VYPR

CVEs

386,289 total · page 589 of 7,726

  • CVE-2026-11430HigAug 7, 2026
    risk 0.40cvss 7.3epss 0.01

    Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookToken is configured, a compound conditional short-circuits and skips token validation, so an unauthenticated remote attacker who…

  • CVE-2025-71413MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased workload and reduced situational awareness. This type of attack can be carried out remotely over radio frequency.

  • CVE-2025-71412HigAug 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actions by flight crews, traffic controllers, and ground operations. This type of attack can be carried out remotely over radio…

  • CVE-2025-71411MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.

  • CVE-2025-71410MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.00

    Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC functions requiring a reversion to voice communication and increased controller workload. This type of attack can be carried out…

  • CVE-2025-71409HigAug 7, 2026
    risk 0.46cvss 7.1epss 0.00

    Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misleading clearances and potential pilot confusion. This type of attack can be carried out remotely over radio frequency.

  • CVE-2025-63235HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients send invalid CONNECT packets - either due to repeated attempts or failed authentication - the server may silently drop the…

  • CVE-2026-66058MedAug 7, 2026
    risk 0.27cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is possible for an authenticated user. This issue is fixed in versions 16.20.0 and 15.112.0.

  • CVE-2026-64638HigAug 7, 2026
    risk 0.60cvss —epss 0.01

    WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers…

  • CVE-2026-64637CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.

  • CVE-2026-64636HigAug 7, 2026
    risk 0.50cvss 7.7epss 0.00

    An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the panel database.

  • CVE-2026-56818MedAug 7, 2026
    risk 0.35cvss 6.5epss 0.00

    Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, but it does not clear the same state when…

  • CVE-2026-47364MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing opt-out. Impact: The Datadog user UUID and crash data are visible within Firebase Crashlytics. This UUID is not identifying…

  • CVE-2026-47363MedAug 7, 2026
    risk 0.41cvss 6.3epss 0.00

    In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (including OAuth tokens) from Intent extras with no permission guard, and signs the app into that session without validating it…

  • CVE-2026-47362MedAug 7, 2026
    risk 0.30cvss 4.6epss 0.00

    In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive content in plaintext: LocalNotificationDatabase (notification title, message, recipient, service, tags, and on-call/incident deep links) and SearchRecentDatabase…

  • CVE-2026-47361MedAug 7, 2026
    risk 0.42cvss 6.4epss 0.00

    In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent with a caller-supplied conversation_id. When the activity closes and no in-process session matches that ID, it unconditionally…

  • CVE-2026-44965MedAug 7, 2026
    risk 0.36cvss 5.5epss 0.00

    In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedViewWidgetActivity, OnCallShiftsWidgetActivity, OnCallPagesWidgetActivity, SloWidgetActivity, DashboardWidgetActivity) are exported…

  • CVE-2026-44964MedAug 7, 2026
    risk 0.42cvss 6.5epss 0.00

    In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-installed application can launch it with attacker-controlled Intent extras, including a full-screen lock-screen message, an…

  • CVE-2026-19229MedAug 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack…

  • CVE-2026-19213MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in WonderTrader up to 0.9.9. Affected is the function _undone_qty in the library src/WtCore/TraderAdapter.h of the component Pending Order Handler. The manipulation of the argument getUndoneQty leads to enforcement of behavioral workflow. The…

  • CVE-2026-19082HigAug 7, 2026
    risk 0.42cvss 7.5epss 0.01

    Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_string_tags. copy_string_tags() computes an ASCII EXIF tag's length as `entry->size - 1` to strip the trailing NUL. A zero-count…

  • CVE-2026-71557MedAug 7, 2026
    risk 0.34cvss 6.3epss 0.00

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before being used to construct on-disk paths under the reference storage directory, so a maliciously crafted reference name (for example…

  • CVE-2026-71556HigAug 7, 2026
    risk 0.39cvss 7.1epss 0.00

    go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, status, and add) resolve symbolic links inside the working tree without confining resolution to the worktree boundary, so a…

  • CVE-2026-68772HigAug 7, 2026
    risk 0.45cvss 8.0epss 0.01

    ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file…

  • CVE-2026-67585HigAug 7, 2026
    risk 0.50cvss —epss 0.01

    Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abort the Erlang VM via crafted _entities representation keys. Every key of every object in the representations argument of the…

  • CVE-2026-66062MedAug 7, 2026
    risk 0.27cvss 5.3epss 0.01

    SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header parser used by SvelteKit's request handling (for headers such as Accept) uses a regular expression vulnerable to quadratic…

  • CVE-2026-20348HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary…

  • CVE-2026-20347HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary…

  • CVE-2026-20346HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary…

  • CVE-2026-20345HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of…

  • CVE-2026-20339HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary…

  • CVE-2026-20338HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.00

    A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could…

  • CVE-2026-20337HigAug 7, 2026
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an…

  • CVE-2026-19212MedAug 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in WonderTrader up to 0.9.9. This impacts an unknown function of the file src/Includes/WTSTradeDef.hpp of the component TraderATP Cash Trade Conversion. Executing a manipulation of the argument m_offsetType can lead to use of uninitialized…

  • CVE-2026-19211HigAug 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. Performing a manipulation of the argument email results in sql injection. Remote exploitation of the attack is possible. The exploit…

  • CVE-2026-17603HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.00

    Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the…

  • CVE-2026-17601HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.00

    A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or…

  • CVE-2026-17600HigAug 7, 2026
    risk 0.57cvss 8.8epss 0.00

    Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these…

  • CVE-2026-17599HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.00

    Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding…

  • CVE-2026-17598MedAug 7, 2026
    risk 0.32cvss 4.9epss 0.00

    Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a…

  • CVE-2026-17597LowAug 7, 2026
    risk 0.18cvss 2.7epss 0.00

    Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user holding the nexus:settings:update permission could submit arbitrary host and port values to the email test/verification endpoint, causing the…

  • CVE-2026-17596MedAug 7, 2026
    risk 0.40cvss 6.1epss 0.00

    Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another…

  • CVE-2026-17595LowAug 7, 2026
    risk 0.18cvss 2.7epss 0.00

    Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal…

  • CVE-2026-17594MedAug 7, 2026
    risk 0.32cvss 4.9epss 0.01

    Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could…

  • CVE-2026-17593HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.01

    An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them…

  • CVE-2026-14644HigAug 7, 2026
    risk 0.47cvss 7.2epss 0.00

    Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw…

  • CVE-2026-66059MedAug 7, 2026
    risk 0.27cvss —epss 0.00

    Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, a field-level permissions bypass exposes restricted DocType fields. This issue is fixed in versions 16.23.0 and 15.112.0.

  • CVE-2026-62996MedAug 7, 2026
    risk 0.38cvss —epss 0.01

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. From 5.0.0 until 5.8.4, Smarty's stream: resource-name handling does not adequately restrict which PHP stream wrappers and filter chains can be referenced from a…

  • CVE-2026-62992MedAug 7, 2026
    risk 0.38cvss —epss 0.01

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 5.8.2 (and 4.5.7 on the 4.x line), Security::_checkDir() does not fully resolve symbolic links before validating that a requested path lies within a…

  • CVE-2026-48093MedAug 7, 2026
    risk 0.35cvss 6.5epss 0.00

    The Code Embed WordPress plugin prior to version 2.6.1 is vulnerable to stored Cross-Site Scripting (XSS) through the external URL embed feature in post content. The vulnerable code scans rendered content for URL embed tokens, fetches the remote URL, and inserts the remote…