VYPR

CVEs

37,819 total · page 50 of 757

  • CVE-2026-67443CriAug 18, 2026
    risk 0.53cvss —epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true,…

  • CVE-2026-52735CriAug 18, 2026
    risk 0.53cvss —epss 0.01

    ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation counter undercounts redeem scripts containing a disabled opcode followed by signature opcodes. In zebra-script/src/lib.rs,…

  • CVE-2026-55166CriAug 18, 2026
    risk 0.57cvss 9.9epss 0.00

    Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-side destination restriction and trigger AcmeHandler.setup_acme_client to make backend requests. An attacker could target cloud…

  • CVE-2026-47627CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to denial of service.

  • CVE-2026-75625CriAug 18, 2026
    risk 0.59cvss 9.0epss 0.00

    Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache, relying only on CRC32 checksums for piece validation. Attackers on the agent-to-agent path or malicious peers can supply…

  • CVE-2026-75130CriAug 18, 2026
    risk 0.59cvss 9.0epss 0.00

    Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting unsanitized content through the Custom AI Instructions feature served via the MCP server. Attackers can poison the…

  • CVE-2026-71879CriAug 18, 2026
    risk 0.59cvss —epss 0.01

    Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

  • CVE-2026-71878CriAug 18, 2026
    risk 0.60cvss —epss 0.01

    Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attackers to gain administrative control via authentication bypass

  • CVE-2026-67921CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-52610CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on the filesystem subject to the permissions of the web user by specifying a filename in the "saveTemplate" parameter in conjuction…

  • CVE-2026-52608CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecuteCode attribute of any report regardless of the safe_mode setting leading to remote code execution.

  • CVE-2026-50161CriAug 18, 2026
    risk 0.53cvss —epss 0.01

    libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in src/websock/websock.c contains an integer overflow when validating a masked WebSocket frame that uses the 64-bit extended length…

  • CVE-2021-43717CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously.

  • CVE-2021-43716CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.

  • CVE-2026-67271CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in SMB/CIFS. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service and remote execution. This is a Critical vulnerability as a remote user…

  • CVE-2026-57580CriAug 18, 2026
    risk 0.54cvss —epss 0.01

    authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion.…

  • CVE-2026-52723CriAug 18, 2026
    risk 0.52cvss 9.1epss 0.00

    ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3.0, ePA 3.x Integration performs VAU server certificate validation in app/vau/VAUProtokoll.py without anchoring the…

  • CVE-2026-18963CriAug 18, 2026
    risk 0.52cvss 9.1epss 0.03

    A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. The issue allows an unauthenticated attacker to force the password reset process for any user without…

  • CVE-2026-75913CriAug 18, 2026
    risk 0.53cvss 9.3epss 0.00

    CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-options sentinel, so a value beginning with…

  • CVE-2026-73373CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

  • CVE-2026-45118CriAug 18, 2026
    risk 0.53cvss 9.3epss 0.01

    MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in…

  • CVE-2026-45117CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is…

  • CVE-2026-12564CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault…

  • CVE-2026-75784CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack…

  • CVE-2026-74015CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

  • CVE-2026-73996CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

  • CVE-2026-73397CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

  • CVE-2026-73381CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

  • CVE-2026-73380CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

  • CVE-2026-73376CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

  • CVE-2026-73366CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

  • CVE-2026-73365CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

  • CVE-2026-73355CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

  • CVE-2026-73343CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

  • CVE-2026-73341CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

  • CVE-2026-73339CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

  • CVE-2026-73187CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

  • CVE-2026-66627CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.

  • CVE-2026-59940CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without…

  • CVE-2026-32474CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

  • CVE-2026-32470CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

  • CVE-2026-32463CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

  • CVE-2026-32444CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.01

    Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

  • CVE-2026-28192CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

  • CVE-2026-75874CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.00

    Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.

  • CVE-2026-75783CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.01

    A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be…

  • CVE-2026-74990CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-74989CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and…

  • CVE-2026-74988CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in…

  • CVE-2026-74987CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…