VYPR

CVEs

378,628 total · page 480 of 7,573

  • CVE-2026-62663HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, document) in banks accept untrusted user input as file paths via Path(value) and pass them directly to open(file_path, "rb") without…

  • CVE-2026-54722HigJul 30, 2026
    risk 0.50cvss —epss 0.00

    DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.4, is_url_safe in src/helpers.ts strips the @ userinfo delimiter with remove_at_symbol_in_string before new URL parses the URL, allowing an attacker-controlled URL…

  • CVE-2026-54522MedJul 30, 2026
    risk 0.28cvss 5.4epss 0.00

    MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::Buffer#clear in ext/msgpack/buffer.c leaves rmem_last, rmem_end, and rmem_owner stale after _msgpack_buffer_shift_chunk returns an rmem page to the shared pool,…

  • CVE-2026-51295Jul 30, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51294Jul 30, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51293Jul 30, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51292Jul 30, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51291Jul 30, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-51290Jul 30, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-13379CriJul 30, 2026
    risk 0.59cvss 9.1epss 0.00

    The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

  • CVE-2026-13117HigJul 30, 2026
    risk 0.53cvss 8.1epss 0.00

    An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

  • CVE-2026-12996HigJul 30, 2026
    risk 0.53cvss 8.1epss 0.00

    A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

  • CVE-2026-12945HigJul 30, 2026
    risk 0.00cvss 7.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.

  • CVE-2026-12940CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py where the DANGEROUS_ENV_VARS…

  • CVE-2026-12932HigJul 30, 2026
    risk 0.53cvss 8.1epss 0.00

    A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

  • CVE-2026-11885HigJul 30, 2026
    risk 0.00cvss 8.4epss 0.00

    IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity.

  • CVE-2026-11771HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

  • CVE-2026-67596MedJul 30, 2026
    risk 0.00cvss 6.2epss 0.00

    CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file.…

  • CVE-2026-58222HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.00

    A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting…

  • CVE-2026-58216MedJul 30, 2026
    risk 0.34cvss 5.3epss 0.00

    An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed ASN.1-encoded Kerberos password change request, Samba server miscalculates the structure size and attempts to read up to six…

  • CVE-2026-57862HigJul 30, 2026
    risk 0.48cvss 8.5epss 0.00

    Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplying hexadecimal IP address notation in user-controlled URLs. Attackers can submit hexadecimal-encoded internal IP addresses through…

  • CVE-2026-52680CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi…

  • CVE-2026-4978CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL Injection. This issue affects Traffic Analysis System: from 30 before 34.

  • CVE-2026-48910MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This…

  • CVE-2026-44617MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.01

    LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters instead of RFC 4515 filter escaping, leaving special filter characters insufficiently escaped.                   Thi…

  • CVE-2026-44616MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.00

    LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, allowing an authenticated attacker to inject LDAP filter syntax through the user-search endpoint…

  • CVE-2026-44613MedJul 30, 2026
    risk 0.33cvss 6.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a…

  • CVE-2026-28814HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWiki variables. Users are recommended to upgrade to version 2.12.4 or 3.0.0, which fixes this issue.

  • CVE-2026-28813HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.00

    Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

  • CVE-2026-28812CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.

  • CVE-2026-28811HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue.

  • CVE-2026-28323CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

  • CVE-2026-23985MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration.…

  • CVE-2026-23981MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards)…

  • CVE-2026-15658HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.

  • CVE-2026-15657MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

  • CVE-2026-10842HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.

  • CVE-2026-6540HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path…

  • CVE-2026-67349HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers…

  • CVE-2026-67348HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including…

  • CVE-2026-67347MedJul 30, 2026
    risk 0.37cvss 6.8epss 0.00

    Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location.service.ts and asset.service.ts update methods that allows channel-scoped administrators to modify other tenants' data. Attackers can supply global IDs…

  • CVE-2026-67346HigJul 30, 2026
    risk 0.49cvss 8.6epss 0.00

    Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or…

  • CVE-2026-67345HigJul 30, 2026
    risk 0.46cvss 8.1epss 0.00

    MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix…

  • CVE-2026-65635HigJul 30, 2026
    risk 0.47cvss —epss 0.00

    Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3…

  • CVE-2026-54885MedJul 30, 2026
    risk 0.38cvss —epss 0.00

    Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and cloud metadata endpoints. Three code…

  • CVE-2026-53431CriJul 30, 2026
    risk 0.52cvss —epss 0.00

    Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. Boruta accepts JWT-based client authentication…

  • CVE-2026-41187MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.00

    Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection…

  • CVE-2026-41186HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap,…

  • CVE-2026-16308HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

  • CVE-2026-15435CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the…