VYPR

CVEs

378,628 total · page 474 of 7,573

  • CVE-2026-53500HigJul 31, 2026
    risk 0.46cvss 8.2epss 0.00

    Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.

  • CVE-2026-25552LowJul 31, 2026
    risk 0.17cvss 3.7epss 0.00

    Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rate-limiting controls by manipulating the X-Forwarded-For header through a misconfigured Nginx configuration. Attackers can append attacker-controlled values to…

  • CVE-2026-18481HigJul 31, 2026
    risk 0.00cvss 7.3epss 0.00

    Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a …

  • CVE-2026-18321MedJul 31, 2026
    risk 0.31cvss 4.7epss 0.00

    Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

  • CVE-2026-55100HigJul 31, 2026
    risk 0.50cvss —epss 0.00

    hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier values including name, username, group, role, and version into Vault request paths and query strings instead of using…

  • CVE-2026-54737HigJul 31, 2026
    risk 0.40cvss 7.3epss 0.00

    @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to…

  • CVE-2026-54729HigJul 31, 2026
    risk 0.50cvss —epss 0.00

    DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost as safe when DNS resolver 1.1.1.1 returns NXDOMAIN because dns.resolve4 yields no address and no dns.lookup fallback occurs,…

  • CVE-2026-54725CriJul 31, 2026
    risk 0.55cvss 9.6epss 0.00

    vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call…

  • CVE-2026-34497MedJul 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

  • CVE-2026-34495MedJul 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.

  • CVE-2026-34490MedJul 31, 2026
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

  • CVE-2026-21662CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.

  • CVE-2026-67822CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack…

  • CVE-2026-58048CriJul 31, 2026
    risk 0.61cvss —epss 0.01

    Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

  • CVE-2026-58047MedJul 31, 2026
    risk 0.36cvss —epss 0.01

    HTTP Smuggling in cPanel allows potential leak of credentials.

  • CVE-2026-54707MedJul 31, 2026
    risk 0.28cvss 5.4epss 0.00

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop does not enforce the Receive mode disable_files setting in…

  • CVE-2026-54706MedJul 31, 2026
    risk 0.24cvss 4.8epss 0.00

    OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Prior to 2.6.4, OnionShare CLI/Desktop follows symbolic links in cli/onionshare_cli/web/send_base_mode.py through…

  • CVE-2026-52856HigJul 31, 2026
    risk 0.42cvss 7.5epss 0.00

    Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

  • CVE-2026-52855CriJul 31, 2026
    risk 0.57cvss 9.9epss 0.00

    Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg configuration-file templates allow a low-privileged user to read {{config.token}}, {{config.token_id}}, and…

  • CVE-2026-12075higJul 31, 2026
    risk 0.45cvss —epss —

    ### Summary `nltk.pathsec` provides an SSRF filter that NLTK documents as a security control, blocking loopback, private, link-local, and multicast ranges (including obfuscated forms) and recommending strict `ENFORCE` mode for security-sensitive environments. The filter is…

  • CVE-2026-12061higJul 31, 2026
    risk 0.45cvss —epss —

    ### Summary `ReviewsCorpusReader` extracts feature annotations of the form *label* followed by a bracketed signed digit (e.g. a label then `[+2]`) from each review line, using the module-level `FEATURES` regex. The feature-label sub-pattern is unbounded — an optional greedy…

  • CVE-2026-12072higJul 31, 2026
    risk 0.38cvss —epss —

    ### Summary A path-traversal vulnerability in `NKJPCorpusReader` allows an attacker who can influence the `fileids` argument of its public read methods (`header`, `raw`, `words`, `sents`, `tagged_words`) to read files outside the corpus root. The reader builds the…

  • CVE-2026-12074higJul 31, 2026
    risk 0.45cvss —epss —

    ### Summary `FramenetCorpusReader.frame(name)` interpolates a caller-supplied frame name into an XML file path that is read with the builtin `open()`, bypassing `CorpusReader.open()` and the `nltk.pathsec` sandbox — including strict `ENFORCE=True` mode. A `../` sequence in the…

  • CVE-2026-67607MedJul 31, 2026
    risk 0.38cvss 5.9epss 0.00

    LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftpserv.c that allows remote unauthenticated attackers to destabilize or crash the daemon by triggering unsynchronized access to…

  • CVE-2026-59232MedJul 31, 2026
    risk 0.27cvss —epss 0.00

    Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view…

  • CVE-2026-59231MedJul 31, 2026
    risk 0.27cvss —epss 0.00

    Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requests from the server to arbitrary attacker-chosen destinations via unvalidated URLs stored in the finding images field or the…

  • CVE-2026-56571LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.

  • CVE-2026-56570LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames…

  • CVE-2026-56569MedJul 31, 2026
    risk 0.26cvss 4.0epss 0.00

    HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

  • CVE-2026-56568LowJul 31, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters,…

  • CVE-2026-56567MedJul 31, 2026
    risk 0.33cvss 5.1epss 0.00

    HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.

  • CVE-2026-52857MedJul 31, 2026
    risk 0.29cvss 5.5epss 0.00

    Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml configuration-file parsers in parser.go can process an oversized non-file parser configuration file and exhaust Wings process…

  • CVE-2026-18141HigJul 31, 2026
    risk 0.53cvss 8.2epss 0.00

    A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL…

  • CVE-2026-17566CriJul 31, 2026
    risk 0.57cvss 9.9epss 0.01

    pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passing the rendered line to psql via --command. To stop an attacker from breaking out of the (...) wrapper, create_import_export_job()…

  • CVE-2026-17351CriJul 31, 2026
    risk 0.52cvss 9.0epss 0.00

    The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statement before running it inside a BEGIN TRANSACTION READ ONLY wrapper. sqlparse's…

  • CVE-2026-17350MedJul 31, 2026
    risk 0.28cvss 5.4epss 0.00

    The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consistently. In SERVER mode, pgAdmin 4 gates each tool behind a per-tool Flask-Security permission, but the permission decorator…

  • CVE-2026-17349CriJul 31, 2026
    risk 0.55cvss 9.6epss 0.00

    /misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones that server via Server.clone(), which copies every column from the source row, including user_id, shared, shared_username, and the…

  • CVE-2026-17348MedJul 31, 2026
    risk 0.35cvss 6.5epss 0.00

    In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles desktop-mode auto-login and the Kerberos/Webserver-auth redirect, so any route shipped without the decorator is reachable without…

  • CVE-2026-17347HigJul 31, 2026
    risk 0.42cvss 7.5epss 0.00

    The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption key, with %u in the configured string replaced by the current user's name. The previous implementation substituted the username…

  • CVE-2026-17346HigJul 31, 2026
    risk 0.50cvss 8.8epss 0.00

    The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but missed several sinks that had been placed in test_sql_string_literal_lint.py's ALLOWLIST on the incorrect assumption that schema,…

  • CVE-2026-16504CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HTTPS=True.

  • CVE-2026-16503CriJul 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default database password set to "postgres". Because Docker installs its own iptables rules, this exposure bypasses a standard host UFW…

  • CVE-2026-10686MedJul 31, 2026
    risk 0.31cvss 5.8epss 0.00

    Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet() (subsys/net/ip) were affected: the explicit-route path (net_route_packet()) and the on-link cross-interface path…

  • CVE-2025-62347MedJul 31, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the…

  • CVE-2026-67350MedJul 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with…

  • CVE-2026-51301Jul 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51299Jul 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51289Jul 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51288Jul 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51287Jul 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.