VYPR

CVEs

386,791 total · page 721 of 7,736

  • CVE-2016-20096CriJul 21, 2026
    risk 0.64cvss 9.8epss 0.01

    Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands by manipulating the name parameter in a POST request to the login endpoint. Attackers can inject malicious…

  • CVE-2026-56583LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

  • CVE-2026-56582LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected by the SSL/TLS LUCKY13 Vulnerability. An attacker may exploit this vulnerability to decrypt sensitive information through a TLS/SSL padding oracle attack.

  • CVE-2026-56581LowJul 21, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

  • CVE-2026-56580LowJul 21, 2026
    risk 0.00cvss 2.2epss 0.00

    HCL MyCloud was affected by Using Components with Known Vulnerability ( IIS Server ). It may allow attackers to exploit publicly disclosed weaknesses and compromise the system.

  • CVE-2026-56579LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with License Key Revealed in HTTP Response. It may enable attackers to misuse the exposed information and compromise the application's security.

  • CVE-2026-56578LowJul 21, 2026
    risk 0.00cvss 2.2epss 0.00

    HCL MyCloud was affected by Server Version Disclosure. It may help attackers identify and exploit known vulnerabilities affecting the disclosed software versions.

  • CVE-2026-56577LowJul 21, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL MyCloud was affected with Weak Password Policy. It may increase the risk of account compromise through brute-force or credential-based attacks.

  • CVE-2026-47657HigJul 21, 2026
    risk 0.00cvss —epss 0.00

    HumHub is an Open Source Enterprise Social Network. In versions 1.13.0 through 1.18.2, a missing authorization check in the Space member management controller allowed any authenticated user to trigger the removal of all members from any Space, regardless of their own role or…

  • CVE-2026-47425MedJul 21, 2026
    risk 0.38cvss —epss 0.00

    Rattler is a library that provides common functionality used within the conda ecosystem. Prior to version 0.43.2, `EntryPoint::FromStr` in `rattler_conda_types` performs only `.trim()` on the `command` field before the linker joins it onto the install prefix and writes an…

  • CVE-2026-47419HigJul 21, 2026
    risk 0.47cvss 8.3epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an* Insecure Direct Object Reference. The agent CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/agents/{agent_id}`) gate access on…

  • CVE-2026-47418HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The project CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/projects/{project_id}` and `GET…

  • CVE-2026-47417HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The comment endpoints (`POST /workspaces/{workspace_id}/issues/{issue_id}/comments` and `GET .../comments`) gate access on…

  • CVE-2026-47416CriJul 21, 2026
    risk 0.55cvss 9.6epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege escalation. The `PATCH /workspaces/{workspace_id}/members/{user_id}` endpoint is gated by `require_workspace_member(workspace_id)`,…

  • CVE-2026-47415HigJul 21, 2026
    risk 0.47cvss 8.3epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The issue CRUD endpoints (`GET / PATCH / DELETE /workspaces/{workspace_id}/issues/{issue_id}`) gate access on…

  • CVE-2026-47414HigJul 21, 2026
    risk 0.42cvss 7.6epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. Five label endpoints — `PATCH /workspaces/{workspace_id}/labels/{label_id}`, `DELETE .../labels/{label_id}`, `POST…

  • CVE-2026-47413CriJul 21, 2026
    risk 0.55cvss 9.6epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenant member injection. The `POST /workspaces/{workspace_id}/members` endpoint is gated only by `require_workspace_member(workspace_id)…

  • CVE-2026-47412HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.01

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)`…

  • CVE-2026-47411MedJul 21, 2026
    risk 0.35cvss 6.5epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling workspace metadata + settings tampering. The `PATCH /workspaces/{workspace_id}` endpoint is gated only by…

  • CVE-2026-44880HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.01

    A buffer overflow vulnerability was found in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow an remote low-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

  • CVE-2026-21579HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an…

  • CVE-2026-21577MedJul 21, 2026
    risk 0.42cvss 6.5epss 0.00

    This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated…

  • CVE-2026-21575HigJul 21, 2026
    risk 0.52cvss 8.0epss 0.01

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary…

  • CVE-2026-16493HigJul 21, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's concrete_artifact_manager.py constructs git clone commands without a '--' (end-of-options) separator before user-supplied URLs when installing collections from git sources. An…

  • CVE-2026-16439CriJul 21, 2026
    risk 0.52cvss 9.1epss 0.00

    In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.

  • CVE-2026-16243HigJul 21, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.

  • CVE-2026-47410CriJul 21, 2026
    risk 0.57cvss 9.8epss 0.01

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic key. The JWT signing secret defaults to the hardcoded literal `"dev-secret-change-me"` when `PLATFORM_JWT_SECRET` is unset. A…

  • CVE-2026-47409HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.01

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling owner lockout. The `DELETE /workspaces/{workspace_id}/members/{user_id}` endpoint is gated only by…

  • CVE-2026-47408MedJul 21, 2026
    risk 0.35cvss 6.5epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The `GET /workspaces/{workspace_id}/issues/{issue_id}/activity` endpoint is gated by `require_workspace_member(workspace_id)`…

  • CVE-2026-47407CriJul 21, 2026
    risk 0.54cvss —epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources under `/api/v1/workspaces/{workspace_id}/...` and protects them with a `require_workspace_member(workspace_id)` FastAPI dependency.…

  • CVE-2026-47406HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.00

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an Insecure Direct Object Reference. The dependency endpoints (`POST/GET /workspaces/{workspace_id}/issues/{issue_id}/dependencies` and `DELETE…

  • CVE-2026-47405HigJul 21, 2026
    risk 0.50cvss 8.8epss 0.01

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have a broken workspace authorization check that allows any authenticated low-privilege workspace member to escalate their own role to `owner`. The issue is caused by…

  • CVE-2026-47399HigJul 21, 2026
    risk 0.50cvss 8.8epss 0.01

    PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the workspace-scoped REST routes contain a systemic object-level authorization flaw that allows an authenticated user from one workspace to access, modify, and delete…

  • CVE-2026-47398HigJul 21, 2026
    risk 0.46cvss 8.1epss 0.01

    PraisonAI is a multi-agent teams system. The v4.6.32 chokepoint refactor (which patched CVE-2026-44334 / GHSA-xcmw-grxf-wjhj) added the PRAISONAI_ALLOW_LOCAL_TOOLS env-var gate to the tool_override.py sinks. However, two additional spec.loader.exec_module call sites in…

  • CVE-2026-47397HigJul 21, 2026
    risk 0.39cvss —epss 0.00

    PraisonAI is a multi-agent teams system. Prior to version 4.6.40, hidden metadata in a webpage causes PraisonAI agents to write attacker-controlled content to arbitrary paths. `write_file` skips path validation when `workspace=None` (always `None` in production). Version 4.6.40…

  • CVE-2026-44907HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.01

    A denial of service vulnerability could be triggered by sending specially crafted HTTP requests to server function endpoints, this could lead to excessive CPU usage; affecting the following packages: react-server-dom-webpack, react-server-dom-parcel, react-server-dom-turbopack…

  • CVE-2026-24232MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-16454MedJul 21, 2026
    risk 0.21cvss 4.3epss 0.00

    In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identified in the Direct Device Integration (DDI) Controller. This vulnerability allows an authenticated device to escalate its permissions and bypass the strict…

  • CVE-2026-16451MedJul 21, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This impacts an unknown function of the file /api/system/file/upload of the component com.zs.file.controller.SysFileController. Performing a manipulation of the argument…

  • CVE-2026-15829HigJul 21, 2026
    risk 0.53cvss 8.1epss 0.00

    A SQL injection (CWE-89) and security boundary bypass (CWE-863) vulnerability exists in the prebuilt BigQuery forecasting tool (bigquery-forecast) of googleapis/mcp-toolbox. The tool accepts client-controlled parameters (data_col, timestamp_col, and id_cols) as plain strings…

  • CVE-2026-15793HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    BuildKit custom frontends or clients using the raw low-level API can set git.checkoutbundle=true when checking out Git sources. If the Git source is malicious, this could lead to a crafted command invocation on the host.

  • CVE-2026-15792HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

  • CVE-2026-15791HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    A crafted message in the BuildKit low-level build API can be used to remove the contents of the /tmp directory. The action that can normally be used to delete files inside the build container rootfs can escape into the real host temp directory.

  • CVE-2026-15789HigJul 21, 2026
    risk 0.00cvss 7.5epss 0.00

    A custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access the BuildKit control API to issue builds, e.g., bypass authentication, etc.

  • CVE-2026-15724HigJul 21, 2026
    risk 0.57cvss 8.7epss 0.01

    In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether…

  • CVE-2026-15432MedJul 21, 2026
    risk 0.38cvss 5.9epss 0.00

    When verifying a mac with a ChunkedMacVerification object, Tink compares the resulting tag with non constant time comparison. This potentially allows an attacker to use timinig information as a side channel in order to get information how many bytes of a given tag match the…

  • CVE-2026-15342MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected…

  • CVE-2025-68640MedJul 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The Apple Find My backend service through 2025-12-17 allows an attacker in possession of a valid PET (Private Endpoint Token) to enumerate devices and remove offline devices from an Apple ID account without triggering two-factor authentication or ownership verification. This may…

  • CVE-2026-64825CriJul 21, 2026
    risk 0.53cvss 9.3epss 0.01

    Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any directory on the host filesystem by uploading a crafted backup archive during the initial onboarding window. Attackers can manipulate…

  • CVE-2026-64824HigJul 21, 2026
    risk 0.00cvss 8.4epss 0.01

    Home Assistant Core before 2026.7.0 contains a path traversal vulnerability in the backup-restore function that allows attackers to write files to arbitrary absolute filesystem paths by supplying a crafted tar archive with a SYMTYPE entry containing a benign member name paired…