VYPR

CVEs

386,593 total · page 637 of 7,732

  • CVE-2026-43833MedJul 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-43832HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-43831HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-43830CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-43829HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Full details and mitigation steps are currently restricted and will be published at a later date.

  • CVE-2026-6890Jul 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-6889Jul 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-18157HigJul 31, 2026
    risk 0.44cvss 7.8epss 0.00

    A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command…

  • CVE-2026-14541HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When a Google authService is initialized with mcpEnabled: true but lacks an explicitly defined audience or clientId, the…

  • CVE-2026-14540MedJul 31, 2026
    risk 0.40cvss 6.1epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through 1.4.0. While the toolbox implements baseline input sanitization for user-controlled parameters, the underlying HTTP client…

  • CVE-2026-14539HigJul 31, 2026
    risk 0.49cvss 7.5epss 0.00

    An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows an unauthenticated attacker to cause a denial of service (DoS). The /mcp endpoint handler reads incoming payloads directly into…

  • CVE-2026-14538HigJul 31, 2026
    risk 0.50cvss 7.7epss 0.00

    An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1 through 1.4.0 allows an authenticated attacker to bypass allowedDatasets validation checks. The toolbox relies on the BigQuery…

  • CVE-2026-14537CriJul 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Authorization in the direct HTTP API tool invocation endpoint in Google mcp-toolbox versions v1.3.0 and v1.4.0 allows an unauthenticated attacker to invoke tools protected by the scopeRequired feature via sending tool invocation requests through legacy HTTP endpoints…

  • CVE-2026-58039LowJul 31, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects…

  • CVE-2026-66720MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherType 0x88B8) Layer-2 multicast messages. A specially crafted GOOSE frame containing an undersized timestamp field can trigger a heap out-of-bounds read during …

  • CVE-2026-66421CriJul 30, 2026
    risk 0.60cvss 9.3epss 0.01

    OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API.…

  • CVE-2026-66420HigJul 30, 2026
    risk 0.50cvss 8.8epss 0.00

    MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within…

  • CVE-2026-66369MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-2 multicast frame on the process bus. When specific GOOSE message fields are processed, the parser advances its internal buffer position incorrectly,…

  • CVE-2026-66364MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 multicast frame on the process bus. When processing specific payload fields, an attacker controlled inner element length may exceed its enclosing length,…

  • CVE-2026-66360HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    The ISO Presentation layer contains a flaw in the handling of specific parameters during normal mode negotiation. A missing length check in the processing of the encoded presentation data allows an attacker controlled field with a zero length value to trigger a bounded heap…

  • CVE-2026-66349MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed request PDU containing an extended BER tag is received over an established session, the decoder may advance its internal buffer incorrectly due to a missing…

  • CVE-2026-65423HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.01

    An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to trigger an out-of-bounds write.

  • CVE-2026-65421MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length value is not validated, causing a read past the end of a heap buffer. This leads to termination of the MMS service process and a denial-of-service condition.

  • CVE-2026-63550MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request messages. When a crafted BER-encoded element is received over an established MMS session (TCP port 102), the decoder may advance its internal read position …

  • CVE-2026-63362MedJul 30, 2026
    risk 0.38cvss 5.9epss 0.02

    An unsigned integer underflow in the PubSub signature verification path in open62541 may allow a remote attacker to cause a denial of service via a crafted UDP packet.

  • CVE-2026-63035HigJul 30, 2026
    risk 0.53cvss 8.1epss 0.01

    A heap use-after-free vulnerability in the TransferSubscriptions service in open62541 may allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code.

  • CVE-2026-63033MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationObject_ParseObjectAddress to read one byte past the end of the heap-allocated message buffer.

  • CVE-2026-61893MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBuffer to read one byte past the end of the heap-allocated message buffer.

  • CVE-2026-56758MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain fields within the calling AP title, an attacker controlled length value of zero or one may cause the parser to read past the end of a heap buffer.

  • CVE-2026-10031MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    SFTPGo prior to 2.7.4 contains a permission bypass vulnerability that allows authenticated users to circumvent per-directory access controls by creating symbolic links in a permitted directory that point to files in directories where download, upload, or overwrite permissions…

  • CVE-2026-68563MedJul 30, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in ansible-collection-redhat-leapp. When a remediation task is executed with elevated privileges and the `leapp_old_postgresql_data` option is selected, a PostgreSQL data backup archive is created with insecure permissions. This allows a local non-root user on…

  • CVE-2026-68562MedJul 30, 2026
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own…

  • CVE-2026-64816MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.00

    RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_processing.rs. On Windows, a UNC path in lutPath causes an outbound SMB connection to an attacker-controlled host, leaking the victim's NTLMv2 credentials. The…

  • CVE-2026-63559HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.01

    An integer overflow in the UA_Variant arrayDimensions product computation in open62541 may allow a remote attacker to read out-of-bounds heap memory, potentially disclosing sensitive information.

  • CVE-2026-62845MedJul 30, 2026
    risk 0.24cvss 4.7epss 0.00

    Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivers build DDL statements by interpolating the user-supplied DataStoreUsername/DataStoreSchema directly into SQL via fmt.Sprintf, without escaping identifiers.…

  • CVE-2026-62246HigJul 30, 2026
    risk 0.48cvss 8.5epss 0.00

    Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datastore schema, database user, and etcd key prefix from a lossy namespace-and-name normalization in GetDefaultDatastoreSchema() and…

  • CVE-2026-5846MedJul 30, 2026
    risk 0.37cvss 5.7epss 0.00

    The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in…

  • CVE-2026-38709CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.03

    TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to…

  • CVE-2026-18064HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause…

  • CVE-2026-12562HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.00

    The RCU II+ and Multiload II+ are vulnerable to an unauthenticated service that exposes a debug interface granting full root-level access to the embedded system. This vulnerability stems from a network-accessible port running a Target Communications Framework (TCF) service…

  • CVE-2026-68503CriJul 30, 2026
    risk 0.57cvss 9.8epss 0.01

    LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn ships default C2 credentials LazyOwn and LazyOwn in payload.json and core/payload_schema.py and passes them unchanged to lazyc2.py HTTP Basic authentication, allowing…

  • CVE-2026-68502CriJul 30, 2026
    risk 0.57cvss 9.8epss 0.01

    LazyOwn RedTeam/APT Framework is an AI-powered C2 and red-team operations framework. Prior to 0.2.154, LazyOwn's lazyc2.py registers an unauthenticated Socket.IO input event handler that dispatches data.get('value') to LazyOwnShell.one_cmd, reaching LazyOwnShell.do_cmd and…

  • CVE-2026-68501MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.01

    Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints…

  • CVE-2026-68500HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie…

  • CVE-2026-68499MedJul 30, 2026
    risk 0.33cvss 6.2epss 0.00

    re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2's String.prototype.match implementation with a global RE2 pattern that can match the empty string fails to advance its native matching cursor in lib/match.cc, causing an infinite loop…

  • CVE-2026-66803CriJul 30, 2026
    risk 0.00cvss 10.0epss 0.01

    Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

  • CVE-2026-66418CriJul 30, 2026
    risk 0.60cvss 9.3epss 0.01

    OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log.…

  • CVE-2026-61526MedJul 30, 2026
    risk 0.33cvss 6.1epss 0.00

    AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route…

  • CVE-2026-55777MedJul 30, 2026
    risk 0.27cvss —epss 0.00

    GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the parse_ios() function uses an attacker-controlled keyword-to-OS offset as both the source offset and copy length for memmove,…

  • CVE-2026-55768HigJul 30, 2026
    risk 0.50cvss —epss 0.00

    GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11, the built-in WebSocket server narrows a 64-bit extended frame length into the signed 32-bit WSFrame.payloadlen field before…