VYPR

CVEs

37,838 total · page 52 of 757

  • CVE-2026-64849CriKEVAug 17, 2026
    risk 0.66cvss 9.3epss 0.10

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in…

  • CVE-2026-51977CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.00

    An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the RSA private key component

  • CVE-2026-42163CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain circumstances. This applies to LTI 1.1 and LTI 1.3 Advantage.

  • CVE-2026-75110CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check in…

  • CVE-2026-75106CriAug 17, 2026
    risk 0.52cvss 9.1epss 0.00

    OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch…

  • CVE-2026-67967CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-44867 and CVE-2026-36819

  • CVE-2026-67966CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell access.

  • CVE-2026-67965CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function

  • CVE-2026-67926CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module

  • CVE-2026-67917CriAug 17, 2026
    risk 0.57cvss 9.8epss 0.01

    zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` command executes the `db.sql` file extracted from a backup archive without any content validation or sanitization. This allows a remote…

  • CVE-2026-66795CriAug 17, 2026
    risk 0.64cvss 9.9epss 0.00

    A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged…

  • CVE-2026-65974CriAug 17, 2026
    risk 0.57cvss 9.9epss 0.01

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permission boundary in Frappe safe execution because frappe.render_template is exposed without forcing restrict_globals, allowing…

  • CVE-2026-47698CriAug 17, 2026
    risk 0.57cvss 9.8epss 0.01

    vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing sandbox code to sever a host intrinsic's…

  • CVE-2026-47686CriAug 17, 2026
    risk 0.57cvss 9.9epss 0.01

    vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing sandbox code to obtain a powerful host…

  • CVE-2026-39255CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components

  • CVE-2026-39254CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAudioHidDevice::DeviceGetDescriptionString components

  • CVE-2026-71472CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource (CR) editor, to inject malicious shell commands or SQL statements. This occurs because the WORK_MEM string provided in the Search…

  • CVE-2026-68004CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-level security configuration (security.enabled), SrsSecurity::check(), trunk/src/app/srs_app_security.cpp, and SRS RTMP listener…

  • CVE-2026-67678CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

  • CVE-2026-19478CriAug 17, 2026
    risk 0.62cvss 9.4epss 0.60

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user…

  • CVE-2026-66792CriAug 17, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileges by creating a Subscription with specific, crafted annotations. Successful exploitation grants the attacker the ability to…

  • CVE-2026-50775CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, and it fails to return the content or any errors directly.

  • CVE-2026-50774CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.

  • CVE-2026-74254CriAug 17, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection issue related to the styles model. Version 3.6.4 fixed the vector in the frontend, 3.6.5 in the backend.

  • CVE-2026-74253CriAug 17, 2026
    risk 0.65cvss —epss 0.00

    Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.

  • CVE-2026-51346CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.01

    SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensitive information via the store() functions.

  • CVE-2026-50772CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.

  • CVE-2026-50770CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.

  • CVE-2026-50769CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conflict endpoint index.php?module=Appointments&action=CheckConflictOfDates&ajaxSkipHeader=true which is used to check any conflicts…

  • CVE-2026-75045CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.00

    In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

  • CVE-2026-71479CriAug 17, 2026
    risk 0.52cvss 9.1epss 0.01

    New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression…

  • CVE-2026-64859CriAug 17, 2026
    risk 0.52cvss 9.1epss 0.01

    New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized…

  • CVE-2026-55674CriAug 17, 2026
    risk 0.60cvss 9.3epss 0.01

    Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_scheme_id) cookie to inject arbitrary HTML into a Discourse page. Because the…

  • CVE-2026-71566CriAug 17, 2026
    risk 0.60cvss 9.3epss 0.00

    FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG file mounted to the container and completely ignores the credentials. This…

  • CVE-2026-14564CriAug 17, 2026
    risk 0.59cvss 9.0epss 0.00

    Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve Embedded Sensitive Data. This issue affects Logsign SIEM: from 6.4.97 before 6.4.114.

  • CVE-2026-74843CriAug 17, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttpd/www/cgi-bin/export_pingortrace.cgi of the component Export Pingortrace CGI. Executing a manipulation of the argument HTTP_COOKIE…

  • CVE-2026-74901CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.00

    openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to unauthenticated AES-CTR mode. Attackers can modify ciphertext in transit to bypass integrity verification and perform bit-flipping…

  • CVE-2026-74900CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mode, generating a deterministic shared secret from only 16 bytes of the private key and publicly available encapsulated key data.…

  • CVE-2026-74899CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted exec() builtins. Attackers can traverse the Python class hierarchy via __class__.__mro__.__subclasses__() to access system…

  • CVE-2026-74896CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder attribute traversal techniques. Attackers can use __class__, __bases__, __subclasses__(), and __globals__ chains to access…

  • CVE-2026-74895CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can execute malicious plugins with unrestricted access to the filesystem, network, subprocess execution, and all Python modules.

  • CVE-2026-74894CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token string without validation. Attackers can upload arbitrary public keys, enumerate all keys, and revoke keys belonging to any user…

  • CVE-2026-74891CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network can access PostgreSQL databases using well-known default credentials to retrieve sensitive data.

  • CVE-2026-74889CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.00

    openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against…

  • CVE-2026-74886CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules than the AST analyzer's DANGEROUS_MODULES set. Attackers can bypass AST analysis through string obfuscation or encoding to import…

  • CVE-2026-74880CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract tokens from server logs, proxy logs, browser history, and HTTP Referer headers to gain unauthorized access.

  • CVE-2026-74878CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on server restart. Attackers can distribute authentication attempts across multiple server instances or retry immediately after a…

  • CVE-2026-74876CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.00

    openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without verifying signatures. Attackers can call from_dict() followed by to_identity() without signature verification to encrypt data using…

  • CVE-2026-74875CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.00

    openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata to be accepted. Attackers can remove the jsonschema package or supply unknown metadata format versions to bypass all schema checks…

  • CVE-2026-74872CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob patterns to load .so modules without integrity verification. Attackers can place malicious .so files matching the whirlpool*py313*.so…