VYPR

CVEs

386,559 total · page 612 of 7,732

  • CVE-2026-71268CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.01

    OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory. A path-validation function,…

  • CVE-2026-71267CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a stack-allocated mtar_header_t via strcpy(h.name, name), with no check that strlen(name) is less than 100 before the copy.

  • CVE-2026-71266HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer via memcpy(linebuf, p, p_len), guarded only by . The identical vulnerable pattern is duplicated in a second function in the same…

  • CVE-2026-71265HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mochadbuffer into a fixed 50-byte stack buffer tempRFSECbuf using strcpy with no length check, across three separate code branches…

  • CVE-2026-71264HigAug 5, 2026
    risk 0.53cvss 8.2epss 0.00

    WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated…

  • CVE-2026-71263CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.01

    The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit.

  • CVE-2026-71262CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersController, TenantsController, etc.), and no global authorization FallbackPolicy is configured in Startup.cs, leaving its…

  • CVE-2026-71261HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chunk, a stage-1 capacity estimate truncates the 64-bit W64 chunk sizeInBytes to size_t before dividing by DRWAV_CUE_POINT_BYTES; on…

  • CVE-2026-71260MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_server.cpp), a text entity configured with mode: password (TEXT_MODE_PASSWORD) has its JSON "state" field correctly masked as…

  • CVE-2026-71259HigAug 5, 2026
    risk 0.56cvss 8.6epss 0.00

    ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than , any file: URI passes validation regardless of netloc. This validator gates the field of the external_components YAML directive's…

  • CVE-2026-71227MedAug 5, 2026
    risk 0.26cvss 5.1epss 0.00

    A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This…

  • CVE-2026-71226HigAug 5, 2026
    risk 0.40cvss 7.3epss 0.00

    Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

  • CVE-2026-71225MedAug 5, 2026
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A…

  • CVE-2026-16022HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.01

    @oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through string concatenation and executes them with execSync(). A user-controlled project-name argument is inserted into the shell command…

  • CVE-2026-0516MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header and redirect firewall management users to arbitrary web domains.

  • CVE-2026-71256CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_device_identification_res in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The…

  • CVE-2026-71255HigAug 5, 2026
    risk 0.56cvss 8.6epss 0.00

    nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the…

  • CVE-2026-71254CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's…

  • CVE-2026-64582HigAug 5, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: …

  • CVE-2026-61891HigAug 5, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend exposes HTTP file-download endpoints (`GET /file`, `GET /files/`, `PUT /files/`) that convert a client-supplied URI directly to a filesystem path and stream the file, without confining it to…

  • CVE-2026-46581HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, allowing an attacker to specify a URL to a remote Facelet which will be included and processed as part of the normal request, with the…

  • CVE-2026-18933HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.01

    The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no…

  • CVE-2026-71252HigAug 5, 2026
    risk 0.53cvss 8.2epss 0.01

    toner-management's admin state-changing handlers (add.php, edit.php, delete.php under admin/toners, admin/toner-brands, admin/printers, and related admin subdirectories) executed INSERT/UPDATE/DELETE database operations with no authentication or authorization check, while access…

  • CVE-2026-71251MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth middleware) fetched the requested Media record by ID with no verification that it belonged to the requesting portal customer's own…

  • CVE-2026-71250MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Firefly III's webhook URL validator (IsValidWebhookUrl.php) filters most private/reserved IPv4 ranges but contains an explicit early-return that allows any resolved address in 127.0.0.0/8, permitting an authenticated user (with webhooks enabled, which is off by default) to…

  • CVE-2026-71249MedAug 5, 2026
    risk 0.40cvss 6.1epss 0.00

    299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, firstname, email, message) into the page template with no sanitization. The template engine's variable output function (common/Template.php, _show_var) echoes…

  • CVE-2026-71248CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * from user where email = '' and password = ''", with no escaping or parameterization, allowing authentication bypass via a payload…

  • CVE-2026-71247MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any later-or-equal-order, not-yet-signed recipient in the same envelope, with no restriction on field type. A newer V2…

  • CVE-2026-71246MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Pixelfed's SearchController (behind the auth middleware) accepts a URL via its remote-search parameters and fetches it server-side through ActivityPubFetchService, whose validateUrl only blocks the literal hosts 127.0.0.1, localhost, and ::1 and requires https, without checking…

  • CVE-2026-71245Aug 5, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

  • CVE-2026-71244MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, account_type, refresh_token, and expiration from that existing account while allowing the caller to supply a different imap_server,…

  • CVE-2026-71243HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd = "mkdir -p " + path.join(info.destination, info.name) + "; " - and executes the resulting string through a shell via ssh2-exec…

  • CVE-2026-71242HigAug 5, 2026
    risk 0.54cvss 8.3epss 0.00

    Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of one company can…

  • CVE-2026-71241HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required decorator that protects sibling routes (/search_student, /storage) in the same file. Because card_id values are sequential integers,…

  • CVE-2026-71240MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    DjangoCRM's toggle_default_sorting view is the only route in common/urls.py that is not wrapped in login_required or staff_member_required, and it redirects to a caller-supplied next_url GET parameter after only checking secure_url(next_url), which merely verifies the target…

  • CVE-2026-71239HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, in at least three locations: message_previews.py builds an f-string embedding message.subject/message.content directly into a…

  • CVE-2026-71238CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Since this key is used for session signing, CSRF token generation, and password reset tokens, anyone who reads the public repository…

  • CVE-2026-71237CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates it into a raw SQL string: mysql_query("select * from userlists where username='' and password='' limit 1"). An unauthenticated…

  • CVE-2026-71236HigAug 5, 2026
    risk 0.57cvss 8.7epss 0.00

    Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPurifier, then manually reverses HTML-entity encoding of the resulting output by replacing <, >, and & back to…

  • CVE-2026-71235HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. The Lua script engine (re/lua.go) performs no input validation at all and preloads dangerous libraries: db (arbitrary database…

  • CVE-2026-71234HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) accepts a query parameter and grants access whenever the parameter is simply non-empty (len(secureToken) > 0), without comparing it…

  • CVE-2026-71233HigAug 5, 2026
    risk 0.57cvss 8.7epss 0.00

    InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (resources/views/portal/ninja2020/invoices/includes/terms.blade.php) with no HTML sanitization.

  • CVE-2026-71232HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.01

    MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function,…

  • CVE-2026-71231CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='' after base64-decoding the client-supplied lastLogin cookie via safe_decode, which performs URL-safe base64 decoding with no sanitization…

  • CVE-2026-66747CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name…

  • CVE-2026-60009HigAug 5, 2026
    risk 0.50cvss 8.8epss 0.00

    In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, {…

  • CVE-2026-17578LowAug 5, 2026
    risk 0.15cvss —epss 0.00

    Kong Event Gateway versions 1.0.0 through 1.1.1 and 1.2.0 do not enforce key rotation before reaching NIST SP 800-38D recommended usage limit for AES-GCM encryption keys with random nonces when the AWS IAM encryption feature is enabled. If a producer sends messages at a…

  • CVE-2026-14574MedAug 5, 2026
    risk 0.35cvss 6.5epss 0.00

    In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by…

  • CVE-2026-14304MedAug 5, 2026
    risk 0.36cvss 5.5epss 0.00

    In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this…

  • CVE-2026-12609HigAug 5, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP endpoint, which resolves the requested file path with `path.resolve(localPath, filePath)` without verifying that the resolved path…