VYPR

CVEs

386,746 total · page 684 of 7,735

  • CVE-2026-47724CriJul 23, 2026
    risk 0.57cvss 9.9epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trusts the bearer token alone for authorisation on most endpoints. The codebase itself admits this at `internal/api/hosts.go:384`: "API…

  • CVE-2026-47723HigJul 23, 2026
    risk 0.39cvss —epss 0.01

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.1, none of the response paths in `internal/web/` or `internal/api/` set the standard browser-security headers. `grep` for `Content-Security-Policy`, `X-Frame-Options`,…

  • CVE-2026-39155MedJul 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative…

  • CVE-2026-38764HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.00

    An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys

  • CVE-2026-34496HigJul 23, 2026
    risk 0.46cvss —epss 0.00

    Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.

  • CVE-2026-21655HigJul 23, 2026
    risk 0.57cvss —epss 0.00

    Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before…

  • CVE-2026-21653HigJul 23, 2026
    risk 0.47cvss —epss 0.00

    Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.

  • CVE-2026-16796HigJul 23, 2026
    risk 0.41cvss 7.3epss 0.01

    Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remote authenticated user to execute arbitrary commands within the Code Interpreter sandbox via crafted package name arguments. To…

  • CVE-2026-16002HigJul 23, 2026
    risk 0.53cvss 8.2epss 0.00

    The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.

  • CVE-2026-15981CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.02

    The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's…

  • CVE-2026-15968HigJul 23, 2026
    risk 0.00cvss 7.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

  • CVE-2026-15967HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

  • CVE-2026-15966HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

  • CVE-2026-15630CriJul 23, 2026
    risk 0.64cvss 9.9epss 0.00

    A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

  • CVE-2026-10697HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.01

    Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

  • CVE-2026-65706HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. The filter_frame() function reuses a temporary row…

  • CVE-2026-65705HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When…

  • CVE-2026-65704HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking,…

  • CVE-2026-65703HigJul 23, 2026
    risk 0.51cvss 7.8epss 0.00

    FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails…

  • CVE-2026-64785MedJul 23, 2026
    risk 0.27cvss 5.3epss 0.00

    SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in…

  • CVE-2026-63359CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-crafted request to bypass the login page, access other users' credentials, take over other user accounts, access sensitive PII, and…

  • CVE-2026-60122HigJul 23, 2026
    risk 0.44cvss 7.8epss 0.00

    gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is…

  • CVE-2026-48013MedJul 23, 2026
    risk 0.20cvss 4.1epss 0.00

    Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. While the parallel `uploadFromURL` flow validates…

  • CVE-2026-48012MedJul 23, 2026
    risk 0.28cvss 4.3epss 0.00

    Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`. When the endpoint is reached without the expected SSO session state, the application falls back to the request's…

  • CVE-2026-47722HigJul 23, 2026
    risk 0.50cvss —epss 0.00

    nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the…

  • CVE-2026-47670CriJul 23, 2026
    risk 0.54cvss —epss 0.02

    DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid DbGate credentials can execute arbitrary OS commands as root by exploiting an unsanitized `functionName` parameter in the…

  • CVE-2026-47669CriJul 23, 2026
    risk 0.53cvss —epss 0.01

    DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js` (line 27) does not validate that extracted file paths stay within the output directory. A malicious ZIP with `../` entries writes…

  • CVE-2026-25800HigJul 23, 2026
    risk 0.42cvss 7.5epss 0.01

    Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, the `Assembler` component that assembles unordered stream fragments into consecutive chunks of the stream incurs some overhead for…

  • CVE-2026-15212HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.00

    The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is…

  • CVE-2026-12353MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TLS endpoint. Depending on how the RHCS server is configured, a manual intervention to restart it may prove necessary.

  • CVE-2026-65010MedJul 23, 2026
    risk 0.36cvss 6.6epss 0.00

    Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to write arbitrary files by pre-planting symlinks at predictable output paths. Attackers can redirect archive extraction to arbitrary…

  • CVE-2026-63765HigJul 23, 2026
    risk 0.53cvss 8.2epss 0.01

    Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account…

  • CVE-2026-16756HigJul 23, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are…

  • CVE-2026-15687LowJul 23, 2026
    risk 0.00cvss 2.4epss 0.00

    A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.

  • CVE-2026-6516CriJul 23, 2026
    risk 0.00cvss 10.0epss 0.05

    Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

  • CVE-2026-65920MedJul 23, 2026
    risk 0.21cvss 4.3epss 0.00

    Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitrary files by supplying malicious weight_map values in model index JSON. Attackers can use ../ sequences or…

  • CVE-2026-65919HigJul 23, 2026
    risk 0.42cvss 7.5epss 0.02

    Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoints that pass user-supplied file parameters directly to os.Open without path validation. Attackers can supply absolute paths or…

  • CVE-2026-65918HigJul 23, 2026
    risk 0.39cvss 7.1epss 0.00

    PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service…

  • CVE-2026-65763MedJul 23, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vulnerability.

  • CVE-2026-65762MedJul 23, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XSS vulnerability.

  • CVE-2026-65702HigJul 23, 2026
    risk 0.00cvss 8.6epss 0.01

    Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from…

  • CVE-2026-65701CriJul 23, 2026
    risk 0.00cvss 9.1epss 0.01

    SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…

  • CVE-2026-65700CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.02

    h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…

  • CVE-2026-65699MedJul 23, 2026
    risk 0.00cvss 4.2epss 0.00

    AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The…

  • CVE-2026-47769MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.00

    APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f57af2b79a95333d1c8fbeece5, the `/webhooks/:serverSlug/:eventName` endpoint accepts arbitrary unauthenticated JSON and stores it in…

  • CVE-2026-47755MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged authenticated agent can retrieve plaintext credentials and TOTP secrets belonging to another client by directly requesting the…

  • CVE-2026-47752CriJul 23, 2026
    risk 0.00cvss 9.9epss 0.01

    Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection (SSTI) in the notification template feature. The `title_template` and `body_template` fields are rendered using an unsandboxed…

  • CVE-2026-47743HigJul 23, 2026
    risk 0.50cvss 8.7epss 0.00

    Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public…

  • CVE-2026-47668CriJul 23, 2026
    risk 0.58cvss 10.0epss 0.04

    DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execution via code injection in the `functionName` parameter of JSON script `assign` commands. The `functionName` value is interpolated…

  • CVE-2026-44210CriJul 23, 2026
    risk 0.57cvss 9.9epss 0.01

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. Versions prior to 3.31.0 ship with a default configuration that allows pod creators to inject arbitrary command-line arguments into…