VYPR

CVEs

378,377 total · page 94 of 7,568

  • CVE-2026-82795MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    SolarView Compact contains a cross-site scripting vulnerability in Schedule Settings and Mail Send Setting. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-82794HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-82793HigSep 14, 2026
    risk 0.47cvss 7.2epss 0.00

    Unrestricted upload of file with dangerous type issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.

  • CVE-2026-82792MedSep 14, 2026
    risk 0.34cvss 5.2epss 0.00

    Cross-site scripting vulnerability exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82791HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication Wireless LAN / USB Converter Unit. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in…

  • CVE-2026-82790MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in PC-HELPER Wireless I/O DIO-0404RY-LWF and PC-HELPER Wireless I/O DIO-0404RY-LWF-US. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82789HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    An improper neutralization of directives in dynamically evaluated code ('Eval Injection') issue exists in CONPROSYS HMI System(CHS). If exploited, arbitrary code may be executed by an attacker who can log in to the product.

  • CVE-2026-82788MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82787CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.00

    Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.

  • CVE-2026-82786MedSep 14, 2026
    risk 0.41cvss 6.3epss 0.00

    Insufficiently protected credentials issue exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. If this vulnerability is exploited, sensitive information may be restored from a backup file.

  • CVE-2026-82785MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Stack-based buffer overflow vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

  • CVE-2026-82784MedSep 14, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing authentication for critical function vulnerability exists in Remote I/O Coupler Unit (Server Type) CPSN-MCB271-*. An attacker may execute a REST API without authentication, which could allow the attacker to retrieve I/O values and/or control the output.

  • CVE-2026-82783MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials.

  • CVE-2026-82782MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition.

  • CVE-2026-82781MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82780HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product.

  • CVE-2026-82779HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-82778MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

  • CVE-2026-82777HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-82776MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82775MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication.

  • CVE-2026-82774HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in…

  • CVE-2026-82773MedSep 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82772HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    Buffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

  • CVE-2026-82771MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82770HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    Buffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's web service, an arbitrary program may be executed.

  • CVE-2026-82769MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in Contec RP-WAH-SR Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82768HigSep 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Path traversal vulnerability exists in SGA1000. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

  • CVE-2026-82767MedSep 14, 2026
    risk 0.34cvss 5.2epss 0.00

    Cross-site scripting vulnerability exists in SGA1000. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82766HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-82765HigSep 14, 2026
    risk 0.53cvss 8.1epss 0.00

    Path traversal vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, arbitrary files on the server may be viewed and/or altered by an attacker who can access the product via FTP.

  • CVE-2026-82764MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Cross-site request forgery vulnerability exists in multiple Contec products. If a user views a specially crafted page while logged in to the affected product, unintended operations may be performed.

  • CVE-2026-82763MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

  • CVE-2026-82762HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the…

  • CVE-2026-71198HigSep 14, 2026
    risk 0.45cvss epss 0.00

    In OpenStack Glance before 32.0.1, the location API does not validate destination hosts when adding an HTTP location to an image. Unlike the web-download import path, the location API only checks the URL scheme and does not apply the import_filtering_opts host restrictions. An…

  • CVE-2026-68955HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    The installer for Rakuten Kobo Desktop Application (Windows version) insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privileges of the user who performed the…

  • CVE-2026-25832LowSep 14, 2026
    risk 0.17cvss 3.7epss 0.00

    In Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.

  • CVE-2025-26790LowSep 14, 2026
    risk 0.24cvss 3.7epss 0.00

    Withsecure Atlant with Capricorn engine before 2025-01-20_02 allows a Remote Denial of Service via an out-of-bounds memory read during processing of a document file by the antivirus engine.

  • CVE-2024-23176MedSep 14, 2026
    risk 0.28cvss 5.4epss 0.00

    An issue was discovered in the MassMessage extension in MediaWiki before 1.40.2. For a Special:MassMessage?uselang=x-xss URL, the i18n key massmessage-form-page-help allows XSS.

  • CVE-2023-51769MedSep 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Frappe before 14.49.0 allows an XSS attack that is associated with blog pages and exception pages.

  • CVE-2023-50462MedSep 14, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue was discovered in the content_consent (aka Content Consent) extension through 2.0.1 for TYPO3. It fails to verify whether a specified content element identifier is permitted by the plugin. This enables an unauthenticated user to display various content elements, leading…

  • CVE-2023-50461HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in the direct_mail (aka Direct Mail) extension through 9.5.1 for TYPO3. The Configuration backend module of the extension allows an authenticated user to write to an arbitrary TSConfig page for folders configured as Direct Mail. Exploiting this may lead…

  • CVE-2023-50460MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. The backend module allows an authenticated backend user to perform various actions (userLogout, confirmUser, refuseUser, and resendUserConfirmation) for any frontend user in the system.

  • CVE-2023-50459MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in the femanager extension 7.x before 7.2.3 for TYPO3. It fails to check access permissions for the edit user component. An authenticated frontend user can exploit this to either edit data of various frontend users or delete various frontend user accounts.

  • CVE-2026-90687MedSep 14, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was determined in GPAC up to f1219cde. This vulnerability affects the function gf_node_changed_internal of the file scenegraph/base_scenegraph.c of the component MP4Box. This manipulation causes use after free. It is possible to initiate the attack remotely. The…

  • CVE-2026-90686MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.01

    A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and…

  • CVE-2026-90685LowSep 14, 2026
    risk 0.11cvss 2.8epss 0.00

    A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit…

  • CVE-2026-16726MedSep 14, 2026
    risk 0.44cvss epss 0.00

    Buffer overflow vulnerability in Panasonic Industry USB Driver for MINAS A5/A6 allows  attackers  to stop Windows.

  • CVE-2023-46273HigSep 14, 2026
    risk 0.57cvss 8.8epss 0.00

    Bonjour Gateway in Extreme Networks IQ Engine before 10.6r1a, and through 10.6r4 before 10.6r5, has an ah_bgd buffer overflow via ah_event_send.

  • CVE-2023-46035MedSep 14, 2026
    risk 0.31cvss 5.9epss 0.00

    The svg_optimizer gem before 0.3.0 for Ruby performs entity expansion on untrusted documents.