VYPR

CVEs

386,791 total · page 728 of 7,736

  • CVE-2026-42218MedJul 20, 2026
    risk 0.27cvss 5.3epss 0.00

    xrdp is an open source RDP server. Versions 0.10.6 and prior contain a timing side-channel vulnerability in the login interface. Due to a discrepancy in response processing times, a remote attacker can infer the existence of a username on the system, leading to unauthorized…

  • CVE-2026-42210MedJul 20, 2026
    risk 0.00cvss —epss 0.01

    Webmin is a web-based system administration tool for Unix-like servers. Prior to version 2.640, for Webmin accounts that require a second authentication factor (typically TOTP), an attacker with knowledge of the username and password can bypass the 2FA requirement by using Basic…

  • CVE-2026-41521HigJul 20, 2026
    risk 0.46cvss 8.2epss 0.01

    xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during…

  • CVE-2026-41252CriJul 20, 2026
    risk 0.57cvss 9.8epss 0.01

    xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages from a VNC server, where…

  • CVE-2026-40187HigJul 20, 2026
    risk 0.00cvss —epss 0.01

    In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTemplate XML file (`.xet`) to the VFS `/etemplates` mount. The `Widget::expand_name()` method passes template widget attribute values…

  • CVE-2026-39879HigJul 20, 2026
    risk 0.39cvss 7.1epss 0.00

    Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/modules/afsql/afsql.c#L219), syslog-ng before 4.12 are vulnerable to SQL injection from an untrusted source. This is not part of the…

  • CVE-2026-39385HigJul 20, 2026
    risk 0.00cvss —epss 0.00

    Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using unrelated batch. This has been patched in 2.52.0 with enrollment now validating that the batch is linked to course.

  • CVE-2026-35591HigJul 20, 2026
    risk 0.44cvss 7.8epss 0.00

    libvips is a fast image processing library with low memory needs. The `tiffload` operation in libvips versions before and including 8.18.1 could incorrectly determine the number of channels in a JPEG or JPEG2000-encoded tile within a TIFF image, leading to a possible buffer…

  • CVE-2026-35590MedJul 20, 2026
    risk 0.29cvss 5.5epss 0.00

    libvips is a fast image processing library with low memory needs. The EXIF decoder within libvips versions before and including 8.18.1 was not verifying the range of EXIF tag groups before passing data to libexif, leading to a possible null pointer dereference and crash. This…

  • CVE-2026-35217MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.00

    NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Options` field, the broker may still accept the malformed packet and install the subscription into internal broker state. Under a…

  • CVE-2026-35048CriJul 20, 2026
    risk 0.00cvss 9.8epss 0.01

    The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it checks for…

  • CVE-2026-33328MedJul 20, 2026
    risk 0.29cvss 5.5epss 0.00

    libvips is a fast image processing library with low memory needs. On 32-bit systems in versions before and including 8.18.0, the `gifload` operation could incorrectly determine dimensions leading to an integer overflow. This has been patched in version 8.18.1.

  • CVE-2026-33327HigJul 20, 2026
    risk 0.44cvss 7.8epss 0.00

    libvips is a fast image processing library with low memory needs. The `vipsload` operation in versions before and including 8.18.0 could incorrectly determine image dimensions leading to an integer overflow and a subsequent heap-based buffer overflow. This has been patched in…

  • CVE-2026-32825HigJul 20, 2026
    risk 0.00cvss 7.3epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application accepts unlimited password guesses…

  • CVE-2026-32824HigJul 20, 2026
    risk 0.00cvss 7.3epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a low-privileged authenticated API user can supply…

  • CVE-2026-32823MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the application exposes server-side state changes…

  • CVE-2026-32821HigJul 20, 2026
    risk 0.00cvss 8.1epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated API user who has their own access…

  • CVE-2026-32820HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.01

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, the documentation and static markdown renderer…

  • CVE-2026-32819MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, a Standard user can enumerate other users' names…

  • CVE-2026-32806HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any authenticated user can request arbitrary…

  • CVE-2026-16312Jul 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-6793MedJul 20, 2026
    risk 0.00cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS. This issue affects Q-smart NexT Poll: before 1.8.7.

  • CVE-2026-63429HigJul 20, 2026
    risk 0.00cvss 8.6epss 0.01

    HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `POST /api/upload` has no authentication guard, no global guard, no form-context validation, no `openToken` requirement, and no session cookie check. Any anonymous internet user can upload files (PDF, DOC/DOCX,…

  • CVE-2026-63428MedJul 20, 2026
    risk 0.00cvss 5.8epss 0.00

    HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from the submitter and stores it verbatim in `submission.hiddenFields`, without validating the supplied `id`/`name` against the form's…

  • CVE-2026-63102MedJul 20, 2026
    risk 0.35cvss 5.4epss 0.00

    rConfig Core before 8.2.8 contains a privilege escalation vulnerability that allows authenticated users to assign arbitrary roles to any account by submitting an unvalidated role field through the Users API during user creation or profile updates. Attackers can exploit the…

  • CVE-2026-51027CriJul 20, 2026
    risk 0.00cvss 9.9epss 0.01

    An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

  • CVE-2026-51026MedJul 20, 2026
    risk 0.00cvss 6.5epss 0.01

    Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

  • CVE-2026-48824MedJul 20, 2026
    risk 0.27cvss 5.3epss 0.01

    Mailpit is an email testing tool and API for developers. Prior to version 1.30.1, the fix for GHSA-fpxj-m5q8-fphw (CVE-2026-45710, "Mailpit: Set a default 50MB p/m limit to prevent DoS via unlimited SMTP DATA and /api/v1/send body sizes") wrapped only `POST /api/v1/send` with…

  • CVE-2026-46671MedJul 20, 2026
    risk 0.22cvss 4.4epss 0.00

    Rust OneNote File Parser is a parser for Microsoft OneNote files implemented in Rust. Prior to version 1.1.1, a maliciously crafted `.onetoc2` table-of-contents file can cause `Parser::parse_notebook` to open arbitrary files on the host filesystem outside the notebook's…

  • CVE-2026-46428CriJul 20, 2026
    risk 0.52cvss —epss 0.00

    lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` integration silently disables TLS hostname verification for callers using the default (strict) configuration. An on-path attacker…

  • CVE-2026-46415HigJul 20, 2026
    risk 0.46cvss 8.2epss 0.00

    The Caddy Defender plugin is a middleware for Caddy that allows users to block or manipulate requests based on the client's IP address. Prior to version 0.10.1, Caddy Defender used `r.RemoteAddr` when evaluating whether a request should be blocked. `RemoteAddr` is the address of…

  • CVE-2026-46412CriJul 20, 2026
    risk 0.65cvss 10.0epss 0.01

    @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UTC and 22:56 UTC, an attacker used a compromised npm publish token to publish 18 malicious versions of `@beproduct/nestjs-auth`…

  • CVE-2026-45797MedJul 20, 2026
    risk 0.00cvss —epss 0.01

    HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, the `/api/upload` endpoint allows unauthenticated file uploads including SVG files. Uploaded SVGs are stored in the static assets directory and served with `Content-Type: image/svg+xml` by Express's…

  • CVE-2026-45713HigJul 20, 2026
    risk 0.42cvss 7.5epss 0.01

    Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the Mailpit SMTP server has a Server.MaxSize int field that controls the maximum allowed DATA payload size, but the field is never assigned anywhere outside test code, leaving it at Go's zero value…

  • CVE-2026-45712MedJul 20, 2026
    risk 0.31cvss 5.9epss 0.00

    Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the screenshot/print proxy (/proxy?data=…) maintains a package-level assets map[string]MessageAssets cache, but reads the map without holding assetsMutex while a long-running cleanup goroutine…

  • CVE-2026-45711MedJul 20, 2026
    risk 0.31cvss 5.9epss 0.00

    Mailpit is an email testing tool and API for developers. Prior to version 1.30.0, the mailpit dump --http sub-command downloads every message from a remote Mailpit instance and writes each one as .eml inside the user-supplied output directory. The…

  • CVE-2026-45709MedJul 20, 2026
    risk 0.31cvss 5.8epss 0.00

    Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side Request Forgery (SSRF) via HTML Check API"), shipped in mailpit `v1.28.3`, hardened `internal/htmlcheck/css.go::downloadCSSToBytes` with a 5MB size cap, a…

  • CVE-2026-35198CriJul 20, 2026
    risk 0.52cvss 9.0epss 0.00

    HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a low-privileged team member to inject malicious JavaScript that executes when a team owner views the form, leading to complete…

  • CVE-2026-32822MedJul 20, 2026
    risk 0.00cvss 6.1epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, any unauthenticated attacker can place arbitrary…

  • CVE-2026-32807HigJul 20, 2026
    risk 0.00cvss 7.5epss 0.00

    dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handling core processing and framework rules, before and including version 25.07.3, anyone with a DataLink UUID can fetch the attached…

  • CVE-2026-28220HigJul 20, 2026
    risk 0.00cvss 8.4epss 0.01

    Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distributed API (DAPI) handling allow a cluster peer, or any actor able to authenticate to the cluster channel using the shared cluster…

  • CVE-2026-27823HigJul 20, 2026
    risk 0.00cvss —epss 0.01

    A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute arbitrary commands on the server. If user self-registration is enabled, the vulnerability may be exploitable without prior…

  • CVE-2026-26199MedJul 20, 2026
    risk 0.35cvss 6.5epss 0.00

    HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if…

  • CVE-2026-26197HigJul 20, 2026
    risk 0.42cvss 7.5epss 0.00

    HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If a file is corrupted such that an array datatype's size, the number of elements, and the element size are not in agreement it can trigger an out of bounds read. The array…

  • CVE-2026-26081MedJul 20, 2026
    risk 0.31cvss 4.8epss 0.00

    HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

  • CVE-2026-26080LowJul 20, 2026
    risk 0.24cvss 3.7epss 0.01

    HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

  • CVE-2026-25039HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.01

    Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creating a vulnerability if that workspace name is a UNC path. When creating mountpoint in the windows filesystem to mount the…

  • CVE-2026-21824HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.00

    HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of unauthorized administrative operations.

  • CVE-2026-13724MedJul 20, 2026
    risk 0.00cvss 4.3epss 0.00

    Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before…

  • CVE-2026-63091MedJul 20, 2026
    risk 0.35cvss 6.5epss 0.01

    ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow vulnerability in the mod_sftp module's SCP size-record parser that allows authenticated low-privilege attackers to bypass ASLR by sending a crafted file size value of UINT64_MAX, which results in a negative…