VYPR

CVEs

386,273 total · page 565 of 7,726

  • CVE-2026-11738MedAug 11, 2026
    risk 0.29cvss 4.4epss 0.00

    Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.

  • CVE-2026-11737MedAug 11, 2026
    risk 0.29cvss 4.5epss 0.00

    Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality.

  • CVE-2026-11736MedAug 11, 2026
    risk 0.32cvss 4.9epss 0.01

    A stack-based buffer overflow vulnerability affects certain NETGEAR models allowing an authenticated admin user to make unauthorized modification to router software and functionality.

  • CVE-2026-11735MedAug 11, 2026
    risk 0.32cvss 4.9epss 0.01

    A stack-based buffer overflow vulnerability affects the listed NETGEAR models allowing an authenticated admin user to make unauthorized modification to the router's software and functionality.

  • CVE-2026-11734LowAug 11, 2026
    risk 0.18cvss 2.7epss 0.01

    A buffer overflow vulnerability in the listed NETGEAR models allows an authenticated admin user to cause the affected device to become temporarily unavailable.

  • CVE-2026-11733MedAug 11, 2026
    risk 0.32cvss 4.9epss 0.01

    A buffer overflow vulnerability in the listed NETGEAR models allows a device administrator to temporarily interrupt the normal operation of the affected device.

  • CVE-2025-31114CriAug 11, 2026
    risk 0.54cvss —epss 0.01

    Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the…

  • CVE-2026-73067MedAug 11, 2026
    risk 0.37cvss —epss 0.00

    Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run, after which SquishedDawg::Load calls…

  • CVE-2026-73066MedAug 11, 2026
    risk 0.37cvss —epss 0.00

    Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution…

  • CVE-2026-72925MedAug 11, 2026
    risk 0.33cvss 6.1epss 0.00

    SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_minifier 59.0.0, the minifyJson processing in crates/swc_html_minifier/src/lib.rs parsed and serialized attacker-controlled JSON in application/json and…

  • CVE-2026-72922HigAug 11, 2026
    risk 0.46cvss 8.2epss 0.00

    AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected…

  • CVE-2026-72921HigAug 11, 2026
    risk 0.46cvss 8.1epss 0.00

    SeaweedFS is a distributed storage system. Prior to 4.24, the weed/server/filer_server_handlers.go allowed_prefixes authorization check used strings.HasPrefix on raw path strings, so a filer JWT scoped to /tenant1 also authorized sibling paths such as /tenant1234, /tenant1-old,…

  • CVE-2026-72920CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser,…

  • CVE-2026-47702CriAug 11, 2026
    risk 0.52cvss —epss 0.00

    TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or…

  • CVE-2026-18860HigAug 11, 2026
    risk 0.50cvss 8.7epss 0.00

    Velociraptor allows multi-tenant deployments named "Orgs". By default Velociraptor, uses the ROOT org, but users can create child orgs for other tenants within the same deployment. Users can have different permissions in each org. To manage Orgs, Velociraptor usually examines…

  • CVE-2026-18636MedAug 11, 2026
    risk 0.44cvss 6.8epss 0.00

    The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or accessing other orgs, the requested path is prefix checked against a list of denied prefixes. This prefix check can be bypassed…

  • CVE-2026-18635HigAug 11, 2026
    risk 0.47cvss 7.2epss 0.00

    Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, the calling user needs to have the IMPERSONATE permission (usually only given to administrators). Velociraptor versions prior to…

  • CVE-2026-18129HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.01

    Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

  • CVE-2026-18127HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.01

    External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.

  • CVE-2026-18125HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.

  • CVE-2026-17535MedAug 11, 2026
    risk 0.40cvss 6.2epss 0.00

    Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS images. Typically Velociraptor's NTFS parser is used on live NTFS filesystems, limiting the opportunity of attackers corrupting the…

  • CVE-2026-17061CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.

  • CVE-2023-54374Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2023-54373Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2023-54372Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2023-54371Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2023-54370Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2023-54369Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2023-54368Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2023-54367Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2022-50974Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47995Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47994Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47993Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47992Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47991Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47990Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47989Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2021-47988Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37265Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37264Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37263Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37262Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37261Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37260Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37259Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37258Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2020-37257Aug 11, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected.

  • CVE-2026-73210MedAug 11, 2026
    risk 0.26cvss —epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup option was enabled. PlaywrightCapture implements this option to prevent captures from accessing local, loopback, or otherwise non-public network resources.…

  • CVE-2026-51584CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/router/api/v1/auth_service.go, because SSO identity is matched only on an attacker-controllable identifier without binding to the IdP's…