VYPR

CVEs

387,025 total · page 755 of 7,741

  • CVE-2026-10589MedJul 16, 2026
    risk 0.00cvss 6.0epss 0.00

    A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

  • CVE-2026-10588MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.

  • CVE-2026-10587MedJul 16, 2026
    risk 0.00cvss 6.0epss 0.00

    A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

  • CVE-2025-45870MedJul 16, 2026
    risk 0.42cvss 6.5epss 0.00

    LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the…

  • CVE-2026-63082MedJul 16, 2026
    risk 0.00cvss 5.4epss 0.00

    Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers with Agent-level privileges to manipulate the Support Agent assignment field of tickets by bypassing intended authorization…

  • CVE-2026-63081MedJul 16, 2026
    risk 0.00cvss 5.4epss 0.00

    Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated attackers with Agent-level privileges to inject malicious payloads into the Notes field of assigned support tickets. Attackers can…

  • CVE-2026-59867HigJul 16, 2026
    risk 0.39cvss 7.1epss 0.02

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced…

  • CVE-2026-59866CriJul 16, 2026
    risk 0.54cvss —epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path…

  • CVE-2026-59865CriJul 16, 2026
    risk 0.54cvss —epss 0.04

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation..dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied…

  • CVE-2026-59864CriJul 16, 2026
    risk 0.54cvss —epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft…

  • CVE-2026-57206HigJul 16, 2026
    risk 0.49cvss 8.6epss 0.01

    SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST…

  • CVE-2026-57205MedJul 16, 2026
    risk 0.21cvss 4.3epss 0.01

    SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in…

  • CVE-2026-55440MedJul 16, 2026
    risk 0.35cvss 6.5epss 0.01

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.7, the COMMAND_RESULTS handler in ufo/server/ws/handler.py called get_or_create_session in ufo/server/services/session_manager.py without owner_client_id, allowing an…

  • CVE-2026-54733CriJul 16, 2026
    risk 0.54cvss —epss 0.01

    The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0.5, and 5.1.1, the Microsoft Office 365 Integration plugin local_o365 Teams SSO endpoint sso_login.php base64-decodes a JWT…

  • CVE-2026-54568MedJul 16, 2026
    risk 0.21cvss 4.3epss 0.01

    Microsoft UFO open-source framework for intelligent automation across devices and platforms. From 3.0.0 until 3.0.6, a client connected to the UFO WebSocket server as a DEVICE could call DEVICE_INFO_REQUEST with another device's target_id and receive that device's server-side…

  • CVE-2026-53598HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 2.0.0-beta.2, Prompty loaders expanded ${file:...} references in .prompty frontmatter without enforcing that resolved paths stayed within the prompt directory or allowed roots, allowing an attacker-controlled…

  • CVE-2026-53597HigJul 16, 2026
    risk 0.50cvss —epss 0.01

    Prompty is a markdown file format (.prompty) for LLM prompts. From 2.0.0-alpha.1 until 2.0.0-beta.3, the @prompty/core TypeScript loader in runtime/typescript/packages/core/src/core/loader.ts used gray-matter without overriding executable js and javascript frontmatter engines,…

  • CVE-2026-45695CriJul 16, 2026
    risk 0.57cvss 9.8epss 0.02

    Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, and data deduplication. Prior to 0.23.0, Kopia's HTTP server started with --without-password accepts unauthenticated requests to…

  • CVE-2026-14890CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authentication or deserialization safeguards, allowing an attacker to provide a malicious pickle file that results in unauthenticated remote…

  • CVE-2026-12379MedJul 16, 2026
    risk 0.00cvss —epss 0.00

    An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authentication redirect to the application's own origin, so a user who follows a crafted login link can be…

  • CVE-2025-45868HigJul 16, 2026
    risk 0.57cvss 8.8epss 0.01

    LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.

  • CVE-2026-59863HigJul 16, 2026
    risk 0.39cvss —epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing…

  • CVE-2026-59862HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and…

  • CVE-2026-59861HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.02

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs…

  • CVE-2026-59860HigJul 16, 2026
    risk 0.50cvss —epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// ……

  • CVE-2026-59859HigJul 16, 2026
    risk 0.50cvss —epss 0.01

    Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in…

  • CVE-2026-59237MedJul 16, 2026
    risk 0.00cvss —epss 0.01

    Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belonging to any other company (tenant) via…

  • CVE-2026-14254HigJul 16, 2026
    risk 0.00cvss —epss 0.01

    A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login attempts were processed before the failed-login counter and lockout status were updated,…

  • CVE-2026-5674HigJul 16, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a…

  • CVE-2026-56456MedJul 16, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability. The application dashboard inadvertently leaks sensitive information regarding its internal file structure and directory paths through unhandled error messages, system logs, or debugging output, which…

  • CVE-2026-56455MedJul 16, 2026
    risk 0.00cvss 5.3epss 0.00

    HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS). The application fails to properly validate input sizes, allowing an attacker to pass an excessive amount of information into a memory container, which can cause the system…

  • CVE-2026-56454MedJul 16, 2026
    risk 0.00cvss 5.9epss 0.00

    HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1. These legacy protocols contain numerous cryptographic design flaws that expose data to interception and decryption. To remediate this risk, the application must disable all…

  • CVE-2026-56453MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents of the server's HTTP responses before they reach the client application, allowing them to manipulate the authentication or…

  • CVE-2026-35145LowJul 16, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability. The application fails to implement the HTTP Strict Transport Security (HSTS) policy within its responses, which could allow a remote attacker to downgrade the communication channel to…

  • CVE-2026-35143LowJul 16, 2026
    risk 0.00cvss 3.0epss 0.00

    HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability. The application fails to set the "SameSite" attribute on session cookies generated during authentication, which could allow a remote attacker to execute Cross-Site Request Forgery (CSRF) attacks if…

  • CVE-2026-35142LowJul 16, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability. The application includes internal IP address details within its generated server responses, which could allow a remote attacker to gather sensitive network topology information and use it to map the…

  • CVE-2026-35141LowJul 16, 2026
    risk 0.00cvss 2.6epss 0.00

    HCL DFXAnalytics is affected by a Login Replay Attack vulnerability. The application allows a remote attacker to intercept, delay, or fraudulently retransmit valid authentication data to achieve unauthorized access. To mitigate this risk, the application must implement a…

  • CVE-2026-35140LowJul 16, 2026
    risk 0.00cvss 3.0epss 0.00

    HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability. The application fails to set the "secure" attribute on session cookies generated during authentication, which could allow a remote attacker to intercept network traffic…

  • CVE-2026-9494MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is…

  • CVE-2026-63306HigJul 16, 2026
    risk 0.56cvss 8.6epss 0.00

    stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint…

  • CVE-2026-63305HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.02

    AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell…

  • CVE-2026-63304HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.02

    AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can craft a valid encrypted…

  • CVE-2026-12391MedJul 16, 2026
    risk 0.00cvss 5.0epss 0.00

    An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering…

  • CVE-2026-11386CriJul 16, 2026
    risk 0.00cvss 9.0epss 0.01

    An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the…

  • CVE-2025-71388HigJul 16, 2026
    risk 0.42cvss —epss 0.00

    stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks.…

  • CVE-2025-71377HigJul 16, 2026
    risk 0.50cvss —epss 0.01

    stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated…

  • CVE-2024-58360MedJul 16, 2026
    risk 0.35cvss 6.5epss 0.00

    stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and…

  • CVE-2026-59249MedJul 16, 2026
    risk 0.00cvss —epss 0.01

    Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling response-queue poisoning against…

  • CVE-2026-35149HigJul 16, 2026
    risk 0.00cvss 8.2epss 0.00

    HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized…

  • CVE-2026-35148MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without…