VYPR

CVEs

37,851 total · page 63 of 758

  • CVE-2026-19264CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.01

    Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload directory and streams the file without normalising the path or confining it to that directory, and the route requires no…

  • CVE-2022-4995CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.01

    Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arbitrary files, including JSP webshells, by submitting a multipart/form-data POST request to /workrelate/plan/util/uploaderOperate.js…

  • CVE-2026-66914CriAug 7, 2026
    risk 0.60cvss —epss 0.01

    Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.

  • CVE-2026-71560CriAug 7, 2026
    risk 0.52cvss 9.1epss 0.01

    Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deserializing structs containing tagged integer fields. A crafted input payload may trigger an out-of-bounds heap read in the tagged…

  • CVE-2026-71558CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.01

    Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafted input payload can bypass type compatibility checks during polymorphic smart-pointer deserialization, causing an object of an…

  • CVE-2026-54213CriAug 7, 2026
    risk 0.60cvss —epss 0.01

    Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/internalRestart) is accessed. This endpoint is accessible to unauthenticated users over the public Internet. Instead of…

  • CVE-2026-54212CriAug 7, 2026
    risk 0.62cvss —epss 0.01

    Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a specially crafted JSON body, such as one that is at least 8 characters long and begins with a number, an unauthenticated attacker…

  • CVE-2026-54211CriAug 7, 2026
    risk 0.62cvss —epss 0.01

    Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in multiple form data parameters. By submitting excessively long values in these parameters, an authenticated attacker can…

  • CVE-2026-54210CriAug 7, 2026
    risk 0.62cvss —epss 0.01

    Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow condition. By specifying an excessively long filename in a file upload request, an unauthenticated attacker can trigger a crash of the…

  • CVE-2026-54203CriAug 7, 2026
    risk 0.60cvss —epss 0.01

    Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessing the URL “/.well-known/mta-sts.”, the application responds with memory. By repeatedly requesting this endpoint, an attacker…

  • CVE-2026-16258CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.01

    The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to perform PHP Object Injection. When a suitable POP chain is present via another installed Ajax Search Lite WordPress plugin before…

  • CVE-2026-16038CriAug 7, 2026
    risk 0.59cvss 9.1epss 0.00

    The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and…

  • CVE-2026-14205CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.00

    The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price from the attacker-controlled quantity, allowing any authenticated user to create a completed booking for a paid event without…

  • CVE-2026-14365CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.01

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-14364CriAug 7, 2026
    risk 0.57cvss 9.8epss 0.01

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validation in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity before…

  • CVE-2026-70332CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-68823CriAug 7, 2026
    risk 0.59cvss 9.1epss 0.01

    Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

  • CVE-2026-65667CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-63508CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62896CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62873CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62830CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-59118CriAug 7, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-59115CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56162CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.01

    Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-56161CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

  • CVE-2026-50515CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.02

    Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

  • CVE-2026-50481CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-71324CriAug 6, 2026
    risk 0.52cvss 9.1epss 0.01

    Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http.Transport. When the upstream…

  • CVE-2026-70558CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard…

  • CVE-2026-67689CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

  • CVE-2026-67688CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-67622CriAug 6, 2026
    risk 0.64cvss 9.9epss 0.00

    Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without…

  • CVE-2026-65400CriKEVAug 6, 2026
    risk 0.76cvss 9.8epss 0.02

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1, macOS Tahoe 26.7. An attacker on the network may be able to authenticate to Screen Sharing without…

  • CVE-2026-53984CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by…

  • CVE-2026-48088CriAug 6, 2026
    risk 0.61cvss 9.4epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on…

  • CVE-2026-48087CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration…

  • CVE-2026-48086CriAug 6, 2026
    risk 0.64cvss 9.9epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN`…

  • CVE-2026-48085CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional…

  • CVE-2026-3418CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher…

  • CVE-2026-19175CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19171CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19170CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-19166CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19164CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19157CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-19149CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-18367CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

  • CVE-2026-17032CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

  • CVE-2026-15734CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.