VYPR

CVEs

37,851 total · page 62 of 758

  • CVE-2026-55799CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

  • CVE-2026-44416CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

  • CVE-2026-42537CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

  • CVE-2026-40920CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

  • CVE-2026-32227CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the issue.

  • CVE-2026-28672CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.03

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.

  • CVE-2026-66915CriAug 10, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.

  • CVE-2026-19089CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files…

  • CVE-2026-19053CriAug 10, 2026
    risk 0.59cvss 9.1epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.

  • CVE-2026-16299CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2026-16298CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2026-19348CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.04

    A security flaw has been discovered in Shenzhen Aitemi M300 Wi-Fi Repeater r0-ea7890a. Impacted is the function sprintf of the file /protocol.csp?fname=net&opt=smacfilter_conf&function=set&act=add&name=test&enable=1. Performing a manipulation of the argument enable/name/mac…

  • CVE-2026-18473CriAug 9, 2026
    risk 0.59cvss 9.1epss 0.00

    The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

  • CVE-2026-15038CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.01

    The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an…

  • CVE-2026-71993CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and…

  • CVE-2026-71992CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the macfilter function to inject malicious commands and…

  • CVE-2026-71991CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability…

  • CVE-2026-71990CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through…

  • CVE-2026-71989CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71988CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71987CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute…

  • CVE-2026-71986CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute…

  • CVE-2026-71985CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol…

  • CVE-2026-71984CriAug 9, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and…

  • CVE-2026-71983CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.02

    MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit…

  • CVE-2026-71958CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary…

  • CVE-2026-71957CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.01

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by…

  • CVE-2026-71956CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command…

  • CVE-2026-71955CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and…

  • CVE-2026-71954CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid…

  • CVE-2026-71953CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in…

  • CVE-2026-71952CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in…

  • CVE-2026-71951CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in…

  • CVE-2026-71950CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting…

  • CVE-2026-71949CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue…

  • CVE-2026-71948CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting…

  • CVE-2026-71947CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer…

  • CVE-2026-71946CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting…

  • CVE-2026-71945CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field,…

  • CVE-2026-71944CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.03

    D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field,…

  • CVE-2026-68082CriAug 8, 2026
    risk 0.57cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads:…

  • CVE-2026-14526CriAug 8, 2026
    risk 0.64cvss 9.8epss 0.01

    The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-46409CriAug 7, 2026
    risk 0.55cvss 9.6epss 0.00

    OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak desktop backend binds an HTTP API to `127.0.0.1:` (commonly 19141) without server-side Origin validation, loopback…

  • CVE-2026-48170CriAug 7, 2026
    risk 0.52cvss 9.1epss 0.00

    `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototype.someProp` is set process-wide,…

  • CVE-2026-47243CriAug 7, 2026
    risk 0.53cvss —epss 0.00

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to 3.31.0, the runtime-rs standalone virtio-fs path is vulnerable to a guest-root to host-root escape. In this configuration,…

  • CVE-2026-50540CriAug 7, 2026
    risk 0.55cvss 9.6epss 0.01

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Prior to version 4.0.0, kata-runtime is vulnerable to host code execution via an unvalidated configuration path annotation. The…

  • CVE-2026-61808CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.03

    LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication disabled by default, allowing an unauthenticated network attacker to read indexed document content, upload or…

  • CVE-2026-48039CriAug 7, 2026
    risk 0.52cvss 9.1epss 0.01

    Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at `http_auth_integration.py:272` unconditionally forwards unauthenticated Streamable HTTP requests to downstream MCP tool…

  • CVE-2026-71851CriAug 7, 2026
    risk 0.52cvss 9.0epss 0.01

    crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() using a custom variation of the Multiply-With-Carry pseudorandom number generator, seeded from Math.random(), instead of a…

  • CVE-2026-64637CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.00

    Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for the root user account.