VYPR

CVEs

117,507 total · page 496 of 2,351

  • CVE-2026-21693HigJan 7, 2026
    risk 0.00cvss 8.8epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccSegmentedCurveXml::ToXml()` at…

  • CVE-2026-21692HigJan 7, 2026
    risk 0.00cvss 8.8epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `ToXmlCurve()` at…

  • CVE-2026-21688HigJan 7, 2026
    risk 0.00cvss 8.8epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `SIccCalcOp::ArgsPushed()` at…

  • CVE-2026-21687HigJan 7, 2026
    risk 0.00cvss 7.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have Undefined Behavior in `CIccTagCurve::CIccTagCurve()`. This vulnerability…

  • CVE-2026-21686HigJan 7, 2026
    risk 0.00cvss 7.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have Undefined Behavior in `CIccTagLutAtoB::Validate()`. This vulnerability…

  • CVE-2026-21685HigJan 7, 2026
    risk 0.00cvss 7.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have Undefined Behavior in `CIccTagLut16::Read()`. This vulnerability affects…

  • CVE-2026-21684HigJan 7, 2026
    risk 0.00cvss 7.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have Undefined Behavior in `CIccTagSpectralViewingConditions()`. This…

  • CVE-2026-21683HigJan 7, 2026
    risk 0.00cvss 8.8epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `icStatusCMM::CIccEvalCompare::EvaluatePr…

  • CVE-2026-21441HigJan 7, 2026
    risk 0.42cvss 7.5epss 0.03

    urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loading the entire response body into memory at once. urllib3 can perform decoding or decompression…

  • CVE-2025-69264HigJan 7, 2026
    risk 0.50cvss 8.8epss 0.01

    pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts…

  • CVE-2025-69263HigJan 7, 2026
    risk 0.42cvss 7.5epss 0.00

    pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who…

  • CVE-2025-13151HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.01

    Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

  • CVE-2026-22190HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.00

    The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability. The -gp (glyph pattern) command-line option is used directly as the format string for sprintf() with only a single argument supplied. If an attacker…

  • CVE-2026-22187HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.01

    Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes memo files associated with images without…

  • CVE-2026-22186HigJan 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files,…

  • CVE-2026-22184HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user…

  • CVE-2026-21682HigJan 7, 2026
    risk 0.00cvss 8.8epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a heap-buffer-overflow in `CIccXmlArrayType::ParseText()`. This…

  • CVE-2026-21681HigJan 7, 2026
    risk 0.00cvss 7.1epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Undefined Behavior runtime error. This vulnerability affects users of…

  • CVE-2025-69220HigJan 7, 2026
    risk 0.00cvss 7.1epss 0.00

    LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by…

  • CVE-2025-66620HigJan 7, 2026
    risk 0.52cvss 8.0epss 0.00

    An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data…

  • CVE-2025-61939HigJan 7, 2026
    risk 0.57cvss 8.8epss 0.00

    An unused function in MicroServer can start a reverse SSH connection to a vendor registered domain, without mutual authentication. An attacker on the local network with admin access to the web server, and the ability to manipulate DNS responses, can redirect the SSH connection…

  • CVE-2026-21856HigJan 7, 2026
    risk 0.00cvss 7.2epss 0.00

    The Tarkov Data Manager is a tool to manage the Tarkov item data. Prior to commit 9bdb3a75a98a7047b6d70144eb1da1655d6992a8, a time based blind SQL injection vulnerability in the webhook edit and scanner api endpoints that allow an authenticated attacker to execute arbitrary SQL…

  • CVE-2026-21679HigJan 7, 2026
    risk 0.00cvss 8.8epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow in CIccLocalizedUnicode::GetText(). This issue has been patched in…

  • CVE-2026-21678HigJan 7, 2026
    risk 0.00cvss 7.8epss 0.00

    iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of ICC color management profiles. Prior to version 2.3.1.2, iccDEV is vulnerable to heap-buffer-overflow vulnerability in IccTagXml(). This issue has been patched in…

  • CVE-2026-0669HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Wikimedia Foundation MediaWiki - CSS extension allows Path Traversal.This issue affects MediaWiki - CSS extension: 1.44, 1.43, 1.39.

  • CVE-2026-22544HigJan 7, 2026
    risk 0.57cvss epss 0.00

    An attacker with a network connection could detect credentials in clear text.

  • CVE-2026-22536HigJan 7, 2026
    risk 0.56cvss epss 0.00

    The absence of permissions control for the user XXX allows the current configuration in the sudoers file to escalate privileges without any restrictions

  • CVE-2026-22535HigJan 7, 2026
    risk 0.58cvss epss 0.00

    An attacker with the ability to interact through the network and with access credentials, could, thanks to the unsecured (unencrypted) MQTT communications protocol, write on the server topics of the board that controls the MQTT communications

  • CVE-2025-67366HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.01

    @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path…

  • CVE-2025-67364HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.01

    fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and…

  • CVE-2025-66786HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenAirInterface CN5G AMF<=v2.0.1 There is a logical error when processing JSON format requests. Unauthorized remote attackers can send malicious JSON data to AMF's SBI interface to launch a denial-of-service attack.

  • CVE-2025-65805HigJan 7, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenAirInterface CN5G AMF<=v2.1.9 has a buffer overflow vulnerability in processing NAS messages. Unauthorized remote attackers can launch a denial-of-service attack and potentially execute malicious code by accessing port N1 and sending an imsi string longer than 1000 to AMF.

  • CVE-2025-4676HigJan 7, 2026
    risk 0.57cvss 8.8epss 0.00

    Incorrect Implementation of Authentication Algorithm vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.This issue affects WebPro SNMP Card PowerValue: through 1.1.8.K; WebPro SNMP Card PowerValue UL: through 1.1.8.K.

  • CVE-2026-22541HigJan 7, 2026
    risk 0.53cvss epss 0.00

    The massive sending of ICMP requests causes a denial of service on one of the boards from the EVCharger that allows control the EV interfaces. Since the board must be operating correctly for the charger to also function correctly.

  • CVE-2025-46494HigJan 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themesgrove WidgetKit Pro allows Reflected XSS.This issue affects WidgetKit Pro: from n/a through 1.13.1.

  • CVE-2026-20893HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Origin validation error issue exists in Fujitsu Security Solution AuthConductor Client Basic V2 2.0.25.0 and earlier. If this vulnerability is exploited, an attacker who can log in to the Windows system where the affected product is installed may execute arbitrary code with…

  • CVE-2026-0656HigJan 7, 2026
    risk 0.53cvss 8.2epss 0.00

    The iPaymu Payment Gateway for WooCommerce plugin for WordPress is vulnerable to Missing Authentication in all versions up to, and including, 2.0.2 via the 'check_ipaymu_response' function. This is due to the plugin not validating webhook request authenticity through signature…

  • CVE-2026-0643HigJan 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack…

  • CVE-2026-0628HigJan 7, 2026
    risk 0.58cvss 8.8epss 0.07

    Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

  • CVE-2025-9611HigJan 7, 2026
    risk 0.40cvss epss 0.01

    Microsoft Playwright MCP Server versions prior to 0.0.40 fails to validate the Origin header on incoming connections. This allows an attacker to perform a DNS rebinding attack via a victim’s web browser and send unauthorized requests to a locally running MCP server, resulting…

  • CVE-2025-69082HigJan 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Frenify Arlo arlo allows Reflected XSS.This issue affects Arlo: from n/a through <= 6.0.3.

  • CVE-2025-69081HigJan 7, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.

  • CVE-2025-69080HigJan 7, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in JanStudio Gecko gecko allows PHP Local File Inclusion.This issue affects Gecko: from n/a through <= 1.9.8.

  • CVE-2025-47396HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption occurs when a secure application is launched on a device with insufficient memory.

  • CVE-2025-47394HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when copying overlapping buffers during memory operations due to incorrect offset calculations.

  • CVE-2025-47393HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption when accessing resources in kernel driver.

  • CVE-2025-47388HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while passing pages to DSP with an unaligned starting address.

  • CVE-2025-47380HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while preprocessing IOCTLs in sensors.

  • CVE-2025-47356HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory Corruption when multiple threads concurrently access and modify shared resources.

  • CVE-2025-47348HigJan 7, 2026
    risk 0.51cvss 7.8epss 0.00

    Memory corruption while processing identity credential operations in the trusted application.