VYPR

CVEs

37,846 total · page 58 of 757

  • CVE-2026-73602CriAug 13, 2026
    risk 0.57cvss 9.9epss 0.01

    Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code by exploiting moment locale validation bypass. Attackers can craft a fake String object with a match function that bypasses path…

  • CVE-2026-73487CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.01

    Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate…

  • CVE-2026-59507CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    : Use of Hard-coded Credentials : Exposure of Sensitive Information to an Unauthorized Actor : Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP…

  • CVE-2026-59506CriAug 13, 2026
    risk 0.60cvss 9.3epss 0.00

    : Missing Authentication for Critical Function vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

  • CVE-2026-59504CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.00

    : Client-Side Enforcement of Server-Side Security vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

  • CVE-2026-59503CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.00

    : Exposure of Sensitive Information to an Unauthorized Actor : Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority…

  • CVE-2026-59500CriAug 13, 2026
    risk 0.65cvss 10.0epss 0.01

    : Improper Authentication vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions). This issue affects Portal Generator addon to Priority ERP (developed by Soft Solutions): All versions without Priwall v3.

  • CVE-2026-15413CriAug 13, 2026
    risk 0.65cvss 10.0epss 0.01

    The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp-json/link-factory/v1/ - authenticated by a detached Ed25519 signature verified against a hardcoded operator public key (except…

  • CVE-2026-14182CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.01

    The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, relying on a loose comparison that an attacker can satisfy with a crafted value type, allowing unauthenticated users to verify and…

  • CVE-2026-49819CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.01

    UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerInitSuperuser` (`backend/pb/handlers.go:249`), reachable as `POST /api/upsnap/init-superuser`. The vulnerable code lacks any…

  • CVE-2026-16770CriAug 13, 2026
    risk 0.64cvss 9.8epss 0.01

    PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through…

  • CVE-2026-71193CriAug 12, 2026
    risk 0.55cvss 9.6epss 0.01

    In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the target pool only. An authenticated user can bypass these checks by scheduling a zone to a different pool via the AttributeFilter…

  • CVE-2026-49481CriAug 12, 2026
    risk 0.55cvss 9.6epss 0.01

    UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be…

  • CVE-2026-73519CriAug 12, 2026
    risk 0.57cvss 9.8epss 0.01

    WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs, allowing remote unauthenticated attackers to bypass authentication by supplying this value in the X-WolfStack-Secret header to…

  • CVE-2026-73501CriAug 12, 2026
    risk 0.52cvss 9.1epss 0.01

    kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without checking credentials. This substitution…

  • CVE-2026-71471CriAug 12, 2026
    risk 0.59cvss 9.0epss 0.01

    A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` field. This allows the attacker to deploy an…

  • CVE-2026-18749CriAug 12, 2026
    risk 0.57cvss 9.8epss 0.01

    The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefact that has NOT been marked shared is still retrievable by any case member who has (or is sent) its uuid — leaks not-yet-released…

  • CVE-2024-27253CriAug 12, 2026
    risk 0.65cvss 10.0epss 0.01

    IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

  • CVE-2026-66898CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing or restoring a backup archive, LXD fails to validate instance and storage volume names contained within the archive metadata. An…

  • CVE-2026-19001CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, schema, or object name to a metadata retrieval function. This may result in memory corruption within the calling application's…

  • CVE-2026-73414CriAug 12, 2026
    risk 0.53cvss —epss 0.01

    Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(` and `)` when applications use the escape or escapeAll APIs on Windows with shell set to cmd.exe, or with shell set to true when…

  • CVE-2026-73407CriAug 12, 2026
    risk 0.52cvss —epss 0.01

    Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials from getAuthHeaders and defaultHeaders without requiring the final request destination to match the datasource origin. An…

  • CVE-2026-73269CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to escalate their privileges from…

  • CVE-2026-73268CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate…

  • CVE-2026-72508CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a namespace-admin tenant to perform a confused-deputy attack by creating Subscription Custom Resources (CRs) that leverage a highly…

  • CVE-2026-63300CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_create_instances permissions on a restricted project to bypass project-level security restrictions. When migrating an instance…

  • CVE-2026-63299CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail to verify resource limits during volume operations: the storagePoolVolumeTypePostMove function omits the…

  • CVE-2026-63298CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inject arbitrary configuration directives. By supplying newline characters within the 'nvidia.driver.capabilities' or…

  • CVE-2026-63297CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target project restrictions during cross-project instance copies. When copying an instance to a target project, LXD performs restriction…

  • CVE-2026-63296CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.00

    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When migrating an instance to a target project, LXD accepts configuration overrides without validating the new configuration against the…

  • CVE-2026-63294CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link.…

  • CVE-2026-63293CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or unpacking an image archive, LXD fails to validate whether the metadata.yaml file is a symbolic link. An attacker can exploit this…

  • CVE-2026-62420CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project instance migrations. When moving an instance cross-project to a different cluster member via POST /1.0/instances/{name} with…

  • CVE-2026-19656CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code…

  • CVE-2026-17083CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

  • CVE-2026-73300CriAug 12, 2026
    risk 0.55cvss 9.6epss 0.01

    Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input…

  • CVE-2026-73299CriAug 12, 2026
    risk 0.58cvss 10.0epss 0.02

    Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and…

  • CVE-2026-17276CriAug 12, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high-authority threads.

  • CVE-2026-17218CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

  • CVE-2026-16956CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16860CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

  • CVE-2026-73296CriAug 12, 2026
    risk 0.54cvss 9.4epss 0.04

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and create_mobile_action_server in ufo/client/mcp/http_servers/mobile_mcp_server.py exposed Streamable HTTP MCP services on TCP ports…

  • CVE-2026-73240CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • CVE-2026-73294CriAug 12, 2026
    risk 0.57cvss 9.9epss 0.01

    Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controlled --upload-pack option to CmdGitClient.GetLastRemoteCommitHash through POST /api/project/{id}/repositories and scheduled…

  • CVE-2026-64639CriAug 12, 2026
    risk 0.60cvss —epss 0.01

    Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute arbitrary code on behalf of the database server administrator.

  • CVE-2026-73263CriAug 12, 2026
    risk 0.57cvss 9.9epss 0.01

    Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp auth-provider with config.cmd-path and config.cmd-args because kubeconfig_contains_exec_auth in…

  • CVE-2026-50561CriAug 12, 2026
    risk 0.61cvss 9.4epss 0.01

    Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authentication mechanism contains a flaw. In affected versions, the system does not sufficiently validate the identity token in the…

  • CVE-2025-59324CriAug 12, 2026
    risk 0.59cvss 9.1epss 0.00

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file integrity checks are skipped.

  • CVE-2025-59321CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows the TPM to be unsealed via an unintended execution path or from another hardware platform.

  • CVE-2026-67285CriAug 12, 2026
    risk 0.60cvss —epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.