VYPR

CVEs

385,938 total · page 535 of 7,719

  • CVE-2026-46382HigAug 13, 2026
    risk 0.50cvss —epss 0.00

    The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local URI can be made to be fetched without checks. Version 1.12.2 contains a fix. No known workarounds are available.

  • CVE-2026-17431MedAug 13, 2026
    risk 0.40cvss 6.1epss 0.01

    PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_for. to_pdf reads the generated PDF back from its path argument, and _style_tag_for reads each entry of the stylesheets…

  • CVE-2026-16770CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.01

    PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through…

  • CVE-2026-71194MedAug 12, 2026
    risk 0.37cvss 6.8epss 0.01

    In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones with the same name exist across different pools, the lookup fails with a deterministic error, causing the handler to return…

  • CVE-2026-71193CriAug 12, 2026
    risk 0.55cvss 9.6epss 0.01

    In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter…

  • CVE-2026-49481CriAug 12, 2026
    risk 0.55cvss 9.6epss 0.01

    UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be…

  • CVE-2026-47718MedAug 12, 2026
    risk 0.29cvss —epss 0.00

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid-token requests to read project, alarms, and scheduler APIs. Version 1.3.1 fixes this issue.

  • CVE-2026-47717HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.

  • CVE-2026-15424Aug 12, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-15141MedAug 12, 2026
    risk 0.37cvss 5.7epss 0.00

    The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, or omitting the Referer header entirely, may be accepted and processed due to insufficient validation logic. Successful…

  • CVE-2026-7366MedAug 12, 2026
    risk 0.27cvss 4.2epss 0.00

    IBM DataPower Gateway 11.0.0.0 through 11.0.0.1 and IBM DataPower Gateway 10.5.0.0 through 10.5.0.21 and IBM DataPower Gateway 10.6.0.0 through 10.6.0.9 allows a race condition that results in improper isolation of request state when handling the built‑in X‑Client‑IP…

  • CVE-2026-73519CriAug 12, 2026
    risk 0.57cvss 9.8epss 0.01

    WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to…

  • CVE-2026-73501CriAug 12, 2026
    risk 0.52cvss 9.1epss 0.01

    kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution…

  • CVE-2026-73500HigAug 12, 2026
    risk 0.50cvss —epss 0.01

    etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In client/pkg/transport/listener_tls.go,…

  • CVE-2026-73499HigAug 12, 2026
    risk 0.39cvss —epss 0.01

    etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permission on a single exact key can use the Watch gRPC API with clientv3.WithFromKey() to receive watch events for every key…

  • CVE-2026-73498HigAug 12, 2026
    risk 0.43cvss 7.7epss 0.00

    MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, "rb") in src/mcp_atlassian/confluence/attachments.py through…

  • CVE-2026-73495HigAug 12, 2026
    risk 0.41cvss 7.4epss 0.00

    blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP/1.1 chunked-body trailer fields into Request.headers. Because trailer fields are attacker-controlled, an unauthenticated remote…

  • CVE-2026-73493HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.01

    Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregates fragments of an incoming WebSocket message with no limit on total size or fragment count. A client that completes a WebSocket…

  • CVE-2026-73492LowAug 12, 2026
    risk 0.08cvss —epss 0.00

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: or vbscript: URIs whose scheme is split by semicolon-less numeric…

  • CVE-2026-71846MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch permissions, while the code only requires access to a single specific Secret. This excessive privilege means that a compromise of the…

  • CVE-2026-71473HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerability that allows them to inject arbitrary configuration data. This manipulation can override critical settings, leading to the…

  • CVE-2026-71471CriAug 12, 2026
    risk 0.59cvss 9.0epss 0.01

    A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an…

  • CVE-2026-71469HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory…

  • CVE-2026-19003HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the bounds of an allocated buffer. The issue stems from an incorrect buffer capacity calculation in the dialog's file and folder…

  • CVE-2026-18750MedAug 12, 2026
    risk 0.27cvss 5.3epss 0.00

    vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the record's contact belongs to the requesting group-admin. Lets a vendor admin flip notification routing (or read email/name) for…

  • CVE-2026-18749CriAug 12, 2026
    risk 0.57cvss 9.8epss 0.01

    The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released…

  • CVE-2026-18744MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func only checks _is_my_case, not ownership of kwargs['member']. Bypasses share_status; leaks embargoed vendor affected/not-affected +…

  • CVE-2026-18727MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Configuration Protocol for IPv6 (DHCPv6) packet parsing. Specifically, crafted DHCPv6 Advertise traffic with a short User Datagram…

  • CVE-2026-18726MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in the iscsiuio daemon. By sending a specially crafted Internet Control Message Protocol version 6 (ICMPv6) Router Advertisement with…

  • CVE-2026-17485HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.

  • CVE-2026-10534HigAug 12, 2026
    risk 0.55cvss 8.4epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

  • CVE-2024-27253CriAug 12, 2026
    risk 0.65cvss 10.0epss 0.01

    IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

  • CVE-2026-73491LowAug 12, 2026
    risk 0.08cvss —epss 0.00

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named…

  • CVE-2026-73490MedAug 12, 2026
    risk 0.24cvss 4.7epss 0.00

    Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Prior to 2.25.2, Loofah's HTML5 sanitizer applies its local-reference restriction only to the xlink:href attribute on SVG use and feImage elements, while…

  • CVE-2026-73430MedAug 12, 2026
    risk 0.27cvss 5.3epss 0.01

    Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH_INIT with a 32-byte all-zero Q_C value. Curve25519Kex::server_dh in russh/src/kex/curve25519.rs accepts the all-zero peer public…

  • CVE-2026-73429MedAug 12, 2026
    risk 0.27cvss 5.3epss 0.01

    Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY containing a server ephemeral value that is not 32 bytes long. The client-side Curve25519Kex::compute_shared_secret function in…

  • CVE-2026-73427LowAug 12, 2026
    risk 0.07cvss —epss 0.01

    Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.18, Trix is vulnerable to cross-site scripting when a crafted application/x-trix-document JSON payload is dropped into an editor using the fallback Level0InputController, such as an…

  • CVE-2026-73425LowAug 12, 2026
    risk 0.17cvss 3.7epss 0.00

    Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remotePatterns entry into a regular expression written to .netlify/v1/config.json under images.remote_images for Netlify's Image CDN allowlist. In…

  • CVE-2026-73423MedAug 12, 2026
    risk 0.26cvss —epss 0.00

    Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only through the middleware() primitive, while actions() and pages() can dispatch to user code independently. Mounting actions() before…

  • CVE-2026-73422MedAug 12, 2026
    risk 0.27cvss —epss 0.01

    Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animation properties into an inline style element without escaping them for CSS and HTML contexts. An attacker-controlled View Transition…

  • CVE-2026-73419MedAug 12, 2026
    risk 0.37cvss 6.8epss 0.00

    NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC anti-CSRF checks state, nonce, and the PKCE verifier in global cookies that are not bound to the provider that created them. On…

  • CVE-2026-73418HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.01

    NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper in the next-auth/jwt and @auth/core/jwt modules can throw an uncaught exception when it reads a malformed Authorization: Bearer…

  • CVE-2026-66898CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An…

  • CVE-2026-65370HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed in servicetalk version 0.42.65.

  • CVE-2026-64826MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized directory traversal sequences in the filename GET parameter of the download_export() method. Attackers can craft requests with ../…

  • CVE-2026-62421Aug 12, 2026
    risk 0.00cvss —epss —

    Rejected reason: Voluntarily withdrawn

  • CVE-2026-19654HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege…

  • CVE-2026-19503MedAug 12, 2026
    risk 0.31cvss 4.8epss 0.00

    MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpoints returned by an OIDC issuer's discovery document. A user induced to connect to an uncontrolled MongoDB deployment using MONGODB-OIDC authentication may…

  • CVE-2026-19502MedAug 12, 2026
    risk 0.36cvss 5.5epss 0.00

    MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain connection settings were written without redaction, so authentication material supplied by the operator could appear in plaintext…

  • CVE-2026-19130MedAug 12, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vulnerability. By manipulating `copiedFrom`…