VYPR

CVEs

386,273 total · page 568 of 7,726

  • CVE-2026-50237HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined…

  • CVE-2026-50236HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's…

  • CVE-2026-13739CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrary target URLs. Software customers upgrade to resolved maintenance release. Update Command Center.

  • CVE-2026-13738CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents,…

  • CVE-2026-13737CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance release. Update all Commvault installations, including Commserve, Webserver, Command Center, Media Agents, Clients and HyperScale…

  • CVE-2026-58231CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components,…

  • CVE-2026-73162MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/delete_notification * /account/mark_notification_read * /account/mark_all_read These endpoints require…

  • CVE-2026-33922MedAug 11, 2026
    risk 0.39cvss 6.0epss 0.00

    A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an input parameter. A local user with administrative credentials for the web interface could submit an archive name containing…

  • CVE-2026-33921MedAug 11, 2026
    risk 0.34cvss 5.2epss 0.00

    The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privileges could use the…

  • CVE-2026-73161MedAug 11, 2026
    risk 0.26cvss —epss 0.00

    Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function previously returned the underlying text directly when no search query was supplied, or performed a regex replacement that…

  • CVE-2026-73160HigAug 11, 2026
    risk 0.50cvss —epss 0.00

    Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation routine checked whether a supplied hostname was itself an IP literal and rejected private, loopback, link-local, or reserved IPs.…

  • CVE-2026-73159MedAug 11, 2026
    risk 0.26cvss —epss 0.00

    Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() previously constructed an HTML string directly from the icon value: Because the icon is…

  • CVE-2026-73158MedAug 11, 2026
    risk 0.26cvss —epss 0.00

    Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are later consumed by Pivotick, and Pivotick interprets svgIcon as HTML. Because saved configurations may be created by one user and…

  • CVE-2026-73157LowAug 11, 2026
    risk 0.08cvss —epss 0.00

    Affected versions of cti-transmute render data obtained from a remote MISP instance into the event-browser interface using HTML interpolation. Because fields such as event IDs, event information, organization names, tags, tag colors, TLP labels, distribution labels, and…

  • CVE-2026-72694HigAug 11, 2026
    risk 0.46cvss 7.1epss 0.00

    A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a symlink in the process ID (PID) file path,…

  • CVE-2026-72693HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc//fd/0")`. `stat()` on…

  • CVE-2026-71218MedAug 11, 2026
    risk 0.27cvss 5.3epss 0.01

    A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-controlled message length and allocates memory without an upper bound. This allows the attacker to trigger excessive memory consumption,…

  • CVE-2026-71217HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to…

  • CVE-2026-15567HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size.

  • CVE-2026-15565HigAug 11, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a…

  • CVE-2026-15563HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

  • CVE-2026-15562HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service.

  • CVE-2026-15561HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service.

  • CVE-2026-15560HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.01

    when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security…

  • CVE-2026-15556HigAug 11, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application.

  • CVE-2026-15555HigAug 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.

  • CVE-2026-15554HigAug 11, 2026
    risk 0.48cvss 7.4epss 0.00

    the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509…

  • CVE-2026-10579CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.00

    A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could lead to information disclosure, access to…

  • CVE-2026-73156MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice names may originate directly from STIX or MISP data, including STIX types, relationship_type, pattern prefixes, and MISP category/type…

  • CVE-2026-73155MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users are authorized to view the target comment. The vulnerable react() handler passed an attacker-controlled comment_id directly to…

  • CVE-2026-73140MedAug 11, 2026
    risk 0.27cvss —epss 0.00

    Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal comment retrieval filters comments according to conversion visibility, comment privacy, ownership, authorship, and administrative…

  • CVE-2026-19519MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in claircore's RPM package scanner. Crafted RPM header data in a container layer can cause an unchecked type assertion to panic the scanner. The panic is not recovered, causing the Clair indexer process to crash, leading to a denial of service.

  • CVE-2026-19418HigAug 11, 2026
    risk 0.40cvss —epss 0.00

    The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving the backend and Install Tool applications from the site's main entry script instead of the dedicated typo3/ directory. Whether a…

  • CVE-2026-19518MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.

  • CVE-2026-19517MedAug 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

  • CVE-2026-19391MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. This allows SSSD LDAP bind passwords (ldap_default_authtok) and Pacemaker fence device credentials to be included in cleartext in…

  • CVE-2026-16053HigAug 11, 2026
    risk 0.55cvss 8.5epss 0.02

    Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exchange Online backup module.

  • CVE-2026-8158MedAug 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively affects the tools used for the validation of signed content. The AXIS OS device's signed video functionality remains unaffected.

  • CVE-2026-6505MedAug 11, 2026
    risk 0.33cvss 5.1epss 0.00

    The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…

  • CVE-2026-6181MedAug 11, 2026
    risk 0.38cvss 5.9epss 0.00

    The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer-privileged service account.

  • CVE-2026-5304MedAug 11, 2026
    risk 0.37cvss 5.7epss 0.00

    An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to…

  • CVE-2026-5303MedAug 11, 2026
    risk 0.37cvss 5.7epss 0.00

    The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an…

  • CVE-2026-4757HigAug 11, 2026
    risk 0.47cvss 7.2epss 0.01

    A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can only be exploited after authenticating with an administrator-privileged service account.

  • CVE-2026-19516CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance,…

  • CVE-2026-18348MedAug 11, 2026
    risk 0.20cvss 4.1epss 0.00

    Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound network connections from the Velociraptor server, bypassing the NETWORK ACL permission boundary. This…

  • CVE-2026-14549MedAug 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.

  • CVE-2026-14548MedAug 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary…

  • CVE-2026-13716CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary paths permitted to the Crafty Controller application and perform remote code execution.

  • CVE-2026-12052MedAug 11, 2026
    risk 0.27cvss 5.2epss 0.00

    The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size response for the GET_NTB_PARAMETERS (28-byte struct ntb_parameters) and GET_NTB_INPUT_SIZE (8-byte struct ntb_input_size) class requests…

  • CVE-2026-12051MedAug 11, 2026
    risk 0.23cvss 4.6epss 0.00

    The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer dereference in handle_download() (subsys/usb/device_next/class/usbd_dfu.c). The handler computes MIN(setup->wLength, buf->len) and passes buf->data to the image…