VYPR

CVEs

386,750 total · page 695 of 7,735

  • CVE-2026-63263MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Exponential Data Expansion (CAPEC-197). An authenticated user may submit a specially crafted query to the ES|QL engine that causes exponential CPU consumption during query evaluation.…

  • CVE-2026-63262MedJul 22, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied input that circumvents space-level access control.

  • CVE-2026-16489MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in jsforce up to 3.10.16. This issue affects the function _execCommand in the library lib/registry/sfdx.js of the component SFDX Connection Registry. The manipulation leads to os command injection. The attack can only be performed from a local…

  • CVE-2026-16488MedJul 22, 2026
    risk 0.00cvss 5.0epss 0.01

    A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. This vulnerability affects the function subprocess.Popen of the file minicode/config.py of the component Project File Handler. Executing a manipulation can lead to os command injection. The attack may be launched…

  • CVE-2026-16566modJul 22, 2026
    risk 0.40cvss 6.1epss —

    community.general: community.general: jenkins_credential module returns generated API token in plaintext output

  • CVE-2026-63261MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user can send a specially crafted request to a Kibana machine learning feature, causing the server to exhaust available memory…

  • CVE-2026-63260MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated attacker with low-privilege access can trigger a denial of service condition in Kibana by sending a specially crafted, oversized request…

  • CVE-2026-63259MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplied identifiers that reference scheduled query result data from Kibana Spaces the requester is not authorized to access.

  • CVE-2026-63145MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification records via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A vulnerability exists in Kibana's Machine Learning functionality where a…

  • CVE-2026-63144MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via a specially crafted search request submitted by a low-privileged authenticated user. A user with read-level index access can submit a request that triggers unbounded recursive processing within…

  • CVE-2026-63143MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122). A user with limited feature privileges can access workflow execution outputs in their Kibana space without the authorization required to do so through the…

  • CVE-2026-63142MedJul 21, 2026
    risk 0.00cvss 5.0epss 0.00

    Incomplete List of Disallowed Inputs (CWE-184) in Kibana can allow an authenticated attacker with access to the Reporting feature to bypass outbound request restrictions configured by an administrator, causing the reporting service to send requests to network destinations that…

  • CVE-2026-56820HigJul 21, 2026
    risk 0.41cvss 7.4epss 0.00

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and prior to 4.1.135.Final, `OcspClient` does not validate that the `CertificateID` in an OCSP response matches the requested `CertificateID`,…

  • CVE-2026-56819HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.01

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, a remote unauthenticated peer can leak one direct `ByteBuf` per HTTP/2 `DATA` frame in applications that…

  • CVE-2026-56817CriJul 21, 2026
    risk 0.57cvss 9.8epss 0.01

    Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty channel pipeline containing `XmlDecoder` can send XML with a…

  • CVE-2026-16517LowJul 21, 2026
    risk 0.12cvss 2.9epss 0.00

    A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the…

  • CVE-2026-16486MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting. The attack may be initiated remotely. The exploit has been made…

  • CVE-2026-16485MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The…

  • CVE-2026-16424CriJul 21, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16423HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16422HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)

  • CVE-2026-16421HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16420HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.01

    Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16419CriJul 21, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16418HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.00

    Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16417LowJul 21, 2026
    risk 0.20cvss 3.1epss 0.00

    Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16416CriJul 21, 2026
    risk 0.60cvss 9.3epss 0.00

    Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

  • CVE-2026-16415MedJul 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-16414HigJul 21, 2026
    risk 0.51cvss 7.8epss 0.00

    Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)

  • CVE-2026-16413HigJul 21, 2026
    risk 0.54cvss 8.3epss 0.00

    Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-8989MedJul 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with physical access can boot attacker-controlled code in memory and modify or extract firmware and other sensitive…

  • CVE-2026-8988MedJul 21, 2026
    risk 0.44cvss 6.8epss 0.00

    Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. An attacker with physical access can modify the boot configuration or file system to obtain operating…

  • CVE-2026-8987HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.01

    Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated attacker can supply oversized input, resulting in denial of service and potentially arbitrary code execution.

  • CVE-2026-8986CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.03

    Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP server can supply a crafted diagnostics URL that results in arbitrary command execution on the charging station.

  • CVE-2026-8985CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.07

    Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can supply crafted input in the url parameter to execute arbitrary operating system commands.

  • CVE-2026-8984CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test endpoint can cause the device to download, extract, and execute attacker-controlled files with root…

  • CVE-2026-65319HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely.…

  • CVE-2026-65318HigJul 21, 2026
    risk 0.00cvss 8.6epss 0.01

    Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint.…

  • CVE-2026-65317HigJul 21, 2026
    risk 0.00cvss 8.6epss 0.01

    Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and…

  • CVE-2026-65316MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.01

    XXL-Job version 2.4.2 contains an insecure direct object reference vulnerability that allows authenticated users to read execution log content from job groups they are not authorized to access by supplying arbitrary sequential log IDs to the logDetailCat endpoint. Attackers can…

  • CVE-2026-65315HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension…

  • CVE-2026-65314MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to infer the values of excluded columns by crafting subset where clause conditions against shape responses. Attackers can observe whether subset where conditions…

  • CVE-2026-63141MedJul 21, 2026
    risk 0.41cvss 6.3epss 0.00

    Missing Authorization (CWE-862) in Kibana allows an authenticated user to access and modify Cloud Connect configuration and service settings without the required feature privileges, via direct requests to insufficiently protected product endpoints.

  • CVE-2026-62574HigJul 21, 2026
    risk 0.51cvss 7.8epss 0.00

    Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Install). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK:…

  • CVE-2026-62567HigJul 21, 2026
    risk 0.00cvss 7.7epss 0.00

    Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS…

  • CVE-2026-62565HigJul 21, 2026
    risk 0.00cvss 7.1epss 0.00

    Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-62563MedJul 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-62562MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle…

  • CVE-2026-62561HigJul 21, 2026
    risk 0.00cvss 7.8epss 0.00

    Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS…

  • CVE-2026-62560HigJul 21, 2026
    risk 0.00cvss 7.7epss 0.00

    Vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…