VYPR

CVEs

37,872 total · page 70 of 758

  • CVE-2026-11707CriJul 30, 2026
    risk 0.60cvss 9.3epss 0.00

    IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by a cross-site scripting vulnerability in the administrative console login page.

  • CVE-2026-59310CriKEVJul 30, 2026
    risk 0.76cvss 9.8epss 0.03

    VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

  • CVE-2026-59309CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.

  • CVE-2026-54363CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.01

    CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all…

  • CVE-2026-47876CriJul 30, 2026
    risk 0.00cvss 9.3epss 0.00

    VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3…

  • CVE-2026-17544CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and from 8.5.* before 8.5.9.

  • CVE-2026-17543CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

  • CVE-2026-18363CriJul 30, 2026
    risk 0.00cvss —epss 0.00

    A logic vulnerability in the password reset token validation routine implemented by osTicket in versions prior to v1.17.8 and v1.18.4. During the password reset process, the application retrieves the timestamp associated with the provided token and checks whether the configured…

  • CVE-2026-7849CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

  • CVE-2026-44108CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible, potentially allowing an unauthenticated remote attacker to…

  • CVE-2026-44104CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modified firmware, resulting in full system compromise.

  • CVE-2026-44101CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.

  • CVE-2026-44100CriJul 30, 2026
    risk 0.00cvss 9.4epss 0.01

    The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering.

  • CVE-2026-44092CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.01

    An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss.

  • CVE-2026-44091CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.01

    An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

  • CVE-2026-44090CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised.

  • CVE-2026-58066CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity…

  • CVE-2026-58046CriJul 30, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.

  • CVE-2026-14602CriJul 30, 2026
    risk 0.00cvss 9.0epss 0.01

    The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, allowing unauthenticated attackers to inject arbitrary PHP objects, which can lead to remote code execution when a suitable gadget chain is present through…

  • CVE-2026-16610CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler enforces only a publicly emitted nonce with no…

  • CVE-2026-48449CriJul 30, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-18015CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-18002CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17991CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17990CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)

  • CVE-2026-17987CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)

  • CVE-2026-17947CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17940CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity:…

  • CVE-2026-17924CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-17865CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17856CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17855CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17848CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

  • CVE-2026-17847CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17837CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17834CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17832CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17804CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17803CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Medium)

  • CVE-2026-17801CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17768CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17758CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17749CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)

  • CVE-2026-17738CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-17727CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17726CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17721CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17718CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17717CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.01

    Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17713CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)