VYPR

CVEs

387,160 total · page 766 of 7,744

  • CVE-2026-15751MedJul 14, 2026
    risk 0.00cvss 5.3epss 0.00

    A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is the function execute of the file mastergo/component-workflow.md of the component mcp__getComponentGenerator. The manipulation of the argument rootPath leads to…

  • CVE-2025-56365MedJul 14, 2026
    risk 0.30cvss 5.7epss 0.00

    A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the code incorrectly treats the endpoint as…

  • CVE-2025-56364MedJul 14, 2026
    risk 0.30cvss 5.7epss 0.00

    A use of uninitialized value vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, where the `GetDestinationGroupId().Value()` method is called without first checking whether a value exists. This leads to a crash when an InvokeCommand is sent without…

  • CVE-2025-56363MedJul 14, 2026
    risk 0.30cvss 5.7epss 0.00

    A null pointer dereference vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, affecting the ReadRevisionAttribute function used in multiple clusters (Channel, Account Login, TargetNavigator, etc.). The function lacks proper validation of the delegate pointer…

  • CVE-2025-56362MedJul 14, 2026
    risk 0.30cvss 5.7epss 0.00

    A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is sent and immediately followed by a write of OperationMode=2 (in the Pump…

  • CVE-2026-59733HigJul 14, 2026
    risk 0.50cvss 8.8epss 0.01

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone serve restic --private-repos enforces authorization using the routed user path segment while building the backend object key from the raw…

  • CVE-2026-59732MedJul 14, 2026
    risk 0.26cvss 5.0epss 0.00

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, rclone archive extract can write extracted files outside the user-selected destination prefix when extracting a crafted archive containing parent path…

  • CVE-2026-54684HigJul 14, 2026
    risk 0.39cvss 7.0epss 0.00

    jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicious .xapk file can cause jadx to write attacker-controlled archive entry contents outside the intended XAPK plugin temporary unpack directory because XApkLoader resolves each entry name directly with…

  • CVE-2026-54572HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links, rclone serializes symlinks as .rclonelink text objects and recreates them on a local destination without validating the target,…

  • CVE-2026-50130HigJul 14, 2026
    risk 0.50cvss 8.8epss 0.00

    Pi-hole is a DNS sinkhole that protects devices from unwanted content without installing any client-side software. From 6.0 to 6.4.2, a user with code execution as the unprivileged pihole user can escalate to root by replacing /etc/pihole/logrotate. The replacement is laundered…

  • CVE-2026-49981HigJul 14, 2026
    risk 0.46cvss 8.2epss 0.00

    Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a…

  • CVE-2026-48808HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read…

  • CVE-2026-48807CriJul 14, 2026
    risk 0.59cvss 9.1epss 0.00

    Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings…

  • CVE-2026-48806CriJul 14, 2026
    risk 0.59cvss 9.1epss 0.00

    Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This…

  • CVE-2026-48805CriJul 14, 2026
    risk 0.59cvss 9.1epss 0.00

    Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(),…

  • CVE-2026-48357MedJul 14, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition.…

  • CVE-2026-48354MedJul 14, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this…

  • CVE-2026-48353MedJul 14, 2026
    risk 0.36cvss 5.5epss 0.00

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue…

  • CVE-2026-48352HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue…

  • CVE-2026-48351HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue…

  • CVE-2026-48337HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48336HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48335HigJul 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Illustrator is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • CVE-2026-48334CriJul 14, 2026
    risk 0.60cvss 9.3epss 0.01

    Illustrator is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user…

  • CVE-2026-48312MedJul 14, 2026
    risk 0.44cvss 6.8epss 0.00

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized write access. Exploitation of this issue does not…

  • CVE-2026-48302MedJul 14, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue…

  • CVE-2026-48298MedJul 14, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-48296MedJul 14, 2026
    risk 0.40cvss 6.2epss 0.00

    CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of…

  • CVE-2026-48295HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    CAI Content Credentials is affected by an Insufficiently Protected Credentials vulnerability that could result in disclosure of sensitive information. An attacker could leverage this vulnerability to gain unauthorized read access. Exploitation of this issue does not require user…

  • CVE-2026-48290HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.00

    CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially…

  • CVE-2026-48287HigJul 14, 2026
    risk 0.48cvss 7.4epss 0.00

    CAI Content Credentials is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in…

  • CVE-2026-48275HigJul 14, 2026
    risk 0.56cvss 8.6epss 0.00

    Illustrator is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

  • CVE-2026-47732MedJul 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in…

  • CVE-2026-47730MedJul 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser…

  • CVE-2026-46640HigJul 14, 2026
    risk 0.50cvss 8.8epss 0.01

    Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.() and import-alias dynamic attribute syntax can concatenate an attacker-controlled string into a MacroReferenceExpression name without identifier validation, causing raw PHP to be emitted into the…

  • CVE-2026-46639MedJul 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::getAttribute() with the sandbox argument hardcoded to false, disabling property and method policy checks and allowing an attacker with write access to a…

  • CVE-2026-46638HigJul 14, 2026
    risk 0.46cvss 8.1epss 0.00

    Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been…

  • CVE-2026-46637MedJul 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output…

  • CVE-2026-46635MedJul 14, 2026
    risk 0.21cvss 4.3epss 0.00

    Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template…

  • CVE-2026-46634CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.01

    Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__ name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call…

  • CVE-2026-46633CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.01

    Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP…

  • CVE-2026-46629MedJul 14, 2026
    risk 0.35cvss 6.5epss 0.01

    Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects…

  • CVE-2026-46628MedJul 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0.

  • CVE-2026-46627MedJul 14, 2026
    risk 0.42cvss 6.5epss 0.01

    Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version…

  • CVE-2026-45363CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because OpenSSL::HMAC.digest('SHA256', '', payload) returns a valid digest under an empty…

  • CVE-2026-42447LowJul 14, 2026
    risk 0.16cvss 3.6epss 0.00

    jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx-gui is affected by an HTML injection vulnerability in the Summary tab because SummaryNode.java appends arches and perArchCount values derived from .so file path components inside an APK into an HTML panel without escaping. A…

  • CVE-2026-42049HigJul 14, 2026
    risk 0.48cvss —epss 0.00

    jadx is a Dex to Java decompiler. Prior to 1.5.6, jadx inserts the android:versionName value from an AndroidManifest into the generated app/build.gradle Groovy template without proper sanitization when exporting a decompiled APK as an Android Gradle project. A malicious APK can…

  • CVE-2026-38450CriJul 14, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in Aetopia Digital Asset Management DAM v.1.0.0 allows a remote attacker to execute arbitrary code via the name and description parameter of the Add/Update Project function

  • CVE-2026-21840LowJul 14, 2026
    risk 0.00cvss 3.1epss 0.00

    HCL BigFix Platform is affected by a user enumeration vulnerability which might allow an attacker, through careful system control and response time monitoring, to perform some level of user enumeration for the BigFix service.

  • CVE-2026-15750MedJul 14, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in mastergo-design mastergo-magic-mcp up to 0.2.0. Impacted is the function z.string of the file src/tools/get-component-link.ts of the component mcp__getComponentLink. Executing a manipulation of the argument url can lead to server-side request…