VYPR

CVEs

37,387 total · page 6 of 748

  • CVE-2026-61594CriSep 16, 2026
    risk 0.52cvss 9.1epss 0.00

    djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the live (WebSocket) transport authorizes a mount via `check_view_auth`, not Django's `View.dispatch()` chain. As a result, standard Django…

  • CVE-2026-92805CriSep 16, 2026
    risk 0.57cvss 9.8epss 0.00

    UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to…

  • CVE-2026-92787CriSep 16, 2026
    risk 0.57cvss 9.8epss 0.00

    Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain…

  • CVE-2026-76460CriKEVSep 16, 2026
    risk 0.77cvss 10.0epss 0.01

    A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by…

  • CVE-2026-75513CriSep 16, 2026
    risk 0.52cvss 9.1epss 0.00

    Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. From version 7.0.0 until 9.13.0, several Marten LINQ and tenant-management paths interpolate runtime, potentially attacker-controlled strings into single-quoted SQL literals without escaping or…

  • CVE-2026-20332CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a…

  • CVE-2026-20284CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by…

  • CVE-2025-56563CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts an attacker-controlled address URL parameter and passes it to curl_setopt(CURLOPT_URL) without host or scheme validation. An unauthenticated remote attacker…

  • CVE-2026-92808CriSep 16, 2026
    risk 0.65cvss —epss 0.00

    A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP requests to a destination of the attacker's choosing, including internal services…

  • CVE-2026-89083CriSep 16, 2026
    risk 0.60cvss —epss 0.01

    HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

  • CVE-2026-89082CriSep 16, 2026
    risk 0.60cvss —epss 0.01

    HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, remote code execution, or arbitrary file write under certain conditions, impacting the HP Advance server hosting the software.

  • CVE-2026-88592CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.00

    kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filter is not the same parameter the…

  • CVE-2026-76423CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authorization checks. An…

  • CVE-2026-20341CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.00

    A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software could allow an authenticated, remote attacker to obtain root privileges. This vulnerability is due to unsecured deserialization of untrusted data over the sftunnel management…

  • CVE-2026-20330CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a…

  • CVE-2026-20329CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a…

  • CVE-2026-20326CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered…

  • CVE-2026-20325CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally…

  • CVE-2026-20324CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.00

    A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has…

  • CVE-2026-20322CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally…

  • CVE-2026-20242CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure…

  • CVE-2026-20237CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a…

  • CVE-2026-20211CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This…

  • CVE-2026-20194CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a…

  • CVE-2026-20192CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a…

  • CVE-2026-20176CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative credentials. This…

  • CVE-2026-20130CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review resulted in a…

  • CVE-2026-91106CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91105CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91104CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91103CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91102CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91101CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91100CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91099CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91098CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-91097CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file…

  • CVE-2026-73456CriSep 16, 2026
    risk 0.65cvss 10.0epss 0.01

    Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an unauthenticated gNPSI client can craft a malicious request to allow arbitrary code execution, granting an attacker full administrative control…

  • CVE-2026-68536CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    Server-Side Request Forgery / Local File Inclusion in Apache MyFace Core. Older unsupported versions may also be affected.  Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue.

  • CVE-2026-92720CriSep 16, 2026
    risk 0.52cvss 9.1epss 0.00

    Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored credentials and register malicious webhooks to intercept pipeline events or…

  • CVE-2026-92717CriSep 16, 2026
    risk 0.52cvss 9.1epss 0.00

    Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can use the obtained token to authenticate against the entire operator API and…

  • CVE-2026-92716CriSep 16, 2026
    risk 0.55cvss 9.6epss 0.00

    Shuffle through 2.2.1 contains a cross-tenant privilege escalation vulnerability in the HandleApiGeneration endpoint that allows administrators to reset and read API keys of non-administrator users in other organizations. Attackers with admin privileges in one organization can…

  • CVE-2026-51990CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary code via the biz_helper.exe component

  • CVE-2026-92398CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.02

    A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality of the file /etc/rg_config/admin of the component user_list_note Module. Performing a manipulation of the argument Name results in os command injection. It is…

  • CVE-2026-85385CriSep 16, 2026
    risk 0.55cvss 9.6epss 0.00

    Concrete CMS below 9.5.4 did not validate the user timezone value (uTimezone) on write and rendered it without output encoding on the Dashboard user management page, where Date::getTimezoneDisplayName() returns any non-IANA value unchanged. A stored cross-site scripting payload…

  • CVE-2026-76420CriSep 16, 2026
    risk 0.59cvss 9.0epss 0.00

    A vulnerability in the internal configuration of the Apache JServ Protocol (AJP) connector for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to impersonate a peer device. This vulnerability is due to incorrect initialization of encryption…

  • CVE-2026-20331CriSep 16, 2026
    risk 0.62cvss 9.6epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a…

  • CVE-2026-20307CriSep 16, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least low-privileged…

  • CVE-2026-20306CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid…

  • CVE-2026-20305CriSep 16, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid…