VYPR

CVEs

378,358 total · page 89 of 7,568

  • CVE-2026-53752HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.00

    docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle…

  • CVE-2026-53659HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.00

    http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZip, RequestFilters.GunZip, and the underlying Gzip request-body decompression functions impose no limit on decompressed size. An unauthenticated client can…

  • CVE-2026-53495MedSep 14, 2026
    risk 0.37cvss epss 0.00

    containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the CRI plugin enabled can indefinitely block the drainExecSyncIO goroutine in internal/cri/server/container_execsync.go when CRI ExecSync is used by exec probes…

  • CVE-2026-50276HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.01

    dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote…

  • CVE-2026-50270HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.01

    dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAGE_MAX_ITEMS, which defaults to 64, or DD_TRACE_BAGGAGE_MAX_BYTES, which defaults to 8192, although those limits apply during baggage injection. A remote…

  • CVE-2026-50157MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.01

    Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorizer::authenticate() and Authorizer::supports() paths in the Authorizer security authenticator may accept OAuth 2.0 bearer access tokens from the token URL query…

  • CVE-2026-49400LowSep 14, 2026
    risk 0.14cvss 3.3epss 0.00

    October System provides the system module for October Content Management System. Prior to versions 3.7.17 and 4.2.21, the backend `SessionMaker` trait stored widget session state as `base64(serialize(...))` and consumed it with `unserialize()` without an `allowed_classes`…

  • CVE-2026-49250HigSep 14, 2026
    risk 0.50cvss epss 0.00

    Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4, the parseSubmission future API in packages/conform-dom/formdata.ts repeatedly scans FormData or URLSearchParams entries by each unique…

  • CVE-2026-47256MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenTelemetry, also known as OTel, is a vendor-neutral open source Observability framework for instrumenting, generating, collecting, and exporting telemetry data such as traces, metrics, and logs. Prior to 0.154.0, the Sentry exporter reads the remote OTLP sender-controlled…

  • CVE-2026-46696LowSep 14, 2026
    risk 0.14cvss 3.3epss 0.00

    October System provides the system module for October Content Management System. Versions prior to 3.7.17 and 4.2.21 have a vulnerability in the Twig sandbox security policy that allowed a chained bypass when `cms.safe_mode` is enabled. The Laravel session store was exposed to…

  • CVE-2026-44162LowSep 14, 2026
    risk 0.11cvss 2.7epss 0.00

    fluent-plugin-s3 is an Amazon S3 input and output plugin for Fluentd. From 0.7.0 to 1.8.4, the in_s3 input plugin reads the entire decompressed payload of gzip, lzma2, and lzop objects into memory without enforcing a decompression_size_limit. An attacker with permission to…

  • CVE-2026-34151HigSep 14, 2026
    risk 0.46cvss epss 0.01

    XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinAction can resolve double-encoded parent-directory segments outside the intended skin or web-application resource prefix when Jetty 12 or later decodes the request…

  • CVE-2026-19542MedSep 14, 2026
    risk 0.36cvss 5.6epss 0.00

    Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application. The tdelete implementation keeps an explicit stack of parent nodes for…

  • CVE-2026-19499HigSep 14, 2026
    risk 0.50cvss 7.7epss 0.00

    Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with…

  • CVE-2026-90804MedSep 14, 2026
    risk 0.31cvss 4.8epss 0.00

    A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_si…

  • CVE-2026-90803MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be…

  • CVE-2026-90802MedSep 14, 2026
    risk 0.29cvss 4.4epss 0.00

    A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could…

  • CVE-2026-90801MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released…

  • CVE-2026-90796MedSep 14, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Leave Management System 1.0. This affects an unknown function of the file /module/company/index.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit is publicly available…

  • CVE-2026-84445HigSep 14, 2026
    risk 0.50cvss epss 0.01

    gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() allow internal/transport/http2_server.go to accept an RPC containing neither the :authority header nor the Host header, while RouteAndProcess in…

  • CVE-2026-76461CriKEVSep 14, 2026
    risk 0.76cvss 9.8epss 0.02

    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient…

  • CVE-2026-76443CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases…

  • CVE-2026-76442HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases…

  • CVE-2026-76441CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases…

  • CVE-2026-76440CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases…

  • CVE-2026-61701HigSep 14, 2026
    risk 0.50cvss 8.8epss 0.01

    Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until 2.25.1, MagicLink stores serialized action objects in the magic_links.action database column and deserializes them through src/MagicLink.php and…

  • CVE-2026-59960HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controlled CI branch or ref values from GITHUB_HEAD_REF or ARGOS_BRANCH can flow through config.branch and getMergeBaseCommitSha() when hasRemoteContentAccess is…

  • CVE-2026-57579HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, and 8.2.6, the unauthenticated GET /api/pages/nested endpoint implemented by Api::PagesController#nested in app/controllers/alchemy/api/pages_controller.rb…

  • CVE-2026-57497MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    webtransport-go is an implementation of the WebTransport protocol. Prior to 0.11.1, Session.parseNextCapsule() in session.go skips an unknown WebTransport capsule on the HTTP/3 request stream by calling io.ReadAll on the capsule reader, retaining the complete declared capsule…

  • CVE-2026-55837MedSep 14, 2026
    risk 0.37cvss 6.8epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.20.0, the local OAuth helper in src/dbt_mcp/oauth/fastapi_app.py exposes GET /dbt_platform_context without authentication or Host validation after a user completes the dbt Platform OAuth flow. The…

  • CVE-2026-55451HigSep 14, 2026
    risk 0.47cvss epss 0.00

    gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2i18next.js splits nested translation keys using options.keyseparator, whose default value consists of two number signs, and uses each segment as a dynamic…

  • CVE-2026-55416HigSep 14, 2026
    risk 0.50cvss 8.8epss 0.01

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports…

  • CVE-2026-55102MedSep 14, 2026
    risk 0.31cvss epss 0.00

    hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response…

  • CVE-2026-55073MedSep 14, 2026
    risk 0.33cvss 6.2epss 0.00

    WeasyPrint helps web developers to create PDF documents. Prior to 70.0, server-side applications that configure a restrictive url_fetcher and pass attacker-influenced values to HTML.write_pdf() can have the restriction bypassed through the xmp_metadata or stylesheets options. In…

  • CVE-2026-55072HigSep 14, 2026
    risk 0.48cvss 8.5epss 0.00

    Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only…

  • CVE-2026-54452MedSep 14, 2026
    risk 0.34cvss epss 0.00

    safeurl is a server-side request forgery protection library. Prior to 0.2.4, the privateNetworks list in ip.go omits the IPv6 ranges 64:ff9b:1::/48, 5f00::/16, 3fff::/20, and 100:0:0:1::/64. When an application enables IPv6 with EnableIPv6(true), an attacker-controlled…

  • CVE-2026-54156HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.01

    node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNonce cache used by nonceAlreadyBeenUsed in packages/node-opcua-secure-channel/source/server/server_secure_channel_layer.ts records nonces from…

  • CVE-2026-54155HigSep 14, 2026
    risk 0.43cvss 7.7epss 0.00

    node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentication handler in packages/node-opcua-server/source/opcua_server.ts decrypts an RSA-OAEP password blob but does not verify that the trailing bytes match the…

  • CVE-2026-53496MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    ExifReader is a JavaScript Exif information parser. Prior to 4.40.1, ExifReader.load() and the asynchronous file and URL loaders can pass attacker-supplied HEIC or AVIF data to the ISO-BMFF parser in src/image-header-iso-bmff.js, where findMetaBox() and parseBox() accept an…

  • CVE-2026-20353CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases…

  • CVE-2026-15923MedSep 14, 2026
    risk 0.23cvss 4.6epss 0.00

    The Zephyr SDIO subsystem function sdio_io_rw_extended_helper() in subsys/sd/sdio.c finishes transfers with a byte-I/O loop that uses size = MIN(remaining, func->cis.max_blk_size) as the per-iteration step. The value func->cis.max_blk_size is decoded directly from the SDIO…

  • CVE-2026-90996MedSep 14, 2026
    risk 0.26cvss 4.0epss 0.00

    A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This…

  • CVE-2026-90995MedSep 14, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the…

  • CVE-2026-90994MedSep 14, 2026
    risk 0.26cvss 4.0epss 0.00

    A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or…

  • CVE-2026-90947HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user…

  • CVE-2026-90943HigSep 14, 2026
    risk 0.57cvss 8.7epss 0.00

    parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering that allows authenticated panel users to inject malicious scripts. Attackers can store XSS payloads in comment bodies that execute in the browsers of other…

  • CVE-2026-90795MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function of the file navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. It is possible to launch the attack remotely. The…

  • CVE-2026-90794MedSep 14, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in GPAC up to f1219cde. The affected element is the function gf_sg_script_load of the file scenegraph/vrml_tools.c of the component MP4Box. Performing a manipulation results in use after free. It is possible to initiate the attack remotely. The exploit…

  • CVE-2026-90793MedSep 14, 2026
    risk 0.28cvss 5.4epss 0.00

    A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed from remote. The exploit has been disclosed…

  • CVE-2026-90792MedSep 14, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation of the argument Target causes null pointer dereference. The attack is possible to be carried…