VYPR

CVEs

386,791 total · page 720 of 7,736

  • CVE-2026-65066LowJul 21, 2026
    risk 0.00cvss 3.8epss 0.00

    Data::RingBuffer::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is…

  • CVE-2026-65065MedJul 21, 2026
    risk 0.00cvss 5.5epss 0.00

    Data::RoaringBitmap::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in roaring.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is…

  • CVE-2026-65064LowJul 21, 2026
    risk 0.00cvss 3.8epss 0.00

    Data::HashMap::Shared versions before 0.14 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in shm_generic.h with open(path, O_RDWR | O_CREAT | O_CLOEXEC, 0666). The mode is 0666, so under the default umask 022…

  • CVE-2026-65063LowJul 21, 2026
    risk 0.00cvss 3.8epss 0.00

    Data::RadixTree::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in radix.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is…

  • CVE-2026-65062LowJul 21, 2026
    risk 0.00cvss 3.8epss 0.00

    Data::SortedSet::Shared versions before 0.03 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in sortedset.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is…

  • CVE-2026-65061LowJul 21, 2026
    risk 0.00cvss 3.8epss 0.00

    Data::ReqRep::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in reqrep.h with open(path, O_RDWR | O_CREAT, 0666), for both the request-reply and the integer-variant segments. The…

  • CVE-2026-64880HigJul 21, 2026
    risk 0.46cvss 7.1epss 0.00

    Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

  • CVE-2026-64879CriJul 21, 2026
    risk 0.65cvss 9.9epss 0.02

    A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

  • CVE-2026-64878CriJul 21, 2026
    risk 0.64cvss 9.9epss 0.01

    Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint.

  • CVE-2026-64617LowJul 21, 2026
    risk 0.00cvss 3.8epss 0.00

    Data::PubSub::Shared versions before 0.07 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in pubsub.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created…

  • CVE-2026-64616LowJul 21, 2026
    risk 0.00cvss 3.3epss 0.00

    Data::NDArray::Shared versions before 0.02 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in ndarray.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is…

  • CVE-2026-64615LowJul 21, 2026
    risk 0.00cvss 3.3epss 0.00

    Data::Graph::Shared versions before 0.04 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in graph.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created…

  • CVE-2026-64614LowJul 21, 2026
    risk 0.00cvss 3.8epss 0.00

    Data::Deque::Shared versions before 0.06 for Perl create a world-readable mmap backing file and open it without O_EXCL or O_NOFOLLOW. The segment is created in deque.h with open(path, O_RDWR|O_CREAT, 0666). The mode is 0666, so under the default umask 022 the file is created…

  • CVE-2026-64613MedJul 21, 2026
    risk 0.00cvss 6.2epss 0.00

    Data::Buffer::Shared versions before 0.05 for Perl create a world-readable mmap backing file and open it without O_NOFOLLOW. The segment is created in buf_generic.h with open(path, O_RDWR|O_CREAT|O_EXCL, 0666). O_EXCL blocks a pre-seeded file on create, but the mode is 0666, so…

  • CVE-2026-59147CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the…

  • CVE-2026-59146HigJul 21, 2026
    risk 0.00cvss 7.8epss 0.00

    Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator sph_validate_header checks the header scalars and region layout against…

  • CVE-2026-59145CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough about the header and layout (magic, version, section offsets, total_size,…

  • CVE-2026-59144CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time validator ring_validate_header checks the capacity-overflow and total_size consistency of the header but never caps elem_size…

  • CVE-2026-59143MedJul 21, 2026
    risk 0.00cvss 6.3epss 0.00

    Data::RoaringBitmap::Shared versions before 0.02 for Perl allow an out-of-bounds read via an unvalidated container offset and cardinality in rb_contains_locked. The attach-time validator rb_validate_header checks the header scalars and region layout against the file size, but…

  • CVE-2026-56852HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

  • CVE-2026-56146MedJul 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper Access Control (CWE-284) in Kibana can lead to unauthorized modification of Entity Analytics Watchlist configuration and potential information disclosure. A low-privileged authenticated user with read-only Security Solution access could perform write operations on…

  • CVE-2026-56145MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130). A low-privileged authenticated user with permission to execute EQL sequence queries against an index they control can send a specially crafted query…

  • CVE-2026-56144MedJul 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect Authorization (CWE-863) in Elasticsearch can allow an authenticated user with limited index privileges to exploit insufficient authorization controls in the ingest simulation feature. By targeting indices they are not authorized to access directly, the user can cause…

  • CVE-2026-50759HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.

  • CVE-2026-50758HigJul 21, 2026
    risk 0.00cvss 8.1epss 0.01

    Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter

  • CVE-2026-50757HigJul 21, 2026
    risk 0.00cvss 7.8epss 0.01

    Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server

  • CVE-2026-50756HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component

  • CVE-2026-50755CriJul 21, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value

  • CVE-2026-49092MedJul 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are…

  • CVE-2026-47671MedJul 21, 2026
    risk 0.28cvss 5.4epss 0.00

    Nhost is an open source Firebase alternative with GraphQL. In versions of Nhost CLI prior to 1.46.0, the hidden `nhost configserver` used by `nhost dev` exposes the Mimir GraphQL API with dummy authorization directives and permissive CORS. When a developer is running the local…

  • CVE-2026-47667HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.01

    CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and passed directly to `new unsigned char[header_size]` without being bounded…

  • CVE-2026-46600HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

  • CVE-2026-46403MedJul 21, 2026
    risk 0.34cvss 6.3epss 0.00

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, KVM exposes `ExecuteReadOnlyWithTypedArguments` as a read-only execution mechanism. The hook saves the previous read-only state, sets `runtime.SetReadOnly(true)`, executes the destination…

  • CVE-2026-42397MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user can submit a specially crafted request to affected Entity Analytics endpoints containing an oversized input value…

  • CVE-2026-30632HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.

  • CVE-2026-15957HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions…

  • CVE-2026-59766medJul 21, 2026
    risk 0.26cvss —epss —

    ## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —…

  • CVE-2026-64877HigJul 21, 2026
    risk 0.55cvss 8.4epss 0.00

    An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

  • CVE-2026-63454HigJul 21, 2026
    risk 0.47cvss 7.2epss 0.01

    An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote…

  • CVE-2026-63453HigJul 21, 2026
    risk 0.47cvss 7.2epss 0.01

    Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

  • CVE-2026-59142CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The attach-time validator shm_validate_header checks the header scalars and region layout against the file size, but does not validate the…

  • CVE-2026-59141CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate…

  • CVE-2026-59140CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The…

  • CVE-2026-59139CriJul 21, 2026
    risk 0.00cvss 9.1epss 0.01

    Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not…

  • CVE-2026-55084HigJul 21, 2026
    risk 0.00cvss 8.8epss 0.00

    DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the…

  • CVE-2026-55082HigJul 21, 2026
    risk 0.00cvss —epss 0.01

    DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. DHIS2 SQL View data endpoints allowed authenticated users with SQL View access to provide crafted filter values that were interpolated into generated SQL. An…

  • CVE-2026-55081HigJul 21, 2026
    risk 0.00cvss —epss 0.00

    DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. The DHIS2 OpenAPI HTML endpoint reflected values from the `scope` query parameter into the generated HTML document without sufficient sanitization. A crafted `scope`…

  • CVE-2026-16441CriJul 21, 2026
    risk 0.55cvss 9.6epss 0.01

    In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.

  • CVE-2026-12548MedJul 21, 2026
    risk 0.27cvss 4.2epss 0.00

    A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could…

  • CVE-2026-12547LowJul 21, 2026
    risk 0.00cvss 3.4epss 0.00

    SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy,…