VYPR

CVEs

387,005 total · page 749 of 7,741

  • CVE-2026-16093MedJul 17, 2026
    risk 0.35cvss 5.4epss 0.00

    Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authentication. A flaw was discovered where this enforcement can be bypassed. An attacker with valid client credentials can provide a…

  • CVE-2026-12694CriJul 17, 2026
    risk 0.00cvss 9.1epss 0.00

    Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

  • CVE-2026-12693CriJul 17, 2026
    risk 0.00cvss 9.4epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

  • CVE-2026-12692CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

  • CVE-2026-12691HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.01

    Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.

  • CVE-2026-11763MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. GisLab Laboratory Management System allows Exploitation of Trusted Identifiers. This issue affects GisLab Laboratory Management…

  • CVE-2026-9537MedJul 17, 2026
    risk 0.27cvss 5.3epss 0.00

    Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time varies…

  • CVE-2026-63100MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify global hosting settings by exploiting unprotected show and update actions in the Settings::HostingsController, where the…

  • CVE-2026-63099MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. Attackers can exploit the…

  • CVE-2026-63098MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the…

  • CVE-2026-63097MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    Dendrite through 0.13.8 contains an improper access control vulnerability in the syncapi /context endpoint (syncapi/routing/context.go) that allows authenticated local users to access post-leave room state events by exploiting a flawed membership check that evaluates only the…

  • CVE-2026-63096MedJul 17, 2026
    risk 0.00cvss 5.8epss 0.00

    Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbound TLS connections to arbitrary hosts and ports by supplying an unvalidated serverName parameter to the legacy media download…

  • CVE-2026-63095MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to delete third-party identifier bindings belonging to other users by submitting an arbitrary address and medium to the account…

  • CVE-2026-60025HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection.

  • CVE-2026-60024CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 did by default allow unauthenticated users to upload media assets.

  • CVE-2026-58149MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenticated user enumeration that allows to retrieve account usernames and email addresses.

  • CVE-2026-58148HigJul 17, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

  • CVE-2026-15783MedJul 17, 2026
    risk 0.00cvss —epss 0.00

    A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any repository to read metadata from private repositories they did not have access to, including private repository owners and names, branch…

  • CVE-2026-15343HigJul 17, 2026
    risk 0.00cvss —epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updater container to write files to arbitrary repository paths, including GitHub Actions workflow files under .github/workflows/ as the…

  • CVE-2026-15007MedJul 17, 2026
    risk 0.00cvss —epss 0.01

    A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supplying a repository release notes configuration file containing deeply nested YAML. When release notes were generated, the…

  • CVE-2026-14871HigJul 17, 2026
    risk 0.39cvss —epss 0.00

    osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJAX ticket-management subsystem.

  • CVE-2026-14741HigJul 17, 2026
    risk 0.42cvss 7.5epss 0.01

    HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next…

  • CVE-2026-12715HigJul 17, 2026
    risk 0.00cvss —epss 0.00

    Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other users' deployed source code and access sensitive data via unauthorized GCS URL signing requests. This vulnerability was patched on…

  • CVE-2026-63094HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions…

  • CVE-2026-63093HigJul 17, 2026
    risk 0.57cvss 8.8epss 0.01

    Cursor for Windows version 3.2.16 contains a binary planting vulnerability that allows remote attackers to achieve arbitrary code execution by placing a malicious git.exe file in the repository root directory. When a developer clones and opens a crafted repository, Cursor…

  • CVE-2026-51083MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.

  • CVE-2026-51082HigJul 17, 2026
    risk 0.00cvss 7.2epss 0.00

    A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows…

  • CVE-2026-51081MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.

  • CVE-2026-16089MedJul 17, 2026
    risk 0.28cvss 5.4epss 0.00

    A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that originally requested them. An attacker who can intercept an authorization code can modify it to be…

  • CVE-2026-16017MedJul 17, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the component cron Chat Tool. The manipulation results in missing authorization. The attack may be performed from remote. The exploit has…

  • CVE-2026-12705MedJul 17, 2026
    risk 0.42cvss 6.4epss 0.00

    Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB): through 2.0.175; KNX Update Tool (BJE): through 2.0.175.

  • CVE-2026-9592HigJul 17, 2026
    risk 0.00cvss —epss 0.00

    SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is disclosed inside the URL and a HTTP header.

  • CVE-2026-7488HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.

  • CVE-2026-51080CriJul 17, 2026
    risk 0.64cvss 9.8epss 0.01

    libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

  • CVE-2026-16072MedJul 17, 2026
    risk 0.25cvss 4.9epss 0.00

    A flaw was found in the organization management component of Keycloak. A delegated administrator with permission to manage organizations can create an invitation for a non-existent email address and then retrieve the secret registration link directly through the application…

  • CVE-2026-16016HigJul 17, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument callback_url leads to server-side request forgery. The attack is possible to be carried out…

  • CVE-2026-16015MedJul 17, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was determined in poco-ai poco-claw up to 0.5.4. This vulnerability affects the function create_task of the file executor_manager/app/api/v1/tasks.py of the component executor_manager API. Executing a manipulation can lead to missing authentication. The exploit…

  • CVE-2025-60357HigJul 17, 2026
    risk 0.53cvss 8.1epss 0.00

    AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.

  • CVE-2024-42214MedJul 17, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.

  • CVE-2024-23578MedJul 17, 2026
    risk 0.27cvss 4.2epss 0.00

    HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).

  • CVE-2024-23577MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks,…

  • CVE-2024-23575MedJul 17, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.

  • CVE-2024-23574MedJul 17, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid…

  • CVE-2024-23573LowJul 17, 2026
    risk 0.24cvss 3.7epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be…

  • CVE-2024-23572MedJul 17, 2026
    risk 0.27cvss 4.2epss 0.00

    HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.

  • CVE-2024-23571MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this…

  • CVE-2024-23570MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing,…

  • CVE-2024-23569MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header

  • CVE-2024-23568MedJul 17, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly…

  • CVE-2024-23567MedJul 17, 2026
    risk 0.28cvss 4.3epss 0.00

    HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including…