VYPR

CVEs

378,371 total · page 92 of 7,568

  • CVE-2026-90927MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permissions, allowing authenticated users to buffer arbitrarily large messages. Attackers can send oversized WebSocket messages to exhaust server heap memory and cause…

  • CVE-2026-90784MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of the file src/Compiler/semantics.c. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the…

  • CVE-2026-90716MedSep 14, 2026
    risk 0.29cvss 5.5epss 0.00

    A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of the file src/compiler/gravity_parser.c of the component Number Parser. Performing a manipulation results in out-of-bounds read. It is possible to initiate the…

  • CVE-2026-90715HigSep 14, 2026
    risk 0.40cvss 7.3epss 0.00

    A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the file src/utils/gravity_json.c of the component udp json-parser. Such manipulation leads to integer overflow. The attack may be performed from remote. The…

  • CVE-2026-90714MedSep 14, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the file src/utils/gravity_json.c of the component JSON parser. This manipulation causes memory corruption. The attack is possible to be carried out remotely. The…

  • CVE-2026-90713LowSep 14, 2026
    risk 0.14cvss 3.3epss 0.00

    A security flaw has been discovered in vllm-project vLLM up to 0.29.0. The affected element is the function TiktokenTokenizer::new of the file rust/src/text/src/backend/hf/mod.rs of the component tiktoken vocab File Handler. The manipulation results in denial of service. The…

  • CVE-2026-78336HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query for the list of available OIDC providers configured for SSO with Console and Enduser. The returned payload contains all configuration settings, including client…

  • CVE-2026-78330CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a…

  • CVE-2026-78318MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. The notification message, as optionally shown by Console's and Enduser's login pages can be instructed to display HTML tags with unsafe JS inline, via…

  • CVE-2026-78299CriSep 14, 2026
    risk 0.52cvss 9.1epss 0.00

    In Eclipse Embedded CDT versions 6.0 to 6.7 if the CMSIS-Pack archive extracts a compromised CMSIS pack the archive extraction can extract files to locations outside of the pack, allowing writing of arbitrary files to other locations on disk.

  • CVE-2026-77883MedSep 14, 2026
    risk 0.32cvss 4.9epss 0.00

    Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which allows any administrator with sufficient entitlements for User read to access…

  • CVE-2026-77181CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Authorization vulnerability in Apache Syncope. An administrator with ClientApp's update entitlement is unable to perform the related operation, while ClientApp's create entitlement is checked both for create and update operations on ClientApp. This issue…

  • CVE-2026-77147MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy Command class containing untrusted code in their CommandArgs static…

  • CVE-2026-77051CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized entityKey and opEvent…

  • CVE-2026-75030CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Missing Authorization vulnerability in Apache Syncope. An administrator with task execution entitlements might be able to mass (de)provision group members, regardless of their group-related administration capabilities. This issue affects Apache Syncope: from 3.0.0-M0…

  • CVE-2026-75015MedSep 14, 2026
    risk 0.32cvss 4.9epss 0.00

    Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, are not sufficiently masked for the sensitive values they might carry on their payloads, thus allowing administrators to access such sensitive values. …

  • CVE-2026-73668CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Authorization vulnerability in Apache Syncope. An administrator with adequate entitlements in a given Realm may be able to read via REST the full Connector configuration, confidential properties included, scoped in another Realm and thus be able to effectively…

  • CVE-2026-73579CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect Authorization vulnerability in Apache Syncope. Any search requests are transformed into SQL, Neo4J or Elasticsearch / Opensearch queries, depending on the actual deployment configuration. An important component of such transformation is the Realms filter, which…

  • CVE-2026-73470CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper Privilege Management vulnerability in Apache Syncope. Delegations can be created or updated with Roles not owned by the delegating User, or not for the same Realm subtree under the delegation management was granted for. This issue affects Apache Syncope: from…

  • CVE-2026-73178HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequate entitlements can get access via REST to the list of existing Access Tokens, including their signed JWT body. These values can be then used to perform…

  • CVE-2026-12258CriSep 14, 2026
    risk 0.60cvss epss 0.00

    Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated…

  • CVE-2024-58383HigSep 14, 2026
    risk 0.40cvss 7.3epss 0.00

    Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) generates /etc/pure-ftpd/db/mysql.conf with mode 0644 via the XML configuration templates in lib/configfiles/, even though the file contains the Froxlor SQL user's password. On systems where the parent directories are…

  • CVE-2026-90919CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    LightLLM through 1.2.0 contains a remote code execution vulnerability in the Config Server's unauthenticated /visual_register WebSocket endpoint that passes the first client frame directly to pickle.loads(). Attackers can reach the Config Server port and send a malicious…

  • CVE-2026-90712MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote…

  • CVE-2026-90710HigSep 14, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file com/tarzan/cms/modules/admin/service/biz/ThemeService.java of the component Theme Download Function. Executing a manipulation of the argument httpUrl can lead to…

  • CVE-2026-90709MedSep 14, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the file modsys/console/admin.php of the component Admin Console. Such manipulation of the argument text leads to code injection. It is possible to launch the attack…

  • CVE-2026-79701MedSep 14, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Builder Addons in SP Page Builder Pro 3.2.6 - 6.9.0 - In the ajax_contact, optin_form and form_builder addons, the result returned by the CAPTCHA plugin's…

  • CVE-2026-21391CriSep 14, 2026
    risk 0.62cvss epss 0.00

    An improper validation vulnerability exists within PingAM where a well-crafted request allows arbitrary or protected ID Token claims to be set or overridden. In certain configurations this could allow an attacker to bypass authentication controls via spoofing leading to…

  • CVE-2026-9812MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a property field belongs to the specified run before updating its value which allows an authenticated user with run property-management access to crash the…

  • CVE-2026-90898CriSep 14, 2026
    risk 0.57cvss 9.8epss 0.00

    Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false. Auth off means every…

  • CVE-2026-90891MedSep 14, 2026
    risk 0.36cvss 5.5epss 0.00

    ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to write to improperly restricted I/O ports, resulting in a forced…

  • CVE-2026-90890MedSep 14, 2026
    risk 0.36cvss 5.5epss 0.00

    ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability. Authenticated local attackers can send a specially crafted IOCTL request to cause the driver to dereference an unvalidated pointer, resulting in an operating…

  • CVE-2026-90708HigSep 14, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file global.php of the component Cookie Handler. This manipulation of the argument yot3_user/yot3_pass causes sql injection. It is possible to initiate the attack…

  • CVE-2026-90707HigSep 14, 2026
    risk 0.47cvss 8.3epss 0.00

    A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fallback of the file src/amf/nnrf-handler.c of the component Old AMF Discovery Fallback. The manipulation of the argument discovery_option results in use after…

  • CVE-2026-90706MedSep 14, 2026
    risk 0.43cvss 6.6epss 0.02

    A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly…

  • CVE-2026-90705MedSep 14, 2026
    risk 0.43cvss 6.6epss 0.02

    A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed…

  • CVE-2026-8821HigSep 14, 2026
    risk 0.39cvss 7.1epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel member-management permission during playbook run creation, allowing an authenticated channel member to add an arbitrary user to a restricted channel via the run…

  • CVE-2026-89180HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.

  • CVE-2026-87802CriSep 14, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper verification of cryptographic signature vulnerability in Apache Syncope. When SRA is configured for OAuth 2.0 without JWKS set URI assigned, an attacker can forge arbitrary JWTs to impersonate any user identity and permissions, gaining full access to services proxied…

  • CVE-2026-87785CriSep 14, 2026
    risk 0.59cvss 9.1epss 0.01

    Authentication bypass by spoofing vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can spoof another user's privileges after completing a successful authentication and…

  • CVE-2026-87779HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.00

    Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length (not 16/24/32 bytes) is configured, Syncope will pad the provided value with random characters. The resulting key value is logged. This issue affects…

  • CVE-2026-86460CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to…

  • CVE-2026-82232CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve execution of arbitrary SQL via stacked queries, leveraging unsanitized sort clauses for Task search. …

  • CVE-2026-81566MedSep 14, 2026
    risk 0.33cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The add-to-menu routine invoked the com_menus item model's save() method directly. That model does not perform authorisation itself, because the…

  • CVE-2026-81565MedSep 14, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The folder request parameter replaced the generated date-based destination folder in its entirety and was then passed to Folder::create() and…

  • CVE-2026-81564HigSep 14, 2026
    risk 0.46cvss epss 0.00

    Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same…

  • CVE-2026-79700MedSep 14, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Page Builder Pro 5.1.4 - 6.9.0 - The optin_form addon read the CAPTCHA type, the expected answer and the enabled flag from the request rather than from the…

  • CVE-2026-78375HigSep 14, 2026
    risk 0.56cvss epss 0.00

    Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Free and Pro) 5.2.1 - 6.9.0 - plgContentSppagebuilder::onContentAfterSave() read jform[attribs][sppagebuilder_article_id] from the request and concatenated it…

  • CVE-2026-5132MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpacked SDP messages compressed with zlib, which allows attacker to deny service or crash server via sending many SDP messages that unpack to large size..…

  • CVE-2026-20773HigSep 14, 2026
    risk 0.55cvss epss 0.00

    A role-based access control issue was identified in the administrative expression evaluation functionality. This could allow users with certain administrative roles to access expression testing capabilities beyond their intended permissions.