VYPR

CVEs

386,146 total · page 550 of 7,723

  • CVE-2026-18706MedAug 11, 2026
    risk 0.43cvss 6.6epss 0.00

    An issue in MongoDB Server's $graphLookup aggregation stage could allow an authenticated user able to issue aggregation and memory-management commands to cause an internal reference to be used after the underlying memory has been freed. This could result in a server crash or,…

  • CVE-2026-18705MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view to retrieve documents from a different, protected view over the same underlying collection. This is due to insufficient handling of certain user-supplied…

  • CVE-2026-18704MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perform write operations against collections they should not be able to modify. This is due to an internal-use aggregation stage being reachable by external clients…

  • CVE-2026-18703MedAug 11, 2026
    risk 0.27cvss 4.2epss 0.00

    An issue in MongoDB Server could allow a party with a valid client certificate and a corresponding user account to authenticate using a certificate-based authentication method, even when an administrator has configured the server to restrict authentication to other mechanisms.…

  • CVE-2026-18702MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.00

    An issue in MongoDB Server could allow an authenticated user with limited, database-scoped privileges to modify diagnostic logging settings that affect the entire server rather than just the intended database. This could allow suppression of diagnostic logging server-wide,…

  • CVE-2026-18701MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server process to terminate unexpectedly by submitting a specially formed query filter. This could result in a denial of service.

  • CVE-2026-18700MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed, through concurrent operations against a collection using a certain type of validator.…

  • CVE-2026-18699MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the server process to terminate unexpectedly by submitting a specially formed query against a collection with a text index. This could result in a denial of service,…

  • CVE-2026-18698MedAug 11, 2026
    risk 0.35cvss 5.4epss 0.00

    An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that should require more specific privileges. This could result in exposure of collection metadata and, on certain…

  • CVE-2026-18697HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in MongoDB Server's aggregation framework could allow an unauthenticated party to cause a mongos (router) process to terminate unexpectedly by submitting a specially formed aggregation command. This could result in a denial of service, disrupting client connections…

  • CVE-2026-18696MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to perform certain data-definition operations, such as dropping or modifying collections, against collections they do not have permission to manipulate. This is…

  • CVE-2026-18695MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a denial of service.

  • CVE-2026-18694HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in MongoDB Server's geospatial query processing could allow an authenticated user with write privileges to cause certain malformed geometry data to be stored and later processed without proper validation. Subsequent queries against this data could then result in the…

  • CVE-2026-18693HigAug 11, 2026
    risk 0.49cvss 7.6epss 0.00

    An issue in MongoDB Server's handling of timeseries collections could allow an authenticated user with write privileges to cause an internal data structure to become inconsistent through certain document insertions. A subsequent insert into the affected bucket could then result…

  • CVE-2026-18692HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal reference to be used after the underlying memory has been freed. Subsequent operations could then result in a server crash or,…

  • CVE-2026-18691HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechanism is used when one replica set member connects to another. Under certain conditions, this could cause the cluster's shared…

  • CVE-2026-18690HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collections that their assigned privileges should not permit. This could result in critical system collections being dropped and…

  • CVE-2026-18688HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially formed numeric parameter in a certain aggregation pipeline stage. This could result in a server crash (denial of service) and may…

  • CVE-2026-18687HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection's encrypted field configuration before use. An authenticated user with readWrite privileges could submit a specially formed…

  • CVE-2026-15426HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.11.1. This is due to the plugin not properly verifying that a user is authorized…

  • CVE-2026-73219MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT job can submit a batch automatic annotation request to RequestViewSet.create with inconsistent task and job IDs, and because the…

  • CVE-2026-73218HigAug 11, 2026
    risk 0.50cvss —epss 0.01

    Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Docker Desktop and the Dev Containers CLI are installed, to launch a privileged container and mount Docker's virtiofs0, granting…

  • CVE-2026-73217HigAug 11, 2026
    risk 0.50cvss —epss 0.00

    Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to replace a virtual environment's Python executable with a malicious wrapper that the Microsoft Python extension invokes outside the…

  • CVE-2026-73216MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.01

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c prematurely calls dec_quota() and releases bandwidth accounting during the first-stage close of a mobility-enabled allocation while…

  • CVE-2026-73215HigAug 11, 2026
    risk 0.39cvss —epss 0.00

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks the unused odd sibling port as TPS_TAKEN_ODD for an EVEN-PORT Allocate request with reservation bit R=0 even though no RTCP socket…

  • CVE-2026-73214HigAug 11, 2026
    risk 0.46cvss —epss 0.01

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket() in src/apps/relay/dtls_listener.c retain OpenSSL dtls1_reassemble_fragment() state for a 35-byte fragmented ClientHello…

  • CVE-2026-73213MedAug 11, 2026
    risk 0.31cvss —epss 0.00

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-wise comparison for native IPv6 min-max intervals in ioa_addr_in_range(), allowing an authenticated TURN client to relay to an…

  • CVE-2026-73212MedAug 11, 2026
    risk 0.31cvss —epss 0.01

    Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_in_range() in src/client/ns_turn_ioaddr.c without canonicalizing IPv4-compatible, 6to4, and 64:ff9b::/96 NAT64 address forms,…

  • CVE-2026-73211CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables,…

  • CVE-2026-73090CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.00

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a…

  • CVE-2026-72713HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitrary files on the host by supplying parent-directory segments in the `file_name` form field with no path containment check.…

  • CVE-2026-72712MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.01

    Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in…

  • CVE-2026-71398CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not…

  • CVE-2026-71362CriKEVAug 11, 2026
    risk 0.64cvss 9.1epss 0.88

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

  • CVE-2026-69113MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on any private video without permission by supplying an arbitrary videoId in the request body. Attackers can inject comments into…

  • CVE-2026-69102CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers…

  • CVE-2026-65680MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

  • CVE-2026-48790MedAug 11, 2026
    risk 0.29cvss 5.5epss 0.00

    Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `settings.json` using Viper's default `configPermissions` of `0o644`, leaving the credential file world-readable on standard Linux…

  • CVE-2026-48771HigAug 11, 2026
    risk 0.53cvss 8.2epss 0.00

    ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured client-side database configuration and insufficient access control policies. Applications using publicly exposed database credentials…

  • CVE-2026-48767HigAug 11, 2026
    risk 0.42cvss 7.6epss 0.00

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the…

  • CVE-2026-48494HigAug 11, 2026
    risk 0.39cvss —epss 0.00

    TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook session that belongs to a different typebot by mixing an authorized `typebotId` and `blockId` and a foreign preview phone number…

  • CVE-2026-48447HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.00

    Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploit depends on conditions beyond the attacker's…

  • CVE-2026-48441HigAug 11, 2026
    risk 0.56cvss 8.6epss 0.00

    Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the…

  • CVE-2026-48416HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user…

  • CVE-2026-48415HigAug 11, 2026
    risk 0.49cvss 7.6epss 0.00

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, causing a limited…

  • CVE-2026-48414HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.00

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-48413HigAug 11, 2026
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-48412LowAug 11, 2026
    risk 0.18cvss 2.7epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user…

  • CVE-2026-48411MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue…

  • CVE-2026-48410HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Lightroom Classic is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.