VYPR

CVEs

386,273 total · page 564 of 7,726

  • CVE-2026-20707MedAug 11, 2026
    risk 0.44cvss —epss 0.00

    Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial…

  • CVE-2026-20705MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This…

  • CVE-2026-20702HigAug 11, 2026
    risk 0.58cvss —epss 0.00

    Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable data exposure. This result may…

  • CVE-2026-20349HigKEVAug 11, 2026
    risk 0.68cvss 8.6epss 0.01

    A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting…

  • CVE-2026-18247MedAug 11, 2026
    risk 0.34cvss —epss 0.00

    A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session.

  • CVE-2026-12571CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.03

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

  • CVE-2025-8087HigAug 11, 2026
    risk 0.46cvss —epss 0.00

    A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation process, potentially resulting in arbitrary code execution.

  • CVE-2025-61970LowAug 11, 2026
    risk 0.07cvss —epss 0.00

    Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to create arbitrary code, potentially resulting in binary hijacking.

  • CVE-2025-48506MedAug 11, 2026
    risk 0.30cvss —epss 0.00

    Uncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, potentially resulting in arbitrary code execution.

  • CVE-2025-48505LowAug 11, 2026
    risk 0.07cvss —epss 0.00

    Weak permissions in the Vitis™ Unified installation path on local Windows machines could allow a low-privileged user to achieve privileged escalation, potentially resulting in arbitrary code execution.

  • CVE-2025-35987MedAug 11, 2026
    risk 0.28cvss —epss 0.00

    Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data…

  • CVE-2025-35973MedAug 11, 2026
    risk 0.29cvss —epss 0.00

    Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result…

  • CVE-2025-31938MedAug 11, 2026
    risk 0.28cvss —epss 0.00

    Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure.…

  • CVE-2025-31936MedAug 11, 2026
    risk 0.37cvss 5.7epss 0.00

    Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of…

  • CVE-2025-31356MedAug 11, 2026
    risk 0.37cvss —epss 0.00

    Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data…

  • CVE-2025-0041MedAug 11, 2026
    risk 0.30cvss —epss 0.00

    Uncontrolled search paths in the Vitis™ Embedded Single File Download (SFD) for local Windows installation could allow a low-privileged user to create arbitrary code execution.

  • CVE-2026-9214MedAug 11, 2026
    risk 0.29cvss 4.5epss 0.00

    Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

  • CVE-2026-73080CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.01

    SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs…

  • CVE-2026-73079HigAug 11, 2026
    risk 0.48cvss 8.5epss 0.00

    Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform API keys issued to tenants are exchanged for upstream requests made with shared provider accounts (ChatGPT/Codex OAuth, OpenAI…

  • CVE-2026-73078HigAug 11, 2026
    risk 0.50cvss 8.8epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into…

  • CVE-2026-73077HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating…

  • CVE-2026-73076HigAug 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record…

  • CVE-2026-73075LowAug 11, 2026
    risk 0.25cvss 3.9epss 0.00

    Vim is an open source, command line text editor. From 9.2.0469 until 9.2.0843, popup_mark_opacity_zindex() in src/popupwin.c can use a negative w_winrow for a text-property-anchored popup with clipwindow and opacity, indexing before the screen array instead of accounting for…

  • CVE-2026-73074MedAug 11, 2026
    risk 0.37cvss 6.7epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to increment a uint16_t property count beyond 0xffff, wrapping the count to zero and copying existing text-property records into a…

  • CVE-2026-73072HigAug 11, 2026
    risk 0.40cvss 7.3epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping…

  • CVE-2026-73071LowAug 11, 2026
    risk 0.14cvss 3.3epss 0.00

    Vim is an open source, command line text editor. From 9.2.0511 until 9.2.0844, json_decode_item() in src/json.c can retain a stale pointer after json_decode_string() invokes channel_fill() to refill and free the current buffer, causing the error path to read freed memory instead…

  • CVE-2026-73070MedAug 11, 2026
    risk 0.29cvss 5.5epss 0.00

    Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connections in socketserver_accept(), causing descriptors to overflow fd_set structures in src/channel.c and fixed-size struct pollfd…

  • CVE-2026-73069CriAug 11, 2026
    risk 0.52cvss 9.1epss 0.01

    Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id…

  • CVE-2026-73068MedAug 11, 2026
    risk 0.31cvss 5.9epss 0.00

    ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database HTTP API in server/src/modules/tooljet-db/controller.ts authorizes operations against the :organizationId URL…

  • CVE-2026-6727MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to…

  • CVE-2026-6726HigAug 11, 2026
    risk 0.51cvss 7.9epss 0.00

    An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and…

  • CVE-2026-67180HigAug 11, 2026
    risk 0.48cvss 8.4epss 0.00

    Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evidence path/name obtains code execution on the worker fleet. Fixed on 2026-07-10.

  • CVE-2026-67179HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the…

  • CVE-2026-56721HigAug 11, 2026
    risk 0.50cvss 8.8epss 0.01

    CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the…

  • CVE-2026-56720MedAug 11, 2026
    risk 0.21cvss 4.3epss 0.00

    CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can send a GET request to the…

  • CVE-2026-53416HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access.

  • CVE-2026-53415HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access.

  • CVE-2026-53414MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access.

  • CVE-2026-53413HigAug 11, 2026
    risk 0.54cvss 8.3epss 0.00

    Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.

  • CVE-2026-48766HigAug 11, 2026
    risk 0.42cvss 7.6epss 0.00

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible API keys by invoking the OpenAI model-listing helper with an attacker-controlled `baseUrl`. The vulnerable path decrypts the…

  • CVE-2026-48495HigAug 11, 2026
    risk 0.39cvss 7.1epss 0.00

    TypeBot is a chatbot builder tool. Prior to version 3.17.0, the Google Sheets OAuth callback decodes a base64-encoded JSON `state` parameter and trusts the embedded `workspaceId`, `typebotId`, `blockId`, and `redirectUrl` without cryptographic integrity protection or…

  • CVE-2026-42142HigAug 11, 2026
    risk 0.39cvss 7.1epss 0.00

    TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handleGetSheets` API handler (`POST /api/sheets/getSheets`) does not validate workspace membership, allowing any authenticated user to access and decrypt another workspace's Google Sheets OAuth credentials and…

  • CVE-2026-19546HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19546.

  • CVE-2026-19078MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user,…

  • CVE-2026-18640HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook record outside the org's data store directory. The file written must have an extension of ".json.db" but can otherwise overwrite…

  • CVE-2026-18639HigAug 11, 2026
    risk 0.47cvss 7.3epss 0.00

    When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change the email claim without verification. Some IdPs do not set the "email_verified" claim and do not actually verify the email. This…

  • CVE-2026-18638MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by calling SetPassword with a username that does not exist.

  • CVE-2026-14180MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By…

  • CVE-2026-11814MedAug 11, 2026
    risk 0.44cvss 6.8epss 0.01

    A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited…

  • CVE-2026-11739MedAug 11, 2026
    risk 0.42cvss 6.4epss 0.01

    A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device.