VYPR

CVEs

386,750 total · page 694 of 7,735

  • CVE-2026-8152CriJul 22, 2026
    risk 0.00cvss —epss 0.00

    Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript…

  • CVE-2026-44191HigJul 22, 2026
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker…

  • CVE-2026-16270MedJul 22, 2026
    risk 0.00cvss —epss 0.00

    Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can result in a DoS attack. This issue was fixed in version 0.6.4.

  • CVE-2026-65603HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the update_user task). Unlike the registration handler, this handler does not strip privilege fields…

  • CVE-2026-65602HigJul 22, 2026
    risk 0.50cvss 8.8epss 0.00

    Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a…

  • CVE-2026-65601HigJul 22, 2026
    risk 0.50cvss 8.8epss 0.01

    Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A…

  • CVE-2026-65600MedJul 22, 2026
    risk 0.27cvss 5.3epss 0.01

    Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When ReplacePathRegex is configured with a regex that captures user-controlled path segments without a mandatory…

  • CVE-2026-65599MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the JWT header's kid field (intended only for a key identifier). Because JWT headers…

  • CVE-2026-65598HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an…

  • CVE-2026-65597MedJul 22, 2026
    risk 0.00cvss 5.4epss 0.00

    n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the sandbox attribute. A sanitizer bypass allows injected script to execute…

  • CVE-2026-65596HigJul 22, 2026
    risk 0.00cvss 8.1epss 0.00

    n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unlike the HTTP Request node. An authenticated user able to create or edit…

  • CVE-2026-65595HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.01

    n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and Public API are enabled, a low-privileged user who can obtain a valid external…

  • CVE-2026-65594MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP…

  • CVE-2026-65593MedJul 22, 2026
    risk 0.00cvss 5.4epss 0.00

    n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute URLs in routing configuration to override baseURL…

  • CVE-2026-65592MedJul 22, 2026
    risk 0.00cvss 5.4epss 0.00

    n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to window.open() without scheme validation. An attacker with workflow…

  • CVE-2026-65591HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.01

    n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n…

  • CVE-2026-65590CriJul 22, 2026
    risk 0.00cvss 9.8epss 0.01

    n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing…

  • CVE-2026-65589MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and…

  • CVE-2026-65016HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role…

  • CVE-2026-65015HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.01

    n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing…

  • CVE-2026-65014MedJul 22, 2026
    risk 0.27cvss 5.3epss 0.01

    n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test…

  • CVE-2026-61392MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.00

    There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.

  • CVE-2026-61391HigJul 22, 2026
    risk 0.00cvss 7.2epss 0.01

    There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

  • CVE-2026-61390HigJul 22, 2026
    risk 0.00cvss 7.7epss 0.00

    There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

  • CVE-2026-57600HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

  • CVE-2026-57599MedJul 22, 2026
    risk 0.00cvss 6.6epss 0.00

    There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

  • CVE-2026-4773HigJul 22, 2026
    risk 0.00cvss 8.1epss 0.00

    Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

  • CVE-2026-44192MedJul 22, 2026
    risk 0.43cvss 6.6epss 0.00

    A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to…

  • CVE-2026-44190HigJul 22, 2026
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended…

  • CVE-2026-44189HigJul 22, 2026
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters…

  • CVE-2026-44187LowJul 22, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key…

  • CVE-2026-16551MedJul 22, 2026
    risk 0.00cvss —epss 0.00

    Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

  • CVE-2026-16544MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events,…

  • CVE-2025-13146MedJul 22, 2026
    risk 0.35cvss 6.5epss 0.00

    The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the software allowing users to execute an action that does not properly validate a value before…

  • CVE-2026-16473MedJul 22, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent…

  • CVE-2026-14551HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the…

  • CVE-2026-63264MedJul 22, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.

  • CVE-2026-2406MedJul 22, 2026
    risk 0.42cvss 6.5epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online Registration and Workflow Management…

  • CVE-2026-15787MedJul 22, 2026
    risk 0.00cvss 6.4epss 0.00

    The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-63048CriJul 22, 2026
    risk 0.61cvss —epss 0.00

    Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file upload, leading to RCE.

  • CVE-2026-63047HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.

  • CVE-2026-45820HigJul 22, 2026
    risk 0.42cvss 7.5epss 0.00

    fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop…

  • CVE-2026-3821HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.01

    Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.

  • CVE-2026-14322MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.00

    The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created through a payment method other than its recognised gateways, allowing unauthenticated users to create fully-approved bookings for priced appointments without making…

  • CVE-2026-12987HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP…

  • CVE-2026-12968HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.01

    The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose…

  • CVE-2026-15802HigJul 22, 2026
    risk 0.00cvss 8.1epss 0.01

    The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with…

  • CVE-2026-56844HigJul 22, 2026
    risk 0.00cvss —epss 0.00

    A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.

  • CVE-2026-16492MedJul 22, 2026
    risk 0.00cvss 5.5epss 0.04

    A weakness has been identified in umijs umi up to 4.6.63. The affected element is the function git.getFileCreateInfo of the file packages/utils/src/getFileGitIno.ts of the component GIT File Helper. This manipulation causes os command injection. The exploit has been made…

  • CVE-2026-16490MedJul 22, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /prescription.php. The manipulation of the argument editid results in sql injection. The attack can be executed remotely. The exploit has been released…