VYPR

CVEs

378,263 total · page 66 of 7,566

  • CVE-2026-18424LowSep 15, 2026
    risk 0.14cvss epss 0.00

    Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a host's validated DNS pin. When multiple remote URLs share the same host, only the first `ValidatedRemoteUrl` is retained and reused for every later URL with…

  • CVE-2026-18423LowSep 15, 2026
    risk 0.14cvss epss 0.00

    Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search preset delete and edit dialogs . An authenticated user holding only view permission on a single Express entity could therefore permanently delete, with no undo,…

  • CVE-2026-18422LowSep 15, 2026
    risk 0.07cvss epss 0.00

    Concrete CMS before 9.5.3 did not enforce a destination-side authorization check and did not validate a CSRF token in the multilingual page assignment backend action (Backend\Page\Multilingual::assign). As a result, an authenticated user who held the Edit Page Multilingual…

  • CVE-2026-13327Sep 15, 2026
    risk 0.00cvss epss 0.00

    Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.

  • CVE-2026-92180HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain…

  • CVE-2026-92179HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability…

  • CVE-2026-92178HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in…

  • CVE-2026-92177HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability…

  • CVE-2026-92176HigSep 15, 2026
    risk 0.51cvss 7.8epss 0.00

    pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exploit this vulnerability in that…

  • CVE-2026-90971Sep 15, 2026
    risk 0.00cvss epss 0.00

    Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection…

  • CVE-2026-90969Sep 15, 2026
    risk 0.00cvss epss 0.00

    Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.

  • CVE-2026-84850Sep 15, 2026
    risk 0.00cvss epss 0.00

    Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed…

  • CVE-2026-84048MedSep 15, 2026
    risk 0.41cvss epss 0.00

    Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.1 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires…

  • CVE-2026-82191MedSep 15, 2026
    risk 0.34cvss epss 0.00

    Joomla Extension - j2commerce.com - Unescaped request data reflected into PayPal notify redirect in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A crafted link to the paypal notify endpoint, if followed by a victim's browser (or an automated system that fetches it), causes…

  • CVE-2026-82190MedSep 15, 2026
    risk 0.41cvss epss 0.00

    Joomla Extension - j2commerce.com - Predictable/forgeable order access token in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Anyone who obtains the site's Joomla `secret` can compute a valid access token for *any* order on the site without ever having placed one, gaining…

  • CVE-2026-82189HigSep 15, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated denial-of-service against the order pipeline: mass-failing pending orders to disrupt revenue and force manual reprocessing, or…

  • CVE-2026-81924LowSep 15, 2026
    risk 0.07cvss epss 0.00

    Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery (CSRF) in the theme page-template activation feature. The Dashboard theme Inspect controller's activate_files() action created PageTemplate records from attacker-supplied pageTemplates[] values without…

  • CVE-2026-81923LowSep 15, 2026
    risk 0.11cvss 2.7epss 0.00

    In Concrete CMS before 9.5.3, the SEO Bulk Update Meta Tags editor did not check per-page edit permissions before saving. The saveRecord() action validated the per-page CSRF token but never called canEditPageProperties() for the target page, so a user who was granted access to…

  • CVE-2026-81922LowSep 15, 2026
    risk 0.11cvss 2.7epss 0.00

    Concrete CMS before 9.5.3 did not enforce a per-page authorization check when reordering pages from the sitemap. In the sitemap Explore dashboard controller, the send_to_top and send_to_bottom reorder tasks ran after only a generic sitemap-access check; the controller loaded the…

  • CVE-2026-81921MedSep 15, 2026
    risk 0.35cvss 5.4epss 0.00

    Concrete CMS 8.5.3 through 9.5.2 enabled the OAuth 2.0 refresh-token grant using the unmodified upstream League grant, which issued new access tokens from a valid refresh token without re-checking the associated account's active status. A user who obtained a refresh token while…

  • CVE-2026-81920MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Concrete CMS below 9.5.3 was vulnerable to Cross-Site Request Forgery in the dashboard SEO Excluded Words page. The reset() controller action cleared the administrator-configured reserved-word list (concrete.seo.exclude_words) but did not validate the anti-CSRF token that the…

  • CVE-2026-81919MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Concrete CMS below 9.5.3 did not validate an anti-CSRF token on the block-arrangement backend endpoint (the arrange() action of Concrete\Controller\Backend\Page\ArrangeBlocks). The action enforced page-edit authorization but performed no token check, and its route accepted any…

  • CVE-2026-81568HigSep 15, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - `J2StoreModelOrderdownloads::getFilePath()` built the on-disk path to a purchased digital download by concatenating the configured attachment folder…

  • CVE-2026-81567HigSep 15, 2026
    risk 0.57cvss epss 0.00

    Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - Unauthenticated, blind extraction of arbitrary database content (e.g. customer records, order data, stored…

  • CVE-2026-79411HigSep 15, 2026
    risk 0.50cvss 8.8epss 0.00

    Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update,…

  • CVE-2026-79410HigSep 15, 2026
    risk 0.46cvss 8.1epss 0.00

    Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

  • CVE-2026-79409MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

  • CVE-2026-78081HigSep 15, 2026
    risk 0.46cvss epss 0.00

    Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-4.1.7 - A forged request riding a victim's active checkout session could silently overwrite the billing or shipping address before…

  • CVE-2026-73467MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    On affected platforms running Arista EOS, under certain circumstances plaintext shared secrets for configured Terminal Access Controller Access-Control System Plus (TACACS+) servers

  • CVE-2026-73466MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    On affected platforms running Arista EOS, under certain circumstances user passwordss may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious actor…

  • CVE-2026-73465MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    On affected platforms running Arista EOS, under certain circumstances plaintext private keys may be written in clear text to log files during operations when specialized non-standard debugging trace levels are explicitly enabled. To exploit these vulnerabilities, a malicious…

  • CVE-2026-73451MedSep 15, 2026
    risk 0.31cvss 4.8epss 0.00

    On affected platforms running Arista EOS with dual switch cards and with ingress Security ACLs configured on Switched Virtual Interfaces (SVI) in shared mode, restarting of the secondary switchcard forwarding agent or insertion of secondary switchcard, can cause security ACLs on…

  • CVE-2026-69216MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember’s chunk decoder trims the chunk-size token and accepts leading plus or minus signs instead of requiring one or more hexadecimal digits followed by the required CRLF. When an intermediary…

  • CVE-2026-69214MedSep 15, 2026
    risk 0.37cvss 6.8epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware stores a response cookie’s Domain attribute without checking that it domain-matches the host that supplied the cookie or rejecting public suffixes. A malicious or…

  • CVE-2026-69213HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames through one unbounded queue consumed by writeLoop. When the peer stops reading, an unauthenticated HTTP/2 client can continue sending PING, SETTINGS, or DATA…

  • CVE-2026-69212MedSep 15, 2026
    risk 0.31cvss 5.9epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The FollowRedirect client middleware strips Authorization and Cookie headers only when a redirect changes authority, but authority comparison excludes the URI scheme. A same-authority redirect from…

  • CVE-2026-69211MedSep 15, 2026
    risk 0.24cvss 4.8epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResponseCookie.render writes attacker-influenced name, content, domain, path, and extension values without neutralizing semicolons or control characters. An application that constructs a…

  • CVE-2026-69209HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbounded message buffering because defragmentation accumulates fragments without a limit and FrameTranscoder accepts declared lengths up to Int.MaxValue. A remote…

  • CVE-2026-69208HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes fresh nonces and stops eviction at the first stale nonce because its stale-nonce comparison is inverted. On an application that protects at least one route…

  • CVE-2026-69204CriSep 15, 2026
    risk 0.53cvss epss 0.00

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/1.1 does not reject messages containing both Transfer-Encoding and Content-Length, so an intermediary and Ember can select different body framing rules. When ember-server is behind a…

  • CVE-2026-69201MedSep 15, 2026
    risk 0.31cvss 5.9epss 0.01

    Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, ResourceService and WebjarService decode each URL path segment but reject only segments exactly equal to an empty string, a dot, or two dots. A request containing percent-encoded slash or backslash…

  • CVE-2026-68534LowSep 15, 2026
    risk 0.08cvss epss 0.00

    Concrete CMS before 9.5.3 rendered Express entry labels as raw HTML when displaying associated entries, resulting in stored cross-site scripting. An unauthenticated attacker could submit a payload through a public Express Form; it then executed in an administrator's dashboard…

  • CVE-2026-68533LowSep 15, 2026
    risk 0.08cvss epss 0.00

    Concrete CMS below 9.5.3 conversation attachment uploaded endpoint imported files into the file manager before evaluating the "Add Message Attachments" permission, which was only checked after the file had been stored. A user denied that permission, or an unauthenticated visitor…

  • CVE-2026-68532LowSep 15, 2026
    risk 0.15cvss epss 0.00

    Concrete CMS 9.0.0 to dashboard group type controller did not validate a CSRF token on its delete action, resulting in cross-site request forgery. A remote unauthenticated attacker could cause an authenticated user with group type management permission to delete a custom group…

  • CVE-2026-68531LowSep 15, 2026
    risk 0.07cvss epss 0.00

    Concrete CMS 9 before 9.5.3 did not escape SQL LIKE wildcard characters in the keyword search filters used by the file manager, file folders, and page list, allowing an authenticated user with editor-level or higher privileges to submit a crafted search containing many…

  • CVE-2026-68530LowSep 15, 2026
    risk 0.07cvss epss 0.00

    Concrete CMS 9 through 9.5.2 did not perform an authorization check on several board-instance actions in the Boards area of the Dashboard. The instance details single-page controller resolved a board instance directly from an attacker-supplied instance ID and then viewed,…

  • CVE-2026-68529LowSep 15, 2026
    risk 0.14cvss epss 0.00

    Concrete CMS 9.0.0 through 9.5.2 was missing an authorization check on the Express entries advanced-search dashboard action. The advanced_search() method in DashboardSelectableExpressEntryListTrait resolved an Express entity directly from a user-supplied entity ID and rendered…

  • CVE-2026-66790Sep 15, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70496, which describes the same vulnerability. Please use CVE-2026-70496 instead.

  • CVE-2026-66789Sep 15, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID was assigned in error as a duplicate of CVE-2026-70495, which describes the same vulnerability. Please use CVE-2026-70495 instead.

  • CVE-2026-58773MedSep 15, 2026
    risk 0.44cvss 6.7epss 0.00

    In link_load_gnss_image of link_device.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.