VYPR

CVEs

386,183 total · page 552 of 7,724

  • CVE-2026-20712MedAug 11, 2026
    risk 0.26cvss —epss 0.00

    Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via…

  • CVE-2026-0465MedAug 11, 2026
    risk 0.36cvss —epss 0.00

    A Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentially resulting in loss of availability

  • CVE-2025-54512HigAug 11, 2026
    risk 0.46cvss —epss 0.00

    A DLL hijacking vulnerability within the AMD Ryzen Master installation could allow a local user-privileged attacker to escalate privileges, potentially resulting in arbitrary code execution.

  • CVE-2025-0046HigAug 11, 2026
    risk 0.46cvss —epss 0.00

    Incorrect directory permissions could allow a local user to escalate their privileges, potentially resulting in arbitrary code execution.

  • CVE-2022-50997HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Weaver (Fanwei) E-cology 8.0 and 9.0 contains a SQL injection vulnerability in the HrmCareerApplyPerView.jsp endpoint that allows unauthenticated remote attackers to extract arbitrary data from the backend database by manipulating the id GET parameter. Attackers can send a…

  • CVE-2016-20097HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    Weaver (Fanwei) E-cology 8.0 contains a SQL injection vulnerability in the SignatureDownLoad servlet that allows unauthenticated remote attackers to read arbitrary files by injecting a UNION SELECT payload into the markId GET parameter, which is concatenated unsanitized into a…

  • CVE-2026-73089HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction,…

  • CVE-2026-73088HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted…

  • CVE-2026-73087LowAug 11, 2026
    risk 0.08cvss —epss 0.00

    Dozzle is a realtime log viewer for docker containers. From 10.5.2 until 10.6.15, the isBlockedIP SSRF guard in internal/notification/dispatcher/webhook.go, used by safeDialContext for webhook notification URLs, does not inspect IPv4 addresses embedded in 6to4, NAT64, Teredo, or…

  • CVE-2026-73086HigAug 11, 2026
    risk 0.41cvss 7.4epss 0.00

    nanoid is a secure, URL-friendly, unique string ID generator for JavaScript. Prior to versions 3.3.12 and 5.1.11, the nanoid(size) function in index.js and index.cjs coerces the user-influenced size parameter to a signed 32-bit integer, allowing a value of 2147483648 to become…

  • CVE-2026-73085MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoints such as /api/me instead of restricting…

  • CVE-2026-73084MedAug 11, 2026
    risk 0.33cvss 6.1epss 0.00

    Activepieces is an open source AI workflow automation platform. Prior to 0.83.0, the /api/redirect OAuth callback endpoint embeds the user-supplied code query parameter directly into an inline script block without proper escaping. A crafted request to /api/redirect with a…

  • CVE-2026-73083HigAug 11, 2026
    risk 0.42cvss —epss 0.00

    Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, in SANDBOX_CODE_ONLY mode, the engine loads the compiled user module with importFresh(), a wrapper around Node.js require(), before the V8 isolate is applied. Top-level module code can therefore…

  • CVE-2026-73082MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An…

  • CVE-2026-73081HigAug 11, 2026
    risk 0.50cvss —epss 0.01

    Activepieces is an open source AI workflow automation platform. Prior to 0.80.0, the worker's code-compilation pipeline builds the on-disk path for a Code step from the step's name and passes that path to a shell-invoked build command. A step name containing shell metacharacters…

  • CVE-2026-72971MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.

  • CVE-2026-71390MedAug 11, 2026
    risk 0.26cvss 4.0epss 0.00

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized limited write access. Exploitation of this issue does…

  • CVE-2026-71389MedAug 11, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-71387HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    ColdFusion is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an…

  • CVE-2026-71386HigAug 11, 2026
    risk 0.58cvss 8.8epss 0.01

    is affected by a Cross-site Scripting (XSS) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. The vulnerable component is restricted to an administrative network…

  • CVE-2026-71384CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application…

  • CVE-2026-71383HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.01

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized read and write access, causing a limited disruption to availability.…

  • CVE-2026-71331HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.01

    Integer overflow or wraparound in Windows Device Health Attestation (DHA) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70355HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70354HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Out-of-bounds write in .NET allows an unauthorized attacker to execute code locally.

  • CVE-2026-70348MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.

  • CVE-2026-70347HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70346HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70345HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Heap-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70344HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Stack-based buffer overflow in Windows Installer allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70340HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.01

    Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70338HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-70337HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Relative path traversal in Microsoft PowerShell Core allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70336HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper control of generation of code ('code injection') in Visual Studio Code allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70335HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally.

  • CVE-2026-70330MedAug 11, 2026
    risk 0.44cvss 6.7epss 0.00

    Heap-based buffer overflow in Windows DNS allows an authorized attacker to elevate privileges locally.

  • CVE-2026-70329HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network.

  • CVE-2026-70328MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-70327MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.01

    Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-70326HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70325MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70324HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.01

    Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70323MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70322MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70321HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.02

    Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2026-70320MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70319MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70318MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.01

    Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70317MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

  • CVE-2026-70316MedAug 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally.