VYPR

CVEs

117,520 total · page 492 of 2,351

  • CVE-2025-13447HigJan 13, 2026
    risk 0.57cvss 8.4epss 0.25

    OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

  • CVE-2025-13444HigJan 13, 2026
    risk 0.57cvss 8.4epss 0.25

    OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker with “User Administration” permissions to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in the API input parameters

  • CVE-2026-0891HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Memory safety bugs present in Firefox ESR 140.6, Thunderbird ESR 140.6, Firefox 146 and Thunderbird 146. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This…

  • CVE-2026-0889HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.01

    Denial-of-service in the DOM: Service Workers component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.

  • CVE-2026-0882HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    Use-after-free in the IPC component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

  • CVE-2026-0880HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.01

    Sandbox escape due to integer overflow in the Graphics component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

  • CVE-2026-0878HigJan 13, 2026
    risk 0.52cvss 8.0epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 147, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

  • CVE-2026-0877HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.

  • CVE-2025-9427HigJan 13, 2026
    risk 0.55cvss epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Lemonsoft WordPress add on allows Cross-Site Scripting (XSS).This issue affects WordPress add on: 2025.7.1.

  • CVE-2025-11669HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.01

    Zohocorp ManageEngine PAM360 versions before 8202; Password Manager Pro versions before 13221; Access Manager Plus versions prior to 4401 are vulnerable to an authorization issue in the initiate remote session functionality.

  • CVE-2025-13774HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability exists in Progress Flowmon ADS versions prior to 12.5.4 and 13.0.1 where an SQL injection vulnerability allows authenticated users to execute unintended SQL queries and commands.

  • CVE-2026-0859HigJan 13, 2026
    risk 0.44cvss 7.8epss 0.00

    TYPO3's mail‑file spool deserialization flaw lets local users with write access to the spool directory craft a malicious file that is deserialized during the mailer:spool:send command, enabling arbitrary PHP code execution on the web server. This issue affects TYPO3 CMS…

  • CVE-2025-59022HigJan 13, 2026
    risk 0.46cvss 8.1epss 0.00

    Backend users who had access to the recycler module could delete arbitrary data from any database table defined in the TCA - regardless of whether they had permission to that particular table. This allowed attackers to purge and destroy critical site data, effectively rendering…

  • CVE-2025-40944HigJan 13, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6…

  • CVE-2025-40942HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges.

  • CVE-2025-41717HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.01

    An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and integrity due to improper control of code…

  • CVE-2025-66177HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched…

  • CVE-2025-66176HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    There is a Buffer overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially crafted packets to an unpatched…

  • CVE-2026-0511HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.00

    SAP Fiori App Intercompany Balance Reconciliation does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. This has high impact on confidentiality and integrity of the application ,availability is not impacted.

  • CVE-2026-0507HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.01

    Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this…

  • CVE-2026-0506HigJan 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Due to a Missing Authorization Check vulnerability in Application Server ABAP and ABAP Platform, an authenticated attacker could misuse an RFC function to execute form routines (FORMs) in the ABAP system. Successful exploitation could allow the attacker to write or modify data…

  • CVE-2026-0492HigJan 13, 2026
    risk 0.57cvss 8.8epss 0.00

    SAP HANA database is vulnerable to privilege escalation allowing an attacker with valid credentials of any user to switch to another user potentially gaining administrative access. This exploit could result in a total compromise of the system�s confidentiality, integrity, and…

  • CVE-2026-22812HigJan 12, 2026
    risk 0.52cvss 8.8epss 0.17

    OpenCode is an open source AI coding agent. Prior to 1.0.216, OpenCode automatically starts an unauthenticated HTTP server that allows any local process (or any website via permissive CORS) to execute arbitrary shell commands with the user's privileges. This vulnerability is…

  • CVE-2026-22805HigJan 12, 2026
    risk 0.56cvss 8.6epss 0.00

    Metabase is an open-source data analytics platform. Prior to 55.13, 56.3, and 57.1, self-hosted Metabase instances that allow users to create subscriptions could be potentially impacted if their Metabase is colocated with other unsecured resources. This vulnerability is fixed in…

  • CVE-2026-22804HigJan 12, 2026
    risk 0.52cvss 8.0epss 0.00

    Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0 to 1.9.0, Stored Cross-Site Scripting (XSS) vulnerability exists in the Termix File Manager component. The application fails to sanitize SVG file content…

  • CVE-2025-15514HigJan 12, 2026
    risk 0.49cvss 7.5epss 0.01

    Ollama 0.11.5-rc0 through current version 0.13.5 contain a null pointer dereference vulnerability in the multi-modal model image processing functionality. When processing base64-encoded image data via the /api/chat endpoint, the application fails to validate that the decoded…

  • CVE-2024-58340HigJan 12, 2026
    risk 0.49cvss 7.5epss 0.00

    LangChain versions up to and including 0.3.1 contain a regular expression denial-of-service (ReDoS) vulnerability in the MRKLOutputParser.parse() method (libs/langchain/langchain/agents/mrkl/output_parser.py). The parser applies a backtracking-prone regular expression when…

  • CVE-2024-58339HigJan 12, 2026
    risk 0.49cvss 7.5epss 0.01

    LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query() logic generates SQL statements from a user-supplied prompt and executes them via…

  • CVE-2024-14021HigJan 12, 2026
    risk 0.51cvss 7.8epss 0.00

    LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py. The function uses pickle.load() to deserialize multi_embed_store.pkl from a…

  • CVE-2026-22799HigJan 12, 2026
    risk 0.00cvss 8.8epss 0.01

    Emlog is an open source website building system. emlog v2.6.1 and earlier exposes a REST API endpoint (/index.php?rest-api=upload) for media file uploads. The endpoint fails to implement proper validation of file types, extensions, and content, allowing authenticated attackers…

  • CVE-2026-22788HigJan 12, 2026
    risk 0.00cvss 8.2epss 0.01

    WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Prior to 1.19, the WebErpMesV2 application exposes multiple sensitive API endpoints without authentication middleware. An unauthenticated remote attacker can read business-critical data…

  • CVE-2026-22786HigJan 12, 2026
    risk 0.40cvss 7.2epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin. Gin-vue-admin <= v2.8.7 has a path traversal vulnerability in the breakpoint resume upload functionality. Attacker can upload any files on any directory. In the breakpoint_continue.go file, the MakeFile…

  • CVE-2023-36331HigJan 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Incorrect access control in the /member/orderList API of xmall v1.1 allows attackers to arbitrarily access other users' order details via manipulation of the query parameter userId.

  • CVE-2026-22776HigJan 12, 2026
    risk 0.00cvss 7.5epss 0.00

    cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.30.1, a Denial of Service (DoS) vulnerability exists in cpp-httplib due to the unsafe handling of compressed HTTP request bodies (Content-Encoding: gzip, br, etc.). The library…

  • CVE-2026-22771HigJan 12, 2026
    risk 0.50cvss 8.8epss 0.01

    Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway. Prior to 1.5.7 and 1.6.2, EnvoyExtensionPolicy Lua scripts executed by Envoy proxy can be used to leak the proxy's credentials. These credentials can then be…

  • CVE-2026-22200HigJan 12, 2026
    risk 0.58cvss 7.5epss 0.74

    Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which…

  • CVE-2025-68472HigJan 12, 2026
    risk 0.47cvss 8.1epss 0.19

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing…

  • CVE-2025-46068HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism

  • CVE-2025-46067HigJan 12, 2026
    risk 0.53cvss 8.2epss 0.00

    An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file

  • CVE-2025-71063HigJan 12, 2026
    risk 0.00cvss 8.2epss 0.00

    Errands before 46.2.10 does not verify TLS certificates for CalDAV servers.

  • CVE-2025-41078HigJan 12, 2026
    risk 0.53cvss 8.1epss 0.00

    Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the…

  • CVE-2025-41077HigJan 12, 2026
    risk 0.53cvss 8.1epss 0.00

    IDOR vulnerability has been found in Viafirma Inbox v4.5.13 that allows any authenticated user without privileges in the application to list all users, access and modify their data. This allows the user's email addresses to be modified and, subsequently, using the password…

  • CVE-2025-41005HigJan 12, 2026
    risk 0.57cvss epss 0.00

    Imaster's MEMS Events CRM contains an SQL injection vulnerability in‘keyword’ parameter in ‘/memsdemo/exchange_offers.php’.

  • CVE-2025-41004HigJan 12, 2026
    risk 0.57cvss epss 0.00

    Imaster's Patient Records Management System is vulnerable to SQL Injection in the endpoint ‘/projects/hospital/admin/complaints.php’ through the ‘id’ parameter.

  • CVE-2025-14279HigJan 12, 2026
    risk 0.46cvss 8.1epss 0.00

    MLFlow versions up to and including 3.4.0 are vulnerable to DNS rebinding attacks due to a lack of Origin header validation in the MLFlow REST server. This vulnerability allows malicious websites to bypass Same-Origin Policy protections and execute unauthorized calls against…

  • CVE-2026-0855HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Certain IP Camera models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

  • CVE-2026-0854HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.01

    Certain DVR/NVR models developed by Merit LILIN has a OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the device.

  • CVE-2025-69276HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Object Injection.This issue affects DX NetOps Spectrum: 24.3.13 and earlier.

  • CVE-2025-69274HigJan 12, 2026
    risk 0.57cvss 8.8epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Privilege Escalation.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.

  • CVE-2025-69273HigJan 12, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Authentication vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Authentication Bypass.This issue affects DX NetOps Spectrum: 24.3.10 and earlier.