VYPR

CVEs

385,816 total · page 517 of 7,717

  • CVE-2026-16708HigAug 14, 2026
    risk 0.54cvss 8.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.

  • CVE-2026-73679HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.01

    ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded…

  • CVE-2026-73678CriAug 14, 2026
    risk 0.65cvss 10.0epss 0.02

    MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which…

  • CVE-2026-50029MedAug 14, 2026
    risk 0.27cvss 5.3epss 0.00

    js-toml is a TOML parser for JavaScript, Prior to version 1.1.2, the interpreter checks whether a key already exists in a parser-built container with `if (object[key])` instead of `if (key in object)`. When the prior value is a falsy primitive — `false`, `0`, `0n`, `0.0`,…

  • CVE-2026-50027CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An…

  • CVE-2026-49457CriAug 14, 2026
    risk 0.52cvss 9.1epss 0.00

    erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared…

  • CVE-2026-45699HigAug 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining…

  • CVE-2026-19188CriAug 14, 2026
    risk 0.65cvss 10.0epss 0.03

    A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input…

  • CVE-2026-18403MedAug 14, 2026
    risk 0.32cvss —epss 0.00

    LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injection vulnerability in the Central Participant Database (CPDB) workflow that copies survey participant tokens to the central participant list.

  • CVE-2025-7639HigAug 14, 2026
    risk 0.46cvss 7.1epss 0.01

    The vulnerability, if exploited, could allow an authenticated miscreant with "DNA Authority - Operator" privilege to tamper with serialized data, potentially resulting in code execution during deserialization under the privilege of Enterprise SCADA security group "DNA Apps".

  • CVE-2026-73850HigAug 14, 2026
    risk 0.56cvss —epss 0.00

    Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php.

  • CVE-2026-73849CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname,…

  • CVE-2026-73847MedAug 14, 2026
    risk 0.44cvss 6.8epss 0.00

    Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_tool action in admin/ai.php lets a remote unauthenticated attacker submit a forged cross-site request from an attacker-controlled page to a recently…

  • CVE-2026-72970HigAug 14, 2026
    risk 0.54cvss 8.3epss 0.01

    Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-63361HigAug 14, 2026
    risk 0.48cvss —epss 0.01

    LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding.

  • CVE-2026-49282MedAug 14, 2026
    risk 0.33cvss 5.1epss 0.00

    Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's public `cs_insn_name()` API forwards caller-supplied instruction IDs directly to the selected architecture backend. Most backends validate the ID before indexing instruction-name tables, but the M68K…

  • CVE-2026-49263LowAug 14, 2026
    risk 0.13cvss —epss 0.00

    Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Capstone's WebAssembly backend accepts attacker-controlled raw WASM instruction bytes through the public `cs_disasm()` and `cs_disasm_iter()` APIs. For a large but well-formed `br_table` instruction, the WASM…

  • CVE-2026-48528CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.00

    Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input…

  • CVE-2026-19847HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be…

  • CVE-2026-19846HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be…

  • CVE-2026-19682CriAug 14, 2026
    risk 0.65cvss 9.9epss 0.03

    A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.

  • CVE-2026-19681CriAug 14, 2026
    risk 0.65cvss 9.9epss 0.10

    An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.

  • CVE-2026-19680HigAug 14, 2026
    risk 0.46cvss 7.1epss 0.00

    A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

  • CVE-2026-19679HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.02

    An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.

  • CVE-2026-19639MedAug 14, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.

  • CVE-2026-19636MedAug 14, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.

  • CVE-2026-19635HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.00

    A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.

  • CVE-2026-19631MedAug 14, 2026
    risk 0.32cvss 4.9epss 0.00

    A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials.

  • CVE-2026-19629HigAug 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables…

  • CVE-2026-12366HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.00

    Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The cleanup switch handled only K_OBJ_MSGQ and K_OBJ_STACK;…

  • CVE-2026-12365MedAug 14, 2026
    risk 0.31cvss 5.8epss 0.00

    A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work item's timeout has been dequeued and its handler work_timeout() is in flight (blocked acquiring the work-queue spinlock), a…

  • CVE-2026-12364HigAug 14, 2026
    risk 0.48cvss 8.4epss 0.00

    The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode implementation z_impl_z_log_msg_static_create()…

  • CVE-2026-12363MedAug 14, 2026
    risk 0.20cvss 4.2epss 0.00

    The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/services/frag_transport.c) does not validate the fragment counter in a received DATA_FRAGMENT command before forwarding it to the configured decoder. In frag_transport_package_callback() the value frag_counter =…

  • CVE-2026-73846MedAug 14, 2026
    risk 0.35cvss 6.5epss 0.00

    CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request parameters with unescaped ampersand, equals-sign, and vertical-bar delimiters, allowing different logical parameter sets used by…

  • CVE-2026-73845MedAug 14, 2026
    risk 0.27cvss 5.3epss 0.00

    CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in src/tools/quality.ts use isValidMqaServer to validate the server_url parameter with a prefix-only regular expression for…

  • CVE-2026-73844LowAug 14, 2026
    risk 0.17cvss 3.7epss 0.00

    CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream response bodies and internal exception messages back to the caller instead of a sanitized, generic message. When the server is pointed at (or redirected/SSRF'd to) a…

  • CVE-2026-73107Aug 14, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-49989HigAug 14, 2026
    risk 0.39cvss —epss 0.00

    CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob…

  • CVE-2026-49986HigAug 14, 2026
    risk 0.39cvss —epss 0.00

    The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer…

  • CVE-2026-49826NonAug 14, 2026
    risk 0.00cvss —epss 0.01

    Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's…

  • CVE-2026-47766MedAug 14, 2026
    risk 0.26cvss —epss 0.00

    crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev` directory without `O_NOFOLLOW`. If an OCI bundle contains `rootfs/dev` as a symlink and the bundle configuration does not mount…

  • CVE-2026-47192LowAug 14, 2026
    risk 0.07cvss —epss 0.00

    kas is a setup tool for bitbake based projects. Starting in version 4.8 and prior to version 5.3, kas checks out and processes repositories regarding configuration includes prior to validating signatures of those repositories. This may allow to replace on original repository…

  • CVE-2026-47191LowAug 14, 2026
    risk 0.07cvss —epss 0.00

    kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked…

  • CVE-2026-46603HigAug 14, 2026
    risk 0.42cvss 7.5epss 0.00

    VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

  • CVE-2026-46439HigAug 14, 2026
    risk 0.44cvss 7.8epss 0.00

    compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an…

  • CVE-2026-46380MedAug 14, 2026
    risk 0.37cvss 6.7epss 0.00

    compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without validation. This allows an attacker to perform Server-Side Request…

  • CVE-2026-19845HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is…

  • CVE-2026-19844HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component ipv6.so. Performing a manipulation of the argument radvdinterfacename results in stack-based buffer overflow. It…

  • CVE-2026-19841LowAug 14, 2026
    risk 0.20cvss 3.1epss 0.00

    A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an unknown function of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes incorrect default permissions. The attack is possible to be carried out remotely. A high degree of complexity is…

  • CVE-2026-19839MedAug 14, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function save_doctor of the file /save_file.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may…