VYPR

CVEs

113,598 total · page 9 of 2,272

  • CVE-2026-19002HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write in the client application process. Triggering this issue requires control over the server the driver connects to, or the ability…

  • CVE-2026-16695HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16033HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory…

  • CVE-2026-14866HigAug 12, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore.

  • CVE-2026-13622HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc//root/ paths using net.Dial() without symlink protection. These socket paths reside…

  • CVE-2026-13476HigAug 12, 2026
    risk 0.47cvss 7.3epss 0.01

    IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.

  • CVE-2026-13433HigAug 12, 2026
    risk 0.54cvss 8.3epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation.

  • CVE-2026-13367HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility.

  • CVE-2026-13105HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration.

  • CVE-2026-13094HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.

  • CVE-2026-10543HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.00

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.

  • CVE-2026-73415HigAug 12, 2026
    risk 0.42cvss epss 0.01

    jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObjectURL for a specially crafted SVG image…

  • CVE-2026-73413HigAug 12, 2026
    risk 0.50cvss epss 0.00

    Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/compose.js repeatedly joins and slices flag fragments when flagProtection is enabled, which is the default, making processing…

  • CVE-2026-73406HigAug 12, 2026
    risk 0.42cvss 7.5epss 0.00

    Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/src/api/index.ts, and tenantUserLookup returned a full PlatformUser document. An unauthenticated caller could query an email or user…

  • CVE-2026-73332HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which…

  • CVE-2026-73331HigAug 12, 2026
    risk 0.39cvss 7.1epss 0.00

    CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates as part of an inadequately parameterized…

  • CVE-2026-73329HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can…

  • CVE-2026-73326HigAug 12, 2026
    risk 0.49cvss 7.6epss 0.00

    CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate…

  • CVE-2026-73303HigAug 12, 2026
    risk 0.46cvss 8.2epss 0.00

    Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId without binding it to the authenticated session, while checking only currentEmail. An authenticated attacker who obtains a victim…

  • CVE-2026-72809HigAug 12, 2026
    risk 0.52cvss 8.0epss 0.00

    SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the administrator role (RoleAdministrator) to any request whose RemoteAddr is loopback (127.0.0.1) for a specific set of endpoints…

  • CVE-2026-72807HigAug 12, 2026
    risk 0.52cvss 8.0epss 0.00

    SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks function, which executes raw SQL using string substitution instead of parameterized queries. Attackers can distribute malicious SiYuan…

  • CVE-2026-72804HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve block-level content of password-protected documents. Attackers can call these endpoints without supplying a password to read…

  • CVE-2026-72801HigAug 12, 2026
    risk 0.49cvss 7.5epss 0.00

    SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish mode. Attackers can retrieve Argon2id salt, cost parameters, password verifiers, and wrapped notebook keys to perform unlimited…

  • CVE-2026-72798HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to…

  • CVE-2026-72795HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden…

  • CVE-2026-72794HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthenticated users in publish mode. Attackers can retrieve the CookieKey value and forge valid session cookies to impersonate users or gain administrative access.

  • CVE-2026-72793HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing anonymous or publish-reader users to obtain the session-cookie signing key, OS username via pandoc path, and encrypted-notebook key material. Attackers can…

  • CVE-2026-72789HigAug 12, 2026
    risk 0.56cvss 8.6epss 0.00

    SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API…

  • CVE-2026-67579HigAug 12, 2026
    risk 0.49cvss epss 0.00

    Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged keyset pagination cursor, resulting in SQL injection or code execution depending on the data layer. Read actions with keyset…

  • CVE-2026-59917HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code…

  • CVE-2026-59916HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary code…

  • CVE-2026-59914HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary…

  • CVE-2026-46731HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges and arbitrary…

  • CVE-2026-19228HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of…

  • CVE-2026-18099HigAug 12, 2026
    risk 0.58cvss 8.9epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-controlled input.

  • CVE-2026-17642HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-17445HigAug 12, 2026
    risk 0.53cvss 8.2epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-supplied user profile name.

  • CVE-2026-17417HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metacharacters.

  • CVE-2026-17111HigAug 12, 2026
    risk 0.49cvss 7.6epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

  • CVE-2026-17082HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied profile name.

  • CVE-2026-16494HigAug 12, 2026
    risk 0.46cvss 7.1epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization…

  • CVE-2026-15217HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in…

  • CVE-2026-15216HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in…

  • CVE-2026-13361HigAug 12, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.

  • CVE-2026-13267HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request.

  • CVE-2026-12618HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of…

  • CVE-2026-12359HigAug 12, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request…

  • CVE-2026-12005HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to…

  • CVE-2026-12004HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of…

  • CVE-2026-11923HigAug 12, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied…