VYPR

CVEs

117,534 total · page 483 of 2,351

  • CVE-2026-1007HigJan 19, 2026
    risk 0.49cvss 7.6epss 0.00

    Incorrect Authorization vulnerability in virtual gateway component in Devolutions Server allows attackers to bypass deny IP rules.This issue affects Server: from 2025.3.1 through 2025.3.12.

  • CVE-2026-1157HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in Totolink LR350 9.3.5u.6369_B20220309. This affects the function setWiFiEasyCfg of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ssid leads to buffer overflow. It is possible to launch the attack remotely. The exploit is…

  • CVE-2026-1156HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in Totolink LR350 9.3.5u.6369_B20220309. Affected by this issue is the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument ssid causes buffer overflow. It is possible to initiate the attack remotely. The…

  • CVE-2026-1155HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in Totolink LR350 9.3.5u.6369_B20220309. Affected by this vulnerability is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ssid results in buffer overflow. The attack may be performed from remote. The…

  • CVE-2025-29847HigJan 19, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the system's checks.…

  • CVE-2026-1143HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A weakness has been identified in TOTOLINK A3700R 9.1.2u.5822_B20200513. This affects the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be launched remotely. The exploit…

  • CVE-2026-1140HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in UTT 进取 520W 1.7.7-180627. This issue affects the function strcpy of the file /goform/ConfigExceptAli. The manipulation results in buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used.…

  • CVE-2026-1139HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability has been found in UTT 进取 520W 1.7.7-180627. This vulnerability affects the function strcpy of the file /goform/ConfigExceptMSN. The manipulation leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2026-1138HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A flaw has been found in UTT 进取 520W 1.7.7-180627. This affects the function strcpy of the file /goform/ConfigExceptQQ. Executing a manipulation can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The vendor…

  • CVE-2026-1137HigJan 19, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was detected in UTT 进取 520W 1.7.7-180627. Affected by this issue is the function strcpy of the file /goform/formWebAuthGlobalConfig. Performing a manipulation results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now…

  • CVE-2026-0943HigJan 19, 2026
    risk 0.49cvss 7.5epss 0.00

    HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability.  Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693.

  • CVE-2026-1133HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /kmf/folder.jsp of the component HTTP GET Parameter Handler. Executing a manipulation of the argument folderid can lead to sql injection. The attack can be launched…

  • CVE-2026-1132HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /kmf/edit_folder.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument folderid results in sql injection. The attack can be initiated…

  • CVE-2026-1131HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in Yonyou KSOA 9.0. Impacted is an unknown function of the file /kmc/save_catalog.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument catalogid leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-1130HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in Yonyou KSOA 9.0. This issue affects some unknown processing of the file /worksheet/worksadd_plan.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely.…

  • CVE-2026-1129HigJan 19, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/worksadd.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The…

  • CVE-2026-23644HigJan 18, 2026
    risk 0.42cvss 7.5epss 0.01

    esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerability due to an incomplete fix. `path.Clean` normalizes a path but does not prevent absolute paths in…

  • CVE-2026-1125HigJan 18, 2026
    risk 0.49cvss 7.3epss 0.15

    A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file /goform/set_wifidog_settings. Executing a manipulation of the argument wd_enable can lead to command injection. The attack can be executed remotely. The…

  • CVE-2026-1124HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksheet/work_report.jsp of the component HTTP GET Parameter Handler. Performing a manipulation of the argument ID results in sql injection. Remote…

  • CVE-2026-0863HigJan 18, 2026
    risk 0.01cvss 8.5epss 0.09

    Using string formatting and exception handling, an attacker may bypass n8n's python-task-executor sandbox restrictions and run arbitrary unrestricted Python code in the underlying operating system. The vulnerability can be exploited via the Code block by an authenticated user…

  • CVE-2026-1123HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in Yonyou KSOA 9.0. Affected is an unknown function of the file /worksheet/work_mod.jsp of the component HTTP GET Parameter Handler. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is…

  • CVE-2026-1122HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in Yonyou KSOA 9.0. This impacts an unknown function of the file /worksheet/work_info.jsp of the component HTTP GET Parameter Handler. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2026-1121HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in Yonyou KSOA 9.0. This affects an unknown function of the file /worksheet/del_workplan.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has…

  • CVE-2026-1120HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/del_work.jsp of the component HTTP GET Parameter Handler. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2026-1119HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in itsourcecode Society Management System 1.0. The affected element is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. It is possible to launch the attack remotely.…

  • CVE-2026-1105HigJan 18, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in EasyCMS up to 1.6. This vulnerability affects unknown code of the file /UserAction.class.php. Such manipulation of the argument _order leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be…

  • CVE-2026-1059HigJan 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in FeMiner wms up to 9cad1f1b179a98b9547fd003c23b07c7594775fa. Affected by this vulnerability is an unknown functionality of the file /src/chkuser.php. The manipulation of the argument Username leads to sql injection. The attack is…

  • CVE-2026-1050HigJan 17, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in risesoft-y9 Digital-Infrastructure up to 9.6.7. This affects an unknown function of the file source-code/src/main/java/net/risesoft/util/Y9PlatformUtil.java of the component REST Authenticate Endpoint. Executing a manipulation can lead to sql injection.…

  • CVE-2025-14478HigJan 17, 2026
    risk 0.42cvss 7.5epss 0.00

    The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve…

  • CVE-2026-0517HigJan 17, 2026
    risk 0.49cvss 7.5epss 0.00

    CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash

  • CVE-2026-22865HigJan 16, 2026
    risk 0.48cvss 7.4epss 0.00

    Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered…

  • CVE-2026-22816HigJan 16, 2026
    risk 0.00cvss 7.4epss 0.00

    Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. When resolving dependencies in versions before 9.3.0, some exceptions were not treated as fatal errors and would not cause a repository to be disabled. If a build encountered…

  • CVE-2026-21223HigJan 16, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper privilege management in Microsoft Edge (Chromium-based) allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-20960HigJan 16, 2026
    risk 0.52cvss 8.0epss 0.00

    Improper authorization in Microsoft Power Apps allows an authorized attacker to execute code over a network.

  • CVE-2026-23742HigJan 16, 2026
    risk 0.50cvss 8.8epss 0.00

    Skipper is an HTTP router and reverse proxy for service composition. The default skipper configuration before 0.23.0 was -lua-sources=inline,file. The problem starts if untrusted users can create lua filters, because of -lua-sources=inline , for example through a Kubernetes…

  • CVE-2026-23735HigJan 16, 2026
    risk 0.50cvss epss 0.01

    GraphQL Modules is a toolset of libraries and guidelines dedicated to create reusable, maintainable, testable and extendable modules out of your GraphQL server. From 2.2.1 to before 2.4.1 and 3.1.1, when 2 or more parallel requests are made which trigger the same service, the…

  • CVE-2026-23723HigJan 16, 2026
    risk 0.00cvss 7.2epss 0.00

    WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was identified in the Atendido_ocorrenciaControle endpoint via the id_memorando parameter. This flaw allows for full database exfiltration, exposure of sensitive PII,…

  • CVE-2026-23535HigJan 16, 2026
    risk 0.45cvss 8.0epss 0.00

    wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.

  • CVE-2026-23490HigJan 16, 2026
    risk 0.42cvss 7.5epss 0.01

    pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnerability is fixed in 0.6.2.

  • CVE-2025-68924HigJan 16, 2026
    risk 0.49cvss 7.5epss 0.01

    In Umbraco UmbracoForms through 8.13.16, an authenticated attacker can supply a malicious WSDL (aka Webservice) URL as a data source for remote code execution.

  • CVE-2025-62291HigJan 16, 2026
    risk 0.53cvss 8.1epss 0.01

    In the eap-mschapv2 plugin (client-side) in strongSwan before 6.0.3, a malicious EAP-MSCHAPv2 server can send a crafted message of size 6 through 8, and cause an integer underflow that potentially results in a heap-based buffer overflow.

  • CVE-2025-48647HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    In cpm_fwtp_msg_handler of cpm/google/lib/tracepoint/cpm_fwtp_ipc.c, there is a possible memory overwrite due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2025-15032HigJan 16, 2026
    risk 0.48cvss 7.4epss 0.00

    Missing about:blank indicator in custom-sized new windows in Dia before 1.9.0 on macOS could allow an attacker to spoof a trusted domain in the window title and mislead users about the current site.

  • CVE-2021-47847HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Disk Sorter Server 13.6.12 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Sorter Server\bin\disksrs.exe' to…

  • CVE-2021-47845HigJan 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Spy Emergency 25.0.650 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted file paths in SpyEmergencyHealth.exe and SpyEmergencySrv.exe to…

  • CVE-2021-47842HigJan 16, 2026
    risk 0.47cvss 7.2epss 0.00

    StudyMD 0.3.2 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling…

  • CVE-2021-47840HigJan 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Moeditor 0.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload specially crafted markdown files with embedded JavaScript that execute when opened, potentially enabling remote…

  • CVE-2021-47839HigJan 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Marky 0.0.1 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts into markdown files. Attackers can upload crafted markdown files with embedded JavaScript payloads that execute when the file is opened, potentially enabling…

  • CVE-2021-47838HigJan 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Markright 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to embed malicious payloads in markdown files. Attackers can upload specially crafted markdown files that execute arbitrary JavaScript when opened, potentially enabling remote code…

  • CVE-2021-47837HigJan 16, 2026
    risk 0.47cvss 7.2epss 0.00

    Markdownify 1.2.0 contains a persistent cross-site scripting vulnerability that allows attackers to store malicious payloads within markdown files. Attackers can upload crafted markdown files with embedded scripts that execute when the file is opened, potentially enabling remote…