VYPR

CVEs

35,144 total · page 8 of 703

  • CVE-2026-65667CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.00

    Missing authorization in Microsoft Teams allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-63508CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.00

    Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62896CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-62873CriAug 7, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-62830CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.00

    Missing authorization in Azure SRE Agent allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-59118CriAug 7, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper authorization in Copilot Cowork allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-59115CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-56162CriAug 7, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-56161CriAug 7, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network.

  • CVE-2026-50515CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.01

    Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network.

  • CVE-2026-50481CriAug 7, 2026
    risk 0.64cvss 9.9epss 0.00

    Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

  • CVE-2026-70558CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) with no path validation. The route is marked @SaIgnore and /download/** is excluded from the Sa-Token interceptor, so the only guard…

  • CVE-2026-67689CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated list endpoints

  • CVE-2026-67688CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-67622CriAug 6, 2026
    risk 0.64cvss 9.9epss 0.00

    Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attackers to access credentials belonging to other workspaces by supplying an arbitrary credential UUID to Assistants endpoints without…

  • CVE-2026-65400CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

  • CVE-2026-53984CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's database_backup event handler that allows any unauthenticated network peer to wipe or replace the entire SQLite database by…

  • CVE-2026-48088CriAug 6, 2026
    risk 0.61cvss 9.4epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /api/tenants/{tenantId}/staff/{staffId}/crypto` accepts and stores attacker-controlled ML-KEM-768 public keys against any tenant on…

  • CVE-2026-48087CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration handler at `POST /api/auth/register/{userId}` validates the relationship between the WebAuthn challenge and the registration…

  • CVE-2026-48086CriAug 6, 2026
    risk 0.64cvss 9.9epss 0.00

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN promotes themselves to platform-wide GLOBAL_ADMIN through a single PUT request. The role-update handler accepts the `GLOBAL_ADMIN`…

  • CVE-2026-48085CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provisioned OpenReception instance accepts unauthenticated POST requests to `/setup/create-admin-account` and creates additional…

  • CVE-2026-3418CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be written to arbitrary server-accessible locations. Exploitation requires authenticated administrative access with publisher…

  • CVE-2026-19175CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Payments in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19171CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Media in Google Chrome on Windows prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19170CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-19166CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Web Authentication in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19164CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Insufficient validation of untrusted input in Codecs in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-19157CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-19149CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-18367CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

  • CVE-2026-17032CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

  • CVE-2026-15734CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.

  • CVE-2026-15733CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.14

    A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

  • CVE-2026-15732CriAug 6, 2026
    risk 0.57cvss 9.8epss 0.00

    A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.

  • CVE-2026-14812CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an…

  • CVE-2026-11976CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.00

    The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct…

  • CVE-2025-14561CriAug 6, 2026
    risk 0.52cvss 9.0epss 0.00

    In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user…

  • CVE-2026-67261CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.02

    Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary…

  • CVE-2026-66709CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

  • CVE-2026-66665CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.00

    Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

  • CVE-2026-66662CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

  • CVE-2026-66447CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

  • CVE-2026-65581CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

  • CVE-2026-65579CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

  • CVE-2026-65578CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

  • CVE-2026-65577CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

  • CVE-2026-65576CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

  • CVE-2026-65575CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

  • CVE-2026-65574CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

  • CVE-2026-65573CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.