VYPR

CVEs

386,146 total · page 548 of 7,723

  • CVE-2026-68432HigAug 12, 2026
    risk 0.50cvss 8.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns vxlan->net. They differ once the device is…

  • CVE-2026-68431CriAug 12, 2026
    risk 0.52cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applies the minimum SMB2 PDU size check only when ProtocolId is SMB2_PROTO_NUMBER. A packet carrying SMB2_TRANSFORM_PROTO_NUM bypasses…

  • CVE-2026-68430Aug 12, 2026
    risk 0.00cvss —epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx8: drop unecessary BUG_ON() There's no need to crash the kernel for this case. (cherry picked from commit 4d7c25208ca612b754f3bf39e9f16e725b828891)

  • CVE-2026-68429Aug 12, 2026
    risk 0.00cvss —epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe() A hotplug or link-loss event can tear down the MST topology (setting mgr->mst_state = false and mgr->mst_primary = NULL)…

  • CVE-2024-14043MedAug 12, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was determined in Open5GS up to 2.7.1. This vulnerability affects the function mme_s6a_subscription_data_from_avp of the file src/mme/mme-fd-path.c of the component Diameter S6a Interface. Executing a manipulation of the argument msisdn_len can lead to heap-based…

  • CVE-2026-73250MedAug 11, 2026
    risk 0.28cvss —epss 0.00

    Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the Notepad++ Windows 11 x64 and ARM64 installer passes the attacker-influenced installation directory `$INSTDIR` from PowerEditor/installer/nppSetup.nsi into a PowerShell `-Command` string used by…

  • CVE-2026-73249HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.00

    calibre is an e-book manager. Prior to 9.12.0, the calibre Content Server endpoint POST /book-update-annotations/{library_id}/{book_id}/{fmt} in src/calibre/srv/books.py omits needs_db_write=True, causing Router.dispatch() to skip ctx.check_for_write_access() before…

  • CVE-2026-73248HigAug 11, 2026
    risk 0.48cvss —epss 0.00

    calibre is an e-book manager. Prior to 9.12.0, calibre processes attacker-controlled composite_template metadata from a malicious EPUB, OPF, PDF, or similar file through program: and a nested template() call whose formatter does not inherit allow_python_templates=False, allowing…

  • CVE-2026-73247HigAug 11, 2026
    risk 0.56cvss 8.6epss 0.00

    Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/HttpFunction.java passes the user-controlled http() uri argument to URI.create() and the server-side HTTP client without restricting…

  • CVE-2026-73246HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndpoint.java serves GET /worker without authentication and serializes the complete live Task object, which can expose commands,…

  • CVE-2026-73245MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut management endpoints on port 8081 without authentication even when Basic Auth protects /api/v1/** on port 8080, allowing…

  • CVE-2026-68067CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record…

  • CVE-2026-67568CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

  • CVE-2026-67558HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live…

  • CVE-2026-66875HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters) can silently rebind the device to an attacker-controlled account, extract stored hormone measurements in cleartext, cause a…

  • CVE-2026-66340MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login attempts. An attacker can use brute-force methods to obtain gain access to user accounts.

  • CVE-2026-66098MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootloader mode. An attacker could cause a denial-of-service condition or disrupt ovulation tracking and fertility monitoring workflow.

  • CVE-2026-64934MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The Mira cloud API accepts the firmware version reported by the companion app as authoritative for a given device, without independently attesting the version from the device itself. An authenticated attacker could submit arbitrary firmware version strings for their own device,…

  • CVE-2026-5917HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    libgit2 versions before 1.8.7 and 1.9.0 before 1.9.7 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that allows remote attackers to execute arbitrary commands on an SSH server by supplying a repository path containing…

  • CVE-2026-29036HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within cJSON_Utils.c that allows unauthenticated attackers to cause JSON Patch operations to target wrong object keys by supplying crafted…

  • CVE-2026-19560HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19559HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19558HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: High)

  • CVE-2026-19557HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19556HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-18710MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatically as part of normal operation and…

  • CVE-2026-71290CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the…

  • CVE-2026-66832MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query string parameter, and a persistent user identifier is included in the WebView's User-Agent header. Both are then transmitted to…

  • CVE-2026-66154HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlier versions which, under a successful MitM attack and controlled network conditions, could permit unauthorized changes.

  • CVE-2026-66150HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.

  • CVE-2026-66149HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

  • CVE-2026-66148MedAug 11, 2026
    risk 0.41cvss 6.3epss 0.01

    An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions which allows low-privileged local user to execute system commands with root privileges.

  • CVE-2026-66147CriAug 11, 2026
    risk 0.61cvss 9.4epss 0.02

    An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

  • CVE-2026-63177HigAug 11, 2026
    risk 0.39cvss 7.1epss 0.00

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evaluates the raw, unnormalized `ngx.var.request_uri`, while Nginx itself routes requests using the normalized path. An authenticated…

  • CVE-2026-63134MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags, but creates directory entries with a raw `os.makedirs(os.path.join(dest, entry.pathname))` that has no traversal protection. An…

  • CVE-2026-63133MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.01

    Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count, directory depth, total entries, or output size. A small malicious archive containing a large number of directory or file entries…

  • CVE-2026-55676HigAug 11, 2026
    risk 0.50cvss 8.8epss 0.01

    Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file…

  • CVE-2026-48765CriAug 11, 2026
    risk 0.57cvss 9.9epss 0.00

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an…

  • CVE-2026-48763HigAug 11, 2026
    risk 0.46cvss 8.2epss 0.01

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{blockId}/storage/upload-url` that accepts an attacker-controlled `filePath` and returns a presigned S3 `PUT` URL for that exact…

  • CVE-2026-48762MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using `fetch()` without applying the SSRF protection that exists elsewhere in the codebase. An attacker can direct the server to make…

  • CVE-2026-29035MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remote attackers to corrupt memory by sending compressed WebSocket frames when both USE_ZLIB and MG_EXPERIMENTAL_INTERFACES are…

  • CVE-2026-19579MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The cancel_by_admin and requestingUser values are read from user-controlled URL path segments and used without a server-side…

  • CVE-2026-19550HigAug 11, 2026
    risk 0.46cvss 8.2epss 0.00

    A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an…

  • CVE-2026-18634HigAug 11, 2026
    risk 0.55cvss 8.4epss 0.00

    An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier versions. A local attacker with the ability to interact with the service could exploit this behavior to perform unauthorized…

  • CVE-2026-15606HigAug 11, 2026
    risk 0.50cvss 8.8epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…

  • CVE-2026-14863HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.03

    FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail…

  • CVE-2026-73283LowAug 11, 2026
    risk 0.16cvss 2.5epss 0.00

    In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

  • CVE-2026-73282MedAug 11, 2026
    risk 0.31cvss 4.8epss 0.00

    In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

  • CVE-2026-73281LowAug 11, 2026
    risk 0.23cvss 3.5epss 0.00

    In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the [email protected] extension.

  • CVE-2026-73244MedAug 11, 2026
    risk 0.27cvss 5.3epss 0.00

    kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the user-controlled path parameter from FileController#getFiles to…