VYPR

CVEs

386,019 total · page 542 of 7,721

  • CVE-2025-24837Aug 12, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2025-24488Aug 12, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2025-20020Aug 12, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused

  • CVE-2026-18725modAug 12, 2026
    risk 0.41cvss 6.3epss —

    open-iscsi: open-iscsi: Out-of-bounds access in iscsiuio ICMPv6 echo handling

  • CVE-2026-18724modAug 12, 2026
    risk 0.49cvss 7.6epss —

    open-iscsi: open-iscsi: Stack buffer overflow in idbm record parsing

  • CVE-2026-73432MedAug 12, 2026
    risk 0.26cvss —epss 0.00

    Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instance addresses were validated only for basic URL syntax before being stored, while the synchronization worker later dereferenced…

  • CVE-2026-73431HigAug 12, 2026
    risk 0.50cvss —epss 0.00

    Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links were generated using stateless signed tokens containing only the user's login. Although the token signature and age were…

  • CVE-2026-73405MedAug 12, 2026
    risk 0.27cvss —epss 0.01

    An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) streams through the /pubsub/subscribe/ endpoint. The token_required decorator used by the Pub/Sub interface authenticated…

  • CVE-2026-73374MedAug 12, 2026
    risk 0.33cvss —epss 0.01

    A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tags associated with vulnerability records. Values from containers.cna.references[].tags[] were directly interpolated into HTML…

  • CVE-2026-73291HigAug 12, 2026
    risk 0.39cvss 7.1epss 0.00

    Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/imageproxy.ts uses the upstream ETag and Content-Type response headers to build a cache filename for the unauthenticated GET…

  • CVE-2026-73290MedAug 12, 2026
    risk 0.27cvss 5.3epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/access.rs that lacks a direct bucket-policy grant falls back to an s3:ListBucket check and returns before the policy_allowed path…

  • CVE-2026-73289HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifiers with the negated string operators StringNotEquals, StringNotEqualsIgnoreCase, StringNotLike, ArnNotEquals, and ArnNotLike using…

  • CVE-2026-73288MedAug 12, 2026
    risk 0.33cvss —epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets check_object_lock_for_deletion, delete_prefix, and lifecycle and scanner sweeps treat ConfigNotFound,…

  • CVE-2026-73287MedAug 12, 2026
    risk 0.28cvss 5.4epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/src/ftps/driver.rs by calling storage.create_bucket without authorize_operation for S3Action::CreateBucket, allowing authenticated…

  • CVE-2026-73286HigAug 12, 2026
    risk 0.46cvss 8.1epss 0.00

    RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request headers from HeaderMap into server-derived userid, username, principaltype, groups, versionid, signatureversion, jwt:, and ldap:…

  • CVE-2026-73285HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTFS_POLICY_PLUGIN_URL in crates/iam/src/sys.rs sets PreparedIamAuth.needs_existing_object_tag incorrectly for PreparedIamMode::Opa,…

  • CVE-2026-73284HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.01

    RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an attacker-controlled target_user after only checking CreateServiceAccountAdminAction, passes it to new_service_account, and…

  • CVE-2026-73265MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadPartCopy sources with s3:GetObject instead of s3:GetObjectVersion, allowing principals without historical-version permission to…

  • CVE-2026-73264HigAug 12, 2026
    risk 0.42cvss 7.6epss 0.00

    Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidated base_url for the openai_compatible provider through POST /api/v1/lighthouse/providers and POST…

  • CVE-2026-73263CriAug 12, 2026
    risk 0.57cvss 9.9epss 0.01

    Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in…

  • CVE-2026-73262MedAug 12, 2026
    risk 0.28cvss 5.4epss 0.00

    Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_tags, assembled by unroll_dict and parse_html_string, into generated reports without HTML escaping, allowing a cloud principal who…

  • CVE-2026-68760MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may bypass authentication under specific cache conditions.

  • CVE-2026-68757HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    A user with access to a valid SAML response may impersonate another user under specific conditions.

  • CVE-2026-68756MedAug 12, 2026
    risk 0.43cvss 6.6epss 0.00

    A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

  • CVE-2026-68755MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    A bundle writer may create misleading release promotion information under specific conditions.

  • CVE-2026-68754MedAug 12, 2026
    risk 0.42cvss 6.5epss 0.00

    A repository publisher without delete permission may modify protected package content under specific conditions.

  • CVE-2026-68753MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

  • CVE-2026-68752HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    A Project Resource Manager may gain broader administrative privileges under specific conditions.

  • CVE-2026-67287MedAug 12, 2026
    risk 0.41cvss —epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on instances with disabled guest commenting by overriding the setting in question with user supplied input.

  • CVE-2026-67286MedAug 12, 2026
    risk 0.41cvss —epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary directory creation and file write in SP Page Builder < 6.8.0 - An unauthenticated attacker can create arbitrary directories and files with a predefined name.

  • CVE-2026-66382MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user may write files outside the intended Artifactory work directory under specific conditions.

  • CVE-2026-66381MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    A repository reader with cache-deploy permission may access content outside a configured upstream path under specific conditions.

  • CVE-2026-66380MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access private OCI referrer metadata under specific conditions.

  • CVE-2026-66379MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user may view private Puppet module metadata without repository read access.

  • CVE-2026-66378MedAug 12, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user without repository read permission may access private NuGet metadata under specific conditions.

  • CVE-2026-66377MedAug 12, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated user may access restricted repository information under specific conditions.

  • CVE-2026-66376MedAug 12, 2026
    risk 0.27cvss 4.2epss 0.00

    Credentials for a deleted user may remain valid for a short period under specific conditions.

  • CVE-2026-66375HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.

  • CVE-2026-50561CriAug 12, 2026
    risk 0.61cvss 9.4epss 0.01

    Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the…

  • CVE-2026-49349MedAug 12, 2026
    risk 0.44cvss 6.8epss 0.00

    regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvertently leaked to external servers. A prerequisite for this attack is a malicious registry server, a malicious blob store, or a registry that does not restrict…

  • CVE-2026-49262LowAug 12, 2026
    risk 0.20cvss 3.0epss 0.00

    In the Aimeos Pagible content management system prior to version 0.10.4, the administrative proxy route (`cmsproxy`) is vulnerable to a Server-Side Request Forgery (SSRF) attack via DNS Rebinding. A Time-of-Check to Time-of-Use (TOCTOU) race condition exists between the URL…

  • CVE-2026-47234MedAug 12, 2026
    risk 0.22cvss 4.4epss 0.00

    Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::setCookie()` logs full cookie values and `Session::start()` logs the current session ID. In a real Admidio deployment this includes both the active session…

  • CVE-2026-47233MedAug 12, 2026
    risk 0.35cvss 6.5epss 0.00

    Admidio is an open-source user management solution. Version 5.0.9 added a missing `isAdministratorInventory()` gate to `case 'item_delete':` in `modules/inventory.php`. The same fix was not applied to the sibling `case 'field_delete':` handler, which destroys an entire inventory…

  • CVE-2026-18171MedAug 12, 2026
    risk 0.37cvss —epss 0.00

    Docker Sandboxes (sbx) applies the read-only intent of a runtime host mount to the in-guest container bind only: the underlying virtio-fs host-edge grant is added to the sandbox's policy-share allowlist with no access mode. The directory stays writable at its shared-export path,…

  • CVE-2026-14479MedAug 12, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT…

  • CVE-2026-14478HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability.

  • CVE-2025-59324CriAug 12, 2026
    risk 0.59cvss 9.1epss 0.00

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

  • CVE-2025-59323HigAug 12, 2026
    risk 0.55cvss 8.4epss 0.00

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, responsible for storing configuration and cryptographic details. Crafted DataStore contents can impact service availability and/or allow for…

  • CVE-2025-59322HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly handle decryption errors and allows encrypted volumes to be mounted as plaintext.

  • CVE-2025-59321CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.