VYPR

CVEs

387,226 total · page 771 of 7,745

  • CVE-2026-47996MedJul 14, 2026
    risk 0.44cvss 6.8epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. A high-privileged attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this…

  • CVE-2026-47995HigJul 14, 2026
    risk 0.53cvss 8.1epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-47994HigJul 14, 2026
    risk 0.57cvss 8.7epss 0.01

    Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page…

  • CVE-2026-47992HigJul 14, 2026
    risk 0.47cvss 7.2epss 0.01

    Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this vulnerability to…

  • CVE-2026-47988HigJul 14, 2026
    risk 0.56cvss 8.6epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access, causing a limited disruption to…

  • CVE-2026-47984HigJul 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and limited write access. Exploitation of this issue does…

  • CVE-2026-47737HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers…

  • CVE-2026-47736HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer while waiting for CRLF to determine whether a PROXY v1 line is present, allowing an attacker that…

  • CVE-2026-47482HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47481MedJul 14, 2026
    risk 0.00cvss 6.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an authentication bypass through an alternative path or channel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information…

  • CVE-2026-47480HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47479HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47478HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47477HigJul 14, 2026
    risk 0.00cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47476HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.

  • CVE-2026-47429CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.01

    Vitest is a testing framework powered by Vite. Prior to 3.2.5 and 4.1.0, the Vitest UI/API server on Windows used isFileServingAllowed incorrectly for /__vitest_attachment__, allowing \\?\\..\\ path traversal to read files outside the project; exposed API write and rerun…

  • CVE-2026-47428CriJul 14, 2026
    risk 0.55cvss 9.6epss 0.01

    Vitest is a testing framework powered by Vite. From 4.0.17 until 4.1.6 and 5.0.0-beta.3, Vitest Browser Mode served /__vitest_test__/ with the otelCarrier query parameter inserted directly into an inline module script, allowing a crafted browser-runner URL to execute arbitrary…

  • CVE-2026-47423HigJul 14, 2026
    risk 0.46cvss 8.2epss 0.00

    DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. In 3.4.4, DOMPurify allowed selectedcontent by default, allowing browsers to re-clone an XSS payload after sanitization so that unsanitized markup inside is returned. This issue…

  • CVE-2026-47212MedJul 14, 2026
    risk 0.28cvss 5.3epss 0.02

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC header, allowing unauthenticated…

  • CVE-2026-45071HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing…

  • CVE-2026-45068HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing…

  • CVE-2026-15714MedJul 14, 2026
    risk 0.42cvss 6.5epss 0.00

    An out-of-bounds read vulnerability was found in libsoup's multipart processing subsystem. The flaw exists in the soup_multipart_input_stream_read_headers() function inside soup-multipart-input-stream.c, which does not adequately restrict or validate the size of incoming…

  • CVE-2026-15713MedJul 14, 2026
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was found in libsoup's HTTP/2 protocol implementation. The library fails to correctly release memory context blocks under specific stream termination conditions, such as when an HTTP/2 connection encounters window exhaustion or explicit stream resets. A remote,…

  • CVE-2026-15711HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote,…

  • CVE-2026-15709HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming…

  • CVE-2026-15410HigKEVJul 14, 2026
    risk 0.24cvss 7.2epss 0.12

    Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute…

  • CVE-2026-15409CriKEVJul 14, 2026
    risk 0.24cvss 10.0epss 0.07

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

  • CVE-2026-13001CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.04

    The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'podlove_handle_cache_files' function in all versions up to, and including, 4.5.1. This makes it possible for unauthenticated attackers to upload…

  • CVE-2026-5040MedJul 14, 2026
    risk 0.44cvss 6.7epss 0.00

    TP-Link Deco M5 v1 uses a weak password hashing mechanism to store user credentials. An attacker who obtains the password hash through system compromise or privileged access could perform brute-force or dictionary attacks. Successful exploitation may result in disclosure of…

  • CVE-2026-47767CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a…

  • CVE-2026-47305HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2026-47304HigJul 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Improper verification of cryptographic signature in .NET allows an unauthorized attacker to bypass a security feature over a network.

  • CVE-2026-47303HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Authentication bypass by assumed-immutable data in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-47302HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.01

    Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network.

  • CVE-2026-47301HigJul 14, 2026
    risk 0.00cvss 8.8epss 0.01

    Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-47300HigJul 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Incorrect implementation of authentication algorithm in ASP.NET Core allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-45755MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST…

  • CVE-2026-45754MedJul 14, 2026
    risk 0.27cvss 5.3epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not verify them, allowing…

  • CVE-2026-45753MedJul 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so…

  • CVE-2026-45305HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document…

  • CVE-2026-45304HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a…

  • CVE-2026-45133HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level…

  • CVE-2026-45075HigJul 14, 2026
    risk 0.46cvss 8.2epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to…

  • CVE-2026-45073HigJul 14, 2026
    risk 0.40cvss 7.3epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping…

  • CVE-2026-45072MedJul 14, 2026
    risk 0.28cvss 5.4epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP…

  • CVE-2026-45070MedJul 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a…

  • CVE-2026-45069CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list…

  • CVE-2026-45064MedJul 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes,…

  • CVE-2026-45063CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress=…

  • CVE-2026-15720HigJul 14, 2026
    risk 0.49cvss 8.6epss 0.01

    In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.