VYPR

CVEs

37,953 total · page 92 of 760

  • CVE-2026-51119CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.01

    An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components

  • CVE-2026-55500CriJul 10, 2026
    risk 0.57cvss 9.9epss 0.01

    9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens, and settings) and full database import (complete overwrite) without any authentication requirement beyond…

  • CVE-2026-15143CriJul 10, 2026
    risk 0.60cvss 9.3epss 0.00

    A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Schema Definition (XSD) string, which is processed without proper restrictions. This can lead to server-side requests to arbitrary…

  • CVE-2026-61444CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.01

    PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated into an f-string without sanitization. Attackers can inject arbitrary Python code that executes when the generated server code runs…

  • CVE-2026-59792CriJul 10, 2026
    risk 0.00cvss 9.6epss 0.01

    In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

  • CVE-2026-56765CriJul 10, 2026
    risk 0.57cvss 9.8epss 0.01

    Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling permission escalation to admin-level shares. The GetTaskAttachment endpoint performs permission checks against user-supplied task…

  • CVE-2026-56688CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.02

    Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS…

  • CVE-2026-53363CriJul 10, 2026
    risk 0.57cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is…

  • CVE-2026-41880CriJul 10, 2026
    risk 0.00cvss —epss 0.01

    R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-controllable file paths without proper sanitization before passing them to the system shell via SSH. In current infrastructure…

  • CVE-2026-15378CriJul 10, 2026
    risk 0.60cvss 9.3epss 0.01

    A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery (SSRF) by submitting a specially crafted XML Schema Definition (XSD) string. This can lead to unauthorized access to sensitive…

  • CVE-2026-40008CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.01

    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qualified Java class name and instantiates it using Class.forName().newInstance() without any validation or allowlisting. This…

  • CVE-2026-40005CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files anywhere the IoTDB process has write permissions with unsafe API. This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. …

  • CVE-2026-28564CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.01

    Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue affects Apache IoTDB: from 1.0.0 before 2.0.10. Users are recommended to upgrade to version 2.0.10,…

  • CVE-2026-15300CriJul 10, 2026
    risk 0.00cvss 9.1epss 0.01

    The GEO my WP plugin for WordPress was vulnerable to SQL Injection via the 'distance', 'lat', and 'lng' parameters in versions up to, and including, 4.5.4. The values were read from $_SERVER['QUERY_STRING'] via parse_str() (bypassing wp_magic_quotes, which does not cover…

  • CVE-2026-15282CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.01

    The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_as_attachment' function in all versions up to, and including, 1.2. This makes it possible for unauthenticated attackers to upload…

  • CVE-2026-14894CriJul 10, 2026
    risk 0.57cvss 9.8epss 0.05

    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the…

  • CVE-2026-55615CriJul 10, 2026
    risk 0.53cvss —epss 0.00

    Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.5, Neo4jChatAgent passes LLM-generated Cypher queries straight to the Neo4j driver with no validation, no statement-type allowlist, and no opt-out gate. The query text is…

  • CVE-2026-54769CriJul 10, 2026
    risk 0.58cvss 10.0epss 0.01

    Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape leading to Remote Code Execution (RCE) in its `TableChatAgent` and `VectorStore` capabilities. When these agents evaluate…

  • CVE-2026-54760CriJul 10, 2026
    risk 0.54cvss —epss 0.01

    Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation, with default `allow_dangerous_operations=False`, combines a raw-text regex blocklist (`_DANGEROUS_SQL_PATTERNS`) with a `sqlglot`…

  • CVE-2026-58123CriJul 9, 2026
    risk 0.00cvss 9.8epss 0.05

    Hermes WebUI before 0.51.788 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by accessing the embedded terminal API endpoints without credentials. Attackers can create a session, attach a PTY shell,…

  • CVE-2026-58122CriJul 9, 2026
    risk 0.00cvss 9.1epss 0.00

    Hermes WebUI before 0.51.307 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to circumvent local-origin IP restrictions on onboarding endpoints by supplying a spoofed X-Forwarded-For header with a loopback address. Attackers can…

  • CVE-2026-54003CriJul 9, 2026
    risk 0.52cvss —epss 0.01

    Kirby is an open-source content management system. Prior to 4.9.4 and from 5.4.4, Kirby sites with no configured user accounts that run on publicly accessible servers behind a reverse proxy setting the Forwarded, X-Client-IP, or X-Real-IP request header could allow remote…

  • CVE-2026-0284CriJul 9, 2026
    risk 0.64cvss 9.9epss 0.00

    An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal…

  • CVE-2026-59827CriJul 9, 2026
    risk 0.00cvss 9.9epss 0.04

    Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database connection, including the default sample database, deserialize arbitrary Java objects returned in H2 native…

  • CVE-2026-59826CriJul 9, 2026
    risk 0.00cvss 9.1epss 0.01

    Metabase is an open-source business intelligence and embedded analytics tool. From 1.55.0 until 1.58.15.1, 1.59.12, 1.60.6.3, and 1.61.2, Metabase did not validate unsafe H2 connection properties on one database-creation code path, allowing an authenticated administrator to…

  • CVE-2026-59726CriJul 9, 2026
    risk 0.00cvss 10.0epss 0.03

    Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to…

  • CVE-2026-51599CriJul 9, 2026
    risk 0.00cvss 9.8epss 0.01

    An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header…

  • CVE-2026-51597CriJul 9, 2026
    risk 0.00cvss 9.1epss 0.01

    MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass…

  • CVE-2026-13461CriJul 9, 2026
    risk 0.00cvss 9.6epss 0.01

    When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the…

  • CVE-2026-42486CriJul 9, 2026
    risk 0.00cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: …

  • CVE-2026-23562CriJul 9, 2026
    risk 0.00cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: …

  • CVE-2026-23561CriJul 9, 2026
    risk 0.00cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: …

  • CVE-2026-23560CriJul 9, 2026
    risk 0.00cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: …

  • CVE-2026-23559CriJul 9, 2026
    risk 0.00cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure different users with different roles, using Role Based Access Control. For more details, see: …

  • CVE-2026-23556CriJul 9, 2026
    risk 0.61cvss —epss 0.00

    When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the new domain can create fewer nodes before beeing deemed to be over quota.

  • CVE-2025-58151CriJul 9, 2026
    risk 0.61cvss —epss 0.00

    varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mapping a buffer prepared by OVMF. Within varstored, there were insufficient compiler barriers, creating TOCTOU issues with data in…

  • CVE-2025-58146CriJul 9, 2026
    risk 0.61cvss —epss 0.00

    There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised input. This causes the database's event thread to terminate and cease further processing. 2. XAPI's UTF-8 encoder…

  • CVE-2025-27464CriJul 9, 2026
    risk 0.61cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to…

  • CVE-2025-27463CriJul 9, 2026
    risk 0.61cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to…

  • CVE-2025-27462CriJul 9, 2026
    risk 0.61cvss —epss 0.00

    [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to…

  • CVE-2026-14261CriJul 9, 2026
    risk 0.52cvss 9.1epss 0.01

    A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.

  • CVE-2026-12116CriJul 9, 2026
    risk 0.57cvss 9.8epss 0.01

    A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.

  • CVE-2026-56291CriKEVJul 9, 2026
    risk 0.18cvss 9.8epss 0.15

    Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

  • CVE-2026-5955CriJul 9, 2026
    risk 0.00cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticaret allows SQL Injection. This issue affects BiEticaret: before v3.3.57.

  • CVE-2026-2342CriJul 9, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp allows Stored XSS. This issue affects ValeApp: through 09072026. NOTE: The vendor was contacted early about this disclosure but…

  • CVE-2026-15158CriJul 9, 2026
    risk 0.00cvss 9.8epss 0.01

    The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename…

  • CVE-2026-14245CriJul 9, 2026
    risk 0.00cvss 9.8epss 0.01

    The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function…

  • CVE-2026-47826CriJul 9, 2026
    risk 0.00cvss 9.1epss 0.01

    The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

  • CVE-2026-47646CriJul 9, 2026
    risk 0.00cvss 9.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-54782CriJul 8, 2026
    risk 0.58cvss 10.0epss 0.00

    CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0 token validation does not correctly resolve the issuer signing key or require signed tokens when IdentityConfiguration is used…