VYPR

CVEs

386,791 total · page 726 of 7,736

  • CVE-2024-51314CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

  • CVE-2024-51312CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

  • CVE-2026-64651MedJul 20, 2026
    risk 0.00cvss —epss 0.00

    The `@ai-sdk/harness-opencode` tool connects HarnessAgent to OpenCode through a sandboxed bridge. Prior to version 1.0.28, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (`host-tool-mcp.mjs`). This allows untrusted…

  • CVE-2026-64650MedJul 20, 2026
    risk 0.00cvss —epss 0.00

    The `@ai-sdk/harness-opencode` tool is an HarnessV1 adapter backed by @openai/codex-sdk, which drives the codex command line interface. Prior to version 1.0.29, the tool relay authorizes requests from any process whose command line contains an allowed helper script path (the…

  • CVE-2026-58624MedJul 20, 2026
    risk 0.28cvss 5.4epss 0.01

    Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server such that SSH clients…

  • CVE-2026-56624HigJul 20, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper certificate validation in Apache MINA SSHD (server-side). Apache MINA SSHD is a Java library for client-side and server-side SSH. Server-side OpenSSH user certificate validation during user authentication in an Apache MINA SSHD server did not check for the…

  • CVE-2026-56623HigJul 20, 2026
    risk 0.39cvss 7.1epss 0.01

    Path traversal on Windows in Apache MINA SSHD component sshd-git. Apache MINA SSHD is a Java library for client-side and server-side SSH. A git server implemented with Apache MINA SSHD component sshd-git and running on Windows could allow an authenticated remote user access…

  • CVE-2026-56452HigJul 20, 2026
    risk 0.42cvss 7.5epss 0.01

    Path traversal in the sshd-scp component of Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. The implementation of receiving files or directories via SCP did not validate filenames in SCP "C" or "D" commands. A malicious sender could…

  • CVE-2026-55219MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementation in app/Livewire/Invoices/Show.php executes a pessimistic row lock (lockForUpdate()) outside of an active database transaction.…

  • CVE-2026-53596MedJul 20, 2026
    risk 0.00cvss 5.3epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does not enforce rate limiting on the file upload endpoint. Any user can flood the server with upload requests, leading to database…

  • CVE-2026-53595CriJul 20, 2026
    risk 0.00cvss 9.4epss 0.02

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{hash}/{invite_sent_at}` (`OpenController@userSetupSave`) selects the target account solely by its `invite_hash` column, then…

  • CVE-2026-53594MedJul 20, 2026
    risk 0.00cvss 4.9epss 0.01

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. FreeScout's `Manage -> Logs -> App Logs` feature uses the bundled `rap2hpoutre/laravel-log-viewer` override to decrypt a user-supplied file identifier and then pass the resolved path to Laravel's…

  • CVE-2026-47198HigJul 20, 2026
    risk 0.00cvss 8.5epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning…

  • CVE-2026-47130HigJul 20, 2026
    risk 0.00cvss 7.1epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR) vulnerability exists in the CRM contact and target update endpoints. The application fails to verify if the authenticated user…

  • CVE-2026-47129HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in the `activateUser` and `deactivateUser` Next.js Server Actions of NextCRM. The application fails to verify if the requesting user…

  • CVE-2026-44585MedJul 20, 2026
    risk 0.35cvss 5.4epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support…

  • CVE-2026-44584MedJul 20, 2026
    risk 0.28cvss 4.3epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain…

  • CVE-2026-44583MedJul 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the PAYPAL-CERT-URL HTTP header without validation, allowing attackers to control server-side…

  • CVE-2026-44509Jul 20, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candidate.

  • CVE-2026-44508Jul 20, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candidate.

  • CVE-2026-44507Jul 20, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43617. Reason: This candidate is a duplicate of CVE-2026-43617. Notes: All CVE users should reference CVE-2026-43617 instead of this candidate.

  • CVE-2026-13381HigJul 20, 2026
    risk 0.53cvss 8.1epss 0.00

    VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated attacker can manipulate the 'remark' request parameter to enumerate, retrieve, and delete files belonging to other users on the…

  • CVE-2026-13380HigJul 20, 2026
    risk 0.49cvss 7.5epss 0.00

    VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credentials are present in these responses only when SFTP connections have been configured within the application. No authentication is…

  • CVE-2024-51313CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.

  • CVE-2024-51311CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.

  • CVE-2026-63767CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers to execute arbitrary commands by sending crafted pickle payloads to the SchedulerServer ZMQ ROUTER socket bound to all interfaces.…

  • CVE-2026-63766CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.02

    GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate unsanitized Gradio textbox values directly into shell commands executed with shell=True. Attackers can inject shell…

  • CVE-2026-53593HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.01

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous file uploads (`Helper::$restricted_extensions`) is incomplete: it does not cover the `.pht` extension. The authenticated upload…

  • CVE-2026-53592MedJul 20, 2026
    risk 0.00cvss 4.6epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in the `getQueryParam` function `/public/js/main.js` and was addressed in version 1.8.139 by blocking URL query keys matching the pattern `__proto__`. However, this…

  • CVE-2026-53591HigJul 20, 2026
    risk 0.00cvss 8.6epss 0.00

    FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject messages into any existing support conversation by sending a single email to the helpdesk's public address with a crafted…

  • CVE-2026-44231CriJul 20, 2026
    risk 0.59cvss 9.1epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain…

  • CVE-2026-44230MedJul 20, 2026
    risk 0.40cvss 6.1epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT…

  • CVE-2026-44229MedJul 20, 2026
    risk 0.35cvss 5.4epss 0.00

    RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated…

  • CVE-2026-16337CriJul 20, 2026
    risk 0.00cvss —epss 0.01

    Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then…

  • CVE-2026-15788HigJul 20, 2026
    risk 0.49cvss 7.5epss 0.00

    BuildKit's cache mount source= selector on Windows Container on Windows (WCOW) workers does not detect NTFS directory junctions placed inside the cache root. A build authored by an untrusted user on a WCOW-configured BuildKit daemon can read arbitrary host files reachable to the…

  • CVE-2026-64619HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    FileCodeBox before 2.4 contains a rate-limit bypass vulnerability in the IPRateLimit class that allows unauthenticated attackers to circumvent request throttling by supplying attacker-controlled X-Real-IP and X-Forwarded-For headers without verification of trusted reverse proxy…

  • CVE-2026-64194HigJul 20, 2026
    risk 0.49cvss 7.5epss 0.01

    Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 1035 compression pointers by recursing into itself with no depth limit. It is possible to construct a name which saturates the call…

  • CVE-2026-64193CriJul 20, 2026
    risk 0.64cvss 9.8epss 0.01

    Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose parses the EXTRA-TEXT field of an EDNS EXTENDED-ERROR option (RFC 8914) by tokenising the raw bytes and passing the result to Perl's…

  • CVE-2026-63771HigJul 20, 2026
    risk 0.39cvss 7.1epss 0.00

    Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values through the unsanitized X-Forwarded-Prefix HTTP header used in Set-Cookie path attributes. Attackers can exploit a misconfigured…

  • CVE-2026-63770HigJul 20, 2026
    risk 0.42cvss 7.5epss 0.00

    Glance through 0.8.5 contains an IP address spoofing vulnerability in the authentication handler that allows unauthenticated attackers to bypass brute-force lockout protections by supplying arbitrary values in the X-Forwarded-For request header when the server proxied option is…

  • CVE-2026-63769HigJul 20, 2026
    risk 0.43cvss 7.7epss 0.00

    Huginn before 2026.09.09 contains a server-side request forgery vulnerability in the fetch_url method of ScenarioImport that allows authenticated users to make arbitrary HTTP requests by submitting crafted URLs. Attackers can probe internal network services, enumerate ports via…

  • CVE-2026-63768MedJul 20, 2026
    risk 0.28cvss 4.3epss 0.00

    cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows attackers to redirect users to arbitrary URLs by crafting malicious state parameters. Attackers can exploit the unsigned state parameter and onErrorReturnTo…

  • CVE-2026-63731HigJul 20, 2026
    risk 0.00cvss 7.7epss 0.00

    HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to arbitrary internal destinations by supplying a caller-controlled host parameter to the ClickHouse proxy test endpoint with no URL validation…

  • CVE-2026-63730MedJul 20, 2026
    risk 0.00cvss 5.0epss 0.00

    HyperDX before 2.31.0 contains a server-side request forgery vulnerability that allows authenticated team members to direct the server to make requests to arbitrary internal network destinations by supplying a caller-controlled URL to the webhook test endpoint. Attackers can…

  • CVE-2026-63108HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.02

    Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts…

  • CVE-2026-63107HigJul 20, 2026
    risk 0.00cvss 7.7epss 0.00

    LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authenticated users to cause the server to issue arbitrary HTTP requests by supplying a manipulated Host header. Attackers can exploit…

  • CVE-2026-62414CriJul 20, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply access control to frontend page list views.

  • CVE-2026-61901MedJul 20, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

  • CVE-2026-61900CriJul 20, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

  • CVE-2026-61425CriJul 20, 2026
    risk 0.00cvss —epss 0.01

    Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.