VYPR

CVEs

386,750 total · page 692 of 7,735

  • CVE-2026-13074MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in exhaust mode. The server's handling of this combination results in a response loop that bypasses normal…

  • CVE-2026-13073MedJul 22, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of service for all connected clients until the process is restarted. The issue stems from an internal engine…

  • CVE-2026-13072HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This…

  • CVE-2026-13071MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue involves improper memory handling during document processing.

  • CVE-2026-13070MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the…

  • CVE-2026-13069MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing an unvalidated field used to control an internal computation loop. The resulting resource exhaustion…

  • CVE-2026-13068MedJul 22, 2026
    risk 0.27cvss 4.2epss 0.00

    An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongoing query operations for other users. The behavior stems from an authorization check that does not…

  • CVE-2026-13067MedJul 22, 2026
    risk 0.41cvss 6.3epss 0.00

    When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-list. This can result in unintended role assignments following MONGODB-X509 authentication. Affected…

  • CVE-2026-13066MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in data returned to the client. This constitutes an unintended information disclosure affecting deployments…

  • CVE-2026-13065MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.01

    A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the mongod process to terminate abnormally, resulting in denial of service. The issue stems from insufficient…

  • CVE-2026-13064MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be interrupted through standard…

  • CVE-2026-13063MedJul 22, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-memory condition by sending a crafted aggregation command. MongoDB's libmongocrypt library insufficiently validates payload-supplied values, which can result in…

  • CVE-2026-13062MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user with write privileges on a Queryable Encryption-enabled collection may be able to modify internal encryption metadata fields that are intended to be server-controlled, by sending crafted write commands through the mongos router on a sharded cluster. This…

  • CVE-2026-13061MedJul 22, 2026
    risk 0.28cvss 4.3epss 0.00

    An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessions aggregation stage. This information is normally restricted to users with cluster-level administrative privileges, and includes active session identifiers,…

  • CVE-2026-13060MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user with limited read privileges may be able to access documents from collections they are not authorized to read, due to an inconsistency in how the $graphLookup aggregation stage is evaluated during authorization and during execution. Affected scenarios…

  • CVE-2026-13059HigJul 22, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated user with low privileges may be able to perform unauthorized reads and writes on data protected by role-based query-level access controls, due to insufficient validation of certain client-supplied command parameters. The issue affects find, update, delete, and…

  • CVE-2026-13058MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. The issue stems from inconsistent validation across related transaction command parameters,…

  • CVE-2026-13057MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In sharded topologies, the $search and $searchMeta aggregation stages use internal routing that is normally populated only by the trusted router during sharded…

  • CVE-2026-13056MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    Using expressions that generate large arrays it is possible to craft a query that creates very large intermediate objects in memory, causing the server to crash with OOM error.

  • CVE-2026-13055MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that aborts the server process. The user must…

  • CVE-2026-3482MedJul 22, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.2.0.0 through 6.2.0.5_2,  6.2.1.0 through 6.2.1.1_2, and  6.2.2.0 through 6.2.2.0_1 could allow an unauthenticated user to read sensitive information by bypassing authentication through a specially crafted HTTP…

  • CVE-2026-22049HigJul 22, 2026
    risk 0.57cvss 8.8epss 0.01

    ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.

  • CVE-2026-16624CriJul 22, 2026
    risk 0.00cvss 9.6epss 0.00

    Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated teamId injection, then steal booking data, including fields like organizer/attendee emails and custom responses, and conditionally…

  • CVE-2026-65650MedJul 22, 2026
    risk 0.00cvss 4.3epss 0.00

    Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.

  • CVE-2026-64835HigJul 22, 2026
    risk 0.57cvss 8.8epss 0.01

    FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel…

  • CVE-2026-64834HigJul 22, 2026
    risk 0.49cvss 7.5epss 0.01

    FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c that allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a…

  • CVE-2026-64833HigJul 22, 2026
    risk 0.46cvss 7.1epss 0.00

    FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can…

  • CVE-2026-64832HigJul 22, 2026
    risk 0.57cvss 8.8epss 0.00

    FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the…

  • CVE-2026-16157HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside of the Program Files directory, or on a custom path, creates a LocalSystem service running from a directory that any standard…

  • CVE-2026-7328MedJul 22, 2026
    risk 0.00cvss —epss 0.00

    Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode allows a privileged local attacker to cause a denial of service via mailbox commands containing unverified AXI addresses. The…

  • CVE-2026-65013HigJul 22, 2026
    risk 0.57cvss 8.8epss 0.01

    Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get,…

  • CVE-2026-65012MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.00

    InvokeAI before 6.13.7 contains an unauthenticated directory enumeration vulnerability in the GET /api/v2/models/scan_folder endpoint that accepts attacker-controlled scan_path parameters. Unauthenticated attackers can recursively enumerate arbitrary server filesystem…

  • CVE-2026-65011MedJul 22, 2026
    risk 0.00cvss 4.3epss 0.00

    Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{definitionId}/duplicate endpoint that allows authenticated users to clone any event definition. Attackers with the low-privilege eventdefinitions:create…

  • CVE-2026-64831HigJul 22, 2026
    risk 0.57cvss 8.8epss 0.01

    FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious…

  • CVE-2026-64830HigJul 22, 2026
    risk 0.57cvss 8.8epss 0.01

    FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array…

  • CVE-2026-16615MedJul 22, 2026
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor…

  • CVE-2026-64828MedJul 22, 2026
    risk 0.40cvss 6.1epss 0.00

    Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML and JavaScript through the order notes field without sanitization. Attackers can craft malicious payloads in customer order…

  • CVE-2026-49499HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-46738CriJul 22, 2026
    risk 0.00cvss 9.1epss 0.01

    Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-46737MedJul 22, 2026
    risk 0.00cvss 6.7epss 0.01

    Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

  • CVE-2026-44276MedJul 22, 2026
    risk 0.00cvss 6.0epss 0.00

    Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information…

  • CVE-2026-40714HigJul 22, 2026
    risk 0.00cvss 7.2epss 0.01

    Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-40712CriJul 22, 2026
    risk 0.00cvss 9.1epss 0.01

    Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-16607HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that…

  • CVE-2026-16606CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.01

    A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote code execution (pre-auth RCE) on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally…

  • CVE-2026-16552Jul 22, 2026
    risk 0.41cvss —epss —

    Rejected reason: The reported issue is invalid, as it requires root privileges to reproduce, and it is out of scope of the threat model of the affected component.

  • CVE-2026-48029HigJul 22, 2026
    risk 0.39cvss 7.1epss 0.00

    libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

  • CVE-2026-2395CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Code Platform allows SQL Injection. This issue affects No Code Platform: from 4.1.3 before 4.1.4.

  • CVE-2026-14985HigJul 22, 2026
    risk 0.00cvss 7.8epss 0.00

    The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to improper privilege delegation and insufficient input validation in a maintenance script.

  • CVE-2026-13321HigJul 22, 2026
    risk 0.00cvss 8.6epss 0.00

    The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1…