VYPR

CVEs

387,099 total · page 762 of 7,742

  • CVE-2026-47142higJul 15, 2026
    risk 0.38cvss —epss —

    MantisBT 2.28.3 and earlier versions contains a SQL injection vulnerability in core/history_api.php. The history_order configuration value is concatenated directly into a SQL ORDER BY clause without any sanitisation, parameterization, or validation against a whitelist. An…

  • CVE-2026-9007MedJul 15, 2026
    risk 0.00cvss —epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (XSS).  Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of…

  • CVE-2026-62843MedJul 15, 2026
    risk 0.37cvss 6.8epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as…

  • CVE-2026-62685HigJul 15, 2026
    risk 0.46cvss 8.1epss 0.01

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=true and CreateUserDir=true,…

  • CVE-2026-62683LowJul 15, 2026
    risk 0.00cvss 3.1epss 0.00

    File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can leave a public directory share behind when the shared directory is deleted through a path with a trailing…

  • CVE-2026-61828HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    Nixpkgs is a collection of software packages that can be installed with the Nix package manager. Prior to the 25.11 and 26.05 channel fixes, the NixOS module for MySQL services.mysql initializes the MySQL database in a way that allows local users, such as unprivileged web or CGI…

  • CVE-2026-61605Jul 15, 2026
    risk 0.00cvss —epss —

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-58655. Reason: This candidate is a duplicate of CVE-2026-58655. Notes: All CVE users should reference CVE-2026-58655 instead of this candidate.

  • CVE-2026-61371HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.01

    Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes…

  • CVE-2026-60005HigJul 15, 2026
    risk 0.53cvss 8.2epss 0.01

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized…

  • CVE-2026-55242HigJul 15, 2026
    risk 0.50cvss 8.8epss 0.00

    ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational role can trigger server-side template injection through a configuration field, resulting in unauthorized disclosure of data…

  • CVE-2026-50148CriJul 15, 2026
    risk 0.00cvss 10.0epss 0.01

    Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10, and 1.60.4, a Metabase user with permission to add or edit a database connection can achieve remote code execution on the…

  • CVE-2026-50147HigJul 15, 2026
    risk 0.00cvss 7.6epss 0.00

    Metabase is an open-source business intelligence and embedded analytics tool. From 1.57.0 until 1.57.19.1, 1.58.14.1, 1.59.10, and 1.60.4, an attacker who can configure a Metabase database connection can read arbitrary files from the Metabase server's filesystem by adding unsafe…

  • CVE-2026-47164HigJul 15, 2026
    risk 0.43cvss 7.7epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO login flow checked the IdP email_verified claim only for new-user creation and not when SSO_SIGNUPS_MATCH_EMAIL=true linked an IdP identity to an existing local account, allowing an…

  • CVE-2026-47160MedJul 15, 2026
    risk 0.31cvss 5.8epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png endpoint used src/http_client.rs checks including should_block_address() and post_resolve() that missed decimal, hexadecimal, and octal IP representations,…

  • CVE-2026-47159MedJul 15, 2026
    risk 0.38cvss —epss 0.01

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO discovery and pre-validation flow returned organization-related SSO metadata including organizationIdentifier values for arbitrary email addresses and allowed a valid pre-validation…

  • CVE-2026-47158HigJul 15, 2026
    risk 0.47cvss 8.3epss 0.00

    Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's SSO authorization flow did not bind the OAuth state parameter accepted by /connect/authorize to the initiating browser session, allowed attacker-controlled PKCE parameters, and left…

  • CVE-2026-46709HigJul 15, 2026
    risk 0.44cvss 7.8epss 0.00

    Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths from tabby-electron/src/pathDrop.ts into the active shell without neutralizing command substitution metacharacters such as $(…) and `…`, so the incomplete…

  • CVE-2026-45806HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url from frontend/src/app/main/data/workspace/media.cljs into the backend RPC method :create-file-media-object-from-url in…

  • CVE-2026-45805HigJul 15, 2026
    risk 0.50cvss 8.8epss 0.00

    Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot MCP's mcp/packages/server/src/ReplServer.ts bound the ReplServer to 0.0.0.0:4403 and exposed an unauthenticated /execute endpoint that passed the code field to…

  • CVE-2026-45150MedJul 15, 2026
    risk 0.34cvss —epss 0.00

    Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted…

  • CVE-2026-44986CriJul 15, 2026
    risk 0.57cvss 9.9epss 0.01

    Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations, embedded an existing profile id in auth.clj prepare-register-profile, and had auth.clj register-profile…

  • CVE-2026-41580MedJul 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, Stirling-PDF's /get-info-on-pdf endpoint rendered PDF Title and Author metadata fields without proper HTML encoding or sanitization, allowing a crafted PDF to…

  • CVE-2026-62294MedJul 15, 2026
    risk 0.26cvss —epss 0.00

    Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same…

  • CVE-2026-61836HigJul 15, 2026
    risk 0.49cvss 8.6epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path, query, and accountability.user but omits authorization context…

  • CVE-2026-61835HigJul 15, 2026
    risk 0.43cvss 7.7epss 0.00

    Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Directus's file-import-from-URL feature can be bypassed using the address 0.0.0.0 because api/src/request/is-denied-ip.ts treats 0.0.0.0 as a keyword for…

  • CVE-2026-61740CriJul 15, 2026
    risk 0.54cvss —epss 0.01

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUNTS unset, X-API-Key protection can be bypassed because lightrag/api/auth.py falls back to a hardcoded DEFAULT_TOKEN_SECRET,…

  • CVE-2026-61736CriJul 15, 2026
    risk 0.54cvss 9.3epss 0.01

    LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentials=True in lightrag/api/lightrag_server.py, causing Starlette CORSMiddleware to effectively whitelist every origin for…

  • CVE-2026-61684HigJul 15, 2026
    risk 0.00cvss —epss 0.01

    FastGPT is a knowledge-based AI application platform. In 4.15.0-beta4, FastGPT plugin invoke reverse-call endpoints under /api/invoke/* authenticate only by verifying a JWT signed with INVOKE_TOKEN_SECRET, which defaults to the constant string token and was not set in official…

  • CVE-2026-61646MedJul 15, 2026
    risk 0.00cvss —epss 0.00

    FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL before handing the request to axios, and axios follows redirects by default. An authenticated workflow user can configure an HTTP…

  • CVE-2026-61644HigJul 15, 2026
    risk 0.00cvss 7.7epss 0.00

    FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, the POST /api/core/chat/record/getCollectionQuote endpoint authenticates the caller's chat and collection context, but the initialId center-node lookup is not bound to that authorized context.…

  • CVE-2026-61613HigJul 15, 2026
    risk 0.00cvss —epss 0.01

    Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowed attacker-controlled web content to connect from inside the agent container to an unauthenticated local agent endpoint, enabling…

  • CVE-2026-60065LowJul 15, 2026
    risk 0.24cvss 3.7epss 0.00

    When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker…

  • CVE-2026-60062MedJul 15, 2026
    risk 0.42cvss 6.4epss 0.00

    The NGINX Agent config_dirs directive allows a low-privileged attacker to gain limited read and write access to files outside of the designated secure directory. The config_dirs directive required for this issue can also be configured through NGINX Instance Manager. A…

  • CVE-2026-59762HigJul 15, 2026
    risk 0.49cvss 7.5epss 0.01

    When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.   Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability…

  • CVE-2026-56434MedJul 15, 2026
    risk 0.42cvss 6.5epss 0.00

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with…

  • CVE-2026-55723HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.01

    When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX…

  • CVE-2026-54563HigJul 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded request suffix to the account…

  • CVE-2026-54562MedJul 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, localhost, IPv6 localhost, or…

  • CVE-2026-54560HigJul 15, 2026
    risk 0.42cvss 7.6epss 0.00

    Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredScopes treats the request like…

  • CVE-2026-52865MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.01

    When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress…

  • CVE-2026-42533HigJul 15, 2026
    risk 0.53cvss 8.1epss 0.01

    A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a…

  • CVE-2026-33213MedJul 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Redash is a package for data visualization and sharing. From 5.0.2 to 26.3.0, the get_next_path() function in Redash's authentication module stripped the scheme and netloc from user-supplied next parameters but did not normalize multiple leading slashes, allowing a crafted login…

  • CVE-2026-62175Jul 15, 2026
    risk 0.00cvss —epss —

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-60091. Reason: This candidate is a duplicate of CVE-2026-60091. Notes: All CVE users should reference CVE-2026-60091 instead of this candidate.

  • CVE-2026-59838MedJul 15, 2026
    risk 0.00cvss 5.9epss 0.00

    A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM…

  • CVE-2026-43637CriJul 15, 2026
    risk 0.52cvss 9.1epss 0.01

    Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache directory by supplying a crafted TAR archive containing ../ sequences, absolute paths, or symlink/hardlink entries to the…

  • CVE-2026-58559MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.00

    DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58558HigJul 15, 2026
    risk 0.00cvss 7.8epss 0.00

    Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2026-58557MedJul 15, 2026
    risk 0.00cvss 4.8epss 0.00

    Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58556MedJul 15, 2026
    risk 0.00cvss 5.1epss 0.00

    Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2026-58555MedJul 15, 2026
    risk 0.00cvss 6.6epss 0.00

    Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.