0.00

    The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘profile_fields_user_email_value_prefix’ parameter in all versions up to, and including, 4.15.0 due to…

  • CVE-2026-85575MedSep 15, 2026
    risk 0.35cvss 6.4epss 0.00

    The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shopengine_product_title_header_size’ parameter in all versions up to, and…

  • CVE-2026-90842LowSep 15, 2026
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument password/email/currentpassword/dbcurrentpwd/newpassword…

  • CVE-2026-90841HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Report Endpoint. The manipulation of the argument…

  • CVE-2026-90840HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipulation leads to improper authentication. The attack can be…

  • CVE-2026-91201MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by acting as window.opener during OAuth authorization, then…

  • CVE-2026-91200HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitrary files on the developer workstation, enabling code…

  • CVE-2026-91199MedSep 14, 2026
    risk 0.33cvss 5.0epss 0.00

    Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated attackers can make the backend issue requests to loopback,…

  • CVE-2026-91198MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared report or experiment identifier can read internal data…

  • CVE-2026-91197MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed…

  • CVE-2026-90835LowSep 14, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scripting. The attack may be initiated remotely. The exploit…

  • CVE-2026-90831MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now…

  • CVE-2026-90830MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit…

  • CVE-2026-90829MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched…

  • CVE-2026-81900MedSep 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them into iframe HTML attributes without escaping or integer casting, resulting in stored cross-site scripting. A user with edit_block permission could inject an event…

  • CVE-2026-77191LowSep 14, 2026
    risk 0.17cvss 2.6epss 0.00

    An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authentication phase and the full enforcement of its assigned ACL.

  • CVE-2026-75945LowSep 14, 2026
    risk 0.17cvss 2.6epss 0.00

    A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.

  • CVE-2026-75944LowSep 14, 2026
    risk 0.17cvss 2.6epss 0.00

    A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control enforcement. User interaction (an…

  • CVE-2026-75943LowSep 14, 2026
    risk 0.17cvss 2.6epss 0.00

    A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass without ACL enforcement.

  • CVE-2026-18116HigSep 14, 2026
    risk 0.47cvss epss 0.00

    Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in the workflow approval and deletion notifications shown in the dashboard "Waiting For Me" block. A registered user permitted to add events to a calendar…

  • CVE-2026-14986MedSep 14, 2026
    risk 0.37cvss 6.8epss 0.00

    The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside its target FIFO interrupt handler target_i2c_isr_fifo() in…

  • CVE-2026-91181MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only the read-only Data Retention Policy permission to obtain a…

  • CVE-2026-91146MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with malicious javascript: hrefs that execute in the instance origin…

  • CVE-2026-91145HigSep 14, 2026
    risk 0.46cvss 7.1epss 0.00

    Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and later evaluated in the full Spring context when a mail task…

  • CVE-2026-91144HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    ZFile through 5.0.5 fails to validate requested file paths against a share link's allowed entries on the download endpoint. Attackers holding a share link can supply arbitrary file paths as query parameters to download any file under the shared base directory, bypassing the…

  • CVE-2026-91143HigSep 14, 2026
    risk 0.47cvss 7.2epss 0.00

    goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing…

  • CVE-2026-90828MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated…

  • CVE-2026-90827LowSep 14, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was identified in GPAC 26.07.0. This affects the function gf_node_deactivate_ex of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack must be carried out locally. The exploit is publicly available…

  • CVE-2026-90826LowSep 14, 2026
    risk 0.11cvss 2.8epss 0.00

    A vulnerability was determined in GPAC 26.07.0. Affected by this issue is the function gf_node_del of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes out-of-bounds read. The attack is restricted to local execution. The exploit has been…

  • CVE-2026-90825LowSep 14, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit…

  • CVE-2026-76081MedSep 14, 2026
    risk 0.29cvss 5.5epss 0.00

    ZITADEL is an open source identity management platform. Prior to version 4.16.0, a bug in how ZITADEL updates permissions when multiple project roles are deleted at the same time can cause some user permissions to be missed. This issue specifically affects User Grants on Granted…

  • CVE-2026-73449MedSep 14, 2026
    risk 0.38cvss 5.9epss 0.00

    On affected platforms running Arista EOS with both 802.1X port authentication and the RADIUS proxy feature configured with dynamic authorization, a low-privileged attacker on an adjacent network segment who induces a RADIUS packet through a configured RADIUS proxy client can…

  • CVE-2026-18117HigSep 14, 2026
    risk 0.47cvss epss 0.00

    Concrete CMS 9.0.0 through 9.5.3 is vulnerable to stored XSS via the custom page alias name (customAliasName) because the Edit Alias dialog applied only trim() to the submitted value and performed no input neutralization. An authenticated user holding canWrite (editor)…

  • CVE-2026-13265MedSep 14, 2026
    risk 0.44cvss 6.8epss 0.00

    IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker with MFT publish authority to obtain…

  • CVE-2026-12944CriSep 14, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 can allow attackers to execute arbitrary Python code with root privileges (UID=0) on the Langflow server by submitting components containing socket or urllib imports. This enables: (1) AWS credential theft via IMDSv1 SSRF with full IAM role…

  • CVE-2026-12759MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption.