VYPR

CVEs

113,594 total · page 5 of 2,272

  • CVE-2026-73566HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty…

  • CVE-2026-73564HigAug 13, 2026
    risk 0.50cvss epss 0.00

    frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by adding 4 to an attacker-controlled four-byte big-endian length. A length of 0xFFFFFFFF makes the uint32 addition wrap to 3, defeats…

  • CVE-2026-73561HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadDefaultConnectionEventListeners to call requestClientId, which calls rpc.send for the get-client-id action and pushes a request…

  • CVE-2026-72741HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauthorized enterprise resources by substituting another enterprise's tenant name in URL paths. Attackers can use any valid API token…

  • CVE-2026-18428HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.01

    A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query access to execute arbitrary code on Apache Spark workers by sending a crafted SQL query to the direct query endpoint.

  • CVE-2024-58374HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet…

  • CVE-2019-25765HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.01

    ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL by manipulating the id parameter in GET requests to the comment listing script. Attackers can bypass the application's keyword…

  • CVE-2026-73266HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by manipulating ClusterClaim labels. This allows the tenant to force a cluster to join a ManagedClusterSet belonging to another tenant.…

  • CVE-2026-59765HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata

  • CVE-2026-59109HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a received e-invoice (UBL/PEPPOL) or an e-commerce export, Zalktis concatenates partner-controlled values directly into SQL statement…

  • CVE-2026-58439HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag

  • CVE-2026-58438HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access

  • CVE-2026-58437HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    Repository Visibility Manipulation via Git Push Options

  • CVE-2026-58436HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

  • CVE-2026-58434HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Private Repository Metadata Remains Accessible After Access Revocation

  • CVE-2026-58427HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Private org member list leaked via /members API endpoint — incomplete fix for PR #38145

  • CVE-2026-58417HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    REST API exposes organization membership of private organizations to public

  • CVE-2026-58416HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    Fork-PR Actions task can read a third private repository via the collaborative-owner branch (missing fork-PR guard)

  • CVE-2026-58314HigAug 13, 2026
    risk 0.43cvss 7.7epss 0.00

    Two SSRF findings in Gitea 1.26.2

  • CVE-2026-57894HigAug 13, 2026
    risk 0.55cvss 8.5epss 0.00

    Repository Migration Follows Git HTTP Redirects After URL Allow/Block Validation, Enabling Internal Git Repository Exfiltration

  • CVE-2026-55987HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    OAuth2 sign-in reactivates an administrator-deactivated account on auth sources without refresh tokens (incomplete fix of #38009)

  • CVE-2026-55402HigAug 13, 2026
    risk 0.57cvss epss 0.00

    CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.

  • CVE-2026-54481HigAug 13, 2026
    risk 0.49cvss 7.5epss 0.00

    Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295)

  • CVE-2026-24791HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    Public-only tokens bypass private-resource restrictions on `/api/v1/user` self routes

  • CVE-2026-13048HigAug 13, 2026
    risk 0.53cvss 8.2epss 0.00

    Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename. load_lexicon builds the catalog path by appending…

  • CVE-2026-73670HigAug 13, 2026
    risk 0.47cvss 7.2epss 0.00

    A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a SHOW COLUMNS FROM statement by supplying unsanitized input through the table_name GET or POST parameter. Attackers can perform…

  • CVE-2026-73570HigAug 13, 2026
    risk 0.58cvss 8.9epss 0.01

    A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an…

  • CVE-2026-73515HigAug 13, 2026
    risk 0.53cvss 8.1epss 0.00

    PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplying a malformed FlatGeobuf buffer. The FlatGeobuf property metadata decoder verifies that a string length field is present but fails…

  • CVE-2026-73514HigAug 13, 2026
    risk 0.50cvss 8.8epss 0.00

    The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a database user with the ability to supply caller-controlled relation names to standardize_address() to trigger memory corruption by…

  • CVE-2026-19710HigAug 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file app/admin/departments/view_department.php. Performing a manipulation of the argument ID results in sql injection. The attack is…

  • CVE-2026-73509HigAug 13, 2026
    risk 0.42cvss 7.6epss 0.00

    OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch.go authorizes only the source directory produced by user.JoinPath(req.SrcDir) and validates renameObject.NewName with…

  • CVE-2026-73507HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDecoder.decode() failed to preserve closing-tag parser state across invocations, so an unauthenticated remote attacker could…

  • CVE-2026-73505HigAug 13, 2026
    risk 0.44cvss 7.8epss 0.00

    Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/path.go passed pt.Path, which includes raw folder names, to template.Render, whose function map exposes cmd, so an…

  • CVE-2026-70464HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.01

    rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection slots by stalling the handshake process before or after module selection without triggering the I/O timeout. Attackers can open…

  • CVE-2026-70463HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when splitting the user list, which fails to correctly handle entries of the form @Group Name where the group name contains a space. The…

  • CVE-2026-70461HigAug 13, 2026
    risk 0.46cvss 8.2epss 0.01

    rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-controlled byte past the end of a heap allocation by supplying a crafted files-from entry. Attackers can trigger the vulnerability…

  • CVE-2026-70460HigAug 13, 2026
    risk 0.46cvss 8.1epss 0.00

    rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks within the module file tree when using --partial-dir or --backup-dir options. Attackers with write access to place a symlink under…

  • CVE-2026-70458HigAug 13, 2026
    risk 0.46cvss 8.2epss 0.00

    rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on file entries with the FLAG_HLINKED flag set while the hard-link preservation option is inactive. Attackers can exploit the…

  • CVE-2026-70456HigAug 13, 2026
    risk 0.46cvss 8.2epss 0.00

    rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent heap memory by sending a crafted argument list. When the argument count causes the argv allocation to be exactly full, the…

  • CVE-2026-70455HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt short alias for --compress-threads, which bypasses the refuse options directive's string matching on long option names. Attackers…

  • CVE-2026-70454HigAug 13, 2026
    risk 0.45cvss 8.0epss 0.00

    rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit…

  • CVE-2026-70453HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.01

    rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of service by delivering a carefully constructed file list. A sender can exploit the quadratic-time worst-case behavior in hash…

  • CVE-2026-70452HigAug 13, 2026
    risk 0.41cvss 7.4epss 0.00

    rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS resolution failures during hostname-based access control evaluation. When a DNS lookup for a hostname-based deny rule fails, the…

  • CVE-2026-6387HigAug 13, 2026
    risk 0.45cvss 7.0epss 0.00

    A potential authentication bypass vulnerability was reported in Lenovo System Update that could allow a local authenticated user to execute arbitrary code with elevated privileges.

  • CVE-2026-68454HigAug 13, 2026
    risk 0.50cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: KVM: s390: pci: Fix handling of AIF enable without AISB When a guest seeks to register IRQs without a summary bit specified, ensure that the associated GAITE then stores 0 for the guest AISB location instead…

  • CVE-2026-68453HigAug 13, 2026
    risk 0.39cvss 7.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in…

  • CVE-2026-68452HigAug 13, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early…

  • CVE-2026-68451HigAug 13, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA ECC private key requests cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if…

  • CVE-2026-66256HigAug 13, 2026
    risk 0.47cvss 7.2epss 0.01

    ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. …

  • CVE-2026-65935HigAug 13, 2026
    risk 0.49cvss epss 0.00

    Passkey entry Bluetooth LE legacy pairing can be bypassed in the RS9116W and SiWx917 by manipulating the temporary key value.  See vulnerability B-E3 in the related paper below.