VYPR

CVEs

386,593 total · page 640 of 7,732

  • CVE-2026-23981MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.01

    An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboards they do not own. When updating a chart's properties via the REST API, a user can provide a list of dashboard IDs (dashboards)…

  • CVE-2026-15658HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.

  • CVE-2026-15657MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

  • CVE-2026-10842HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could allow a remote attacker to bypass security constraints.

  • CVE-2026-6540HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a result, HTTP requests using path-traversal segments, encoded slashes, or repeated slashes are not correctly evaluated by Prefix path…

  • CVE-2026-67349HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud provider credentials. Additionally, adminAuthMiddleware fails open when ADMIN_TOKEN is unset, allowing unauthenticated attackers…

  • CVE-2026-67348HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read another tenant's execution data. Attackers can supply arbitrary execution_id values to retrieve sensitive execution records including…

  • CVE-2026-67347MedJul 30, 2026
    risk 0.37cvss 6.8epss 0.01

    Vendure through 3.7.1, fixed in commit f67ef5f, contains a cross-channel authorization bypass vulnerability in stock-location.service.ts and asset.service.ts update methods that allows channel-scoped administrators to modify other tenants' data. Attackers can supply global IDs…

  • CVE-2026-67346HigJul 30, 2026
    risk 0.49cvss 8.6epss 0.01

    Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url function that fails to validate hostnames through DNS resolution, allowing attackers to bypass the blocklist. Attackers can supply user-controlled image or…

  • CVE-2026-67345HigJul 30, 2026
    risk 0.46cvss 8.1epss 0.01

    MaxKey through 4.1.12, fixed in commit ddbb72f, contains an insufficient redirect URI validation vulnerability in DefaultRedirectResolver.hostMatches() that allows remote attackers to hijack OAuth 2.0 authorization codes by supplying a crafted redirect_uri whose hostname suffix…

  • CVE-2026-65635HigJul 30, 2026
    risk 0.47cvss —epss 0.01

    Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attackers to register OpenID Connect clients with administrative privileges through the dynamic client registration entry point. Boruta.Openid.register_client/3…

  • CVE-2026-54885MedJul 30, 2026
    risk 0.38cvss —epss 0.01

    Server-Side Request Forgery vulnerability in malach-it Boruta allows an unauthenticated remote attacker to cause the OAuth/OpenID authorization server to issue outbound HTTP requests to attacker-chosen URIs, including internal services and cloud metadata endpoints. Three code…

  • CVE-2026-53431CriJul 30, 2026
    risk 0.52cvss —epss 0.01

    Authentication Bypass by Capture-replay vulnerability in malach-it Boruta allows an attacker who has obtained a previously valid JWT client assertion to authenticate as the issuing OAuth client after the assertion has expired. Boruta accepts JWT-based client authentication…

  • CVE-2026-41187MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.00

    Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Delete override on NetworkPolicy, GlobalNetworkPolicy, and their staged variants is not invoked for DeleteCollection requests. A user holding the deletecollection…

  • CVE-2026-41186HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    When Calico's shared debug server is enabled (disabled by default), the Calico kube-controllers and Goldmane components bind their Go pprof debug listener to 0.0.0.0 without authentication. Any pod with network reachability to the listener can retrieve the process heap,…

  • CVE-2026-16308HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial of service due to unbounded accumulation of multipart MIME part-header bytes.

  • CVE-2026-15435CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to write arbitrary files on the…

  • CVE-2026-14980HigJul 30, 2026
    risk 0.00cvss 8.3epss 0.00

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to perform SSRF attacks with elevated privileges when the collectiveController-1.0 feature is enabled.

  • CVE-2026-14522HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to execute arbitrary commands due to improper neutralization of CRLF characters.

  • CVE-2026-14519HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 could allow a remote attacker to read arbitrary files due to a path traversal vulnerability.

  • CVE-2026-12947HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.27 stores potentially sensitive information in log files that could be read by a local user.

  • CVE-2026-11980HigJul 30, 2026
    risk 0.47cvss 7.3epss 0.00

    IBM Aspera Desktop App 1.0.5 through 1.0.19 can allow arbitrary code execution by loading DLL files at start-up.

  • CVE-2026-11897HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.01

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service, caused by sending a specially crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources.

  • CVE-2026-11707CriJul 30, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

  • CVE-2026-11383MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scripting in the Administrative Console.

  • CVE-2025-36431MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended…

  • CVE-2025-36298MedJul 30, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1…

  • CVE-2026-67351HigJul 30, 2026
    risk 0.50cvss 8.8epss 0.01

    Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independently without ensuring both use the same user record. An authenticated Editor can create a username collision with an Administrator…

  • CVE-2026-60075HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an…

  • CVE-2026-60074HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    Date::Manip versions through 7.00 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check. The parse regexes capture year, month and day with the `\d` shorthand, which on a character string matches the whole Unicode decimal digit…

  • CVE-2026-5219HigJul 30, 2026
    risk 0.00cvss 8.3epss 0.00

    Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. This issue affects E-Commerce Pack: before 5.03.01.49.

  • CVE-2026-58218MedJul 30, 2026
    risk 0.35cvss 5.3epss 0.01

    A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names,…

  • CVE-2026-57859HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    e107 prior to version 2.3.8 contains a code execution vulnerability in the e_array deserialization handler that allows an attacker with out-of-band database write access to execute arbitrary PHP code by storing a crafted payload in the user_prefs column. The…

  • CVE-2026-56428HigJul 30, 2026
    risk 0.00cvss 8.1epss 0.00

    The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in…

  • CVE-2026-41709LowJul 30, 2026
    risk 0.00cvss 2.7epss 0.00

    VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.

  • CVE-2026-12722HigJul 30, 2026
    risk 0.00cvss 8.2epss 0.00

    Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. This issue affects FTC E-Commerce Management Panel: before 1.0.2.

  • CVE-2026-59310CriKEVJul 30, 2026
    risk 0.76cvss 9.8epss 0.03

    VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

  • CVE-2026-59309CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

  • CVE-2026-54368HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.01

    CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers…

  • CVE-2026-54367HigJul 30, 2026
    risk 0.00cvss 8.6epss 0.00

    CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId…

  • CVE-2026-54366HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the…

  • CVE-2026-54365HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a…

  • CVE-2026-54364MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectProvider.aspx endpoint.…

  • CVE-2026-54363CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.01

    CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all…

  • CVE-2026-47876CriJul 30, 2026
    risk 0.00cvss 9.3epss 0.00

    VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3…

  • CVE-2026-41703HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out-of-bounds read, potentially leading to information disclosure or more likely a Denial-of-Service (DoS) condition of the host…

  • CVE-2026-7260MedJul 30, 2026
    risk 0.36cvss 5.5epss 0.00

    Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

  • CVE-2026-5582MedJul 30, 2026
    risk 0.00cvss 4.3epss 0.00

    The FuseWP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.24.2. This is due to missing nonce verification on the toggle_sync_status() function. This makes it possible for unauthenticated attackers to toggle the status…

  • CVE-2026-18382MedJul 30, 2026
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary OAuth token endpoint. When authentication.type is set to service-account, the operator sends the tenant's Red Hat SSO…

  • CVE-2026-18381HigJul 30, 2026
    risk 0.49cvss 7.6epss 0.00

    A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an arbitrary upload URL. The operator attaches its own Kubernetes service-account bearer token to queries…