VYPR

CVEs

378,409 total · page 98 of 7,569

  • CVE-2026-90572MedSep 13, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed…

  • CVE-2026-90571MedSep 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site…

  • CVE-2026-90570LowSep 13, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail…

  • CVE-2026-90569LowSep 13, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site…

  • CVE-2026-90568LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross…

  • CVE-2026-90567LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross…

  • CVE-2026-90566HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the…

  • CVE-2026-90565MedSep 13, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is…

  • CVE-2026-90564LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site…

  • CVE-2026-90563LowSep 13, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.

  • CVE-2026-90529LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument…

  • CVE-2026-90528LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes…

  • CVE-2026-90527MedSep 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The…

  • CVE-2026-90526HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is…

  • CVE-2026-90525MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit…

  • CVE-2026-90524HigSep 13, 2026
    risk 0.41cvss 7.3epss 0.01

    A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack…

  • CVE-2026-90523HigSep 13, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint.…

  • CVE-2026-90783HigSep 13, 2026
    risk 0.44cvss 7.8epss 0.00

    MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing…

  • CVE-2026-90782MedSep 13, 2026
    risk 0.27cvss 5.3epss 0.00

    S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap…

  • CVE-2026-90781MedSep 13, 2026
    risk 0.22cvss 4.4epss 0.00

    alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through…

  • CVE-2026-90522HigSep 13, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The…

  • CVE-2026-90521MedSep 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in…

  • CVE-2026-90520MedSep 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to…

  • CVE-2026-90519MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible.…

  • CVE-2026-90780HigSep 13, 2026
    risk 0.42cvss 7.5epss 0.01

    SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when processing SIP messages with header content exceeding 20,490 bytes. Unauthenticated remote attackers can send crafted SIP messages with oversized headers to…

  • CVE-2026-90779HigSep 13, 2026
    risk 0.42cvss 7.5epss 0.01

    SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authentication challenges with oversized algorithm parameters. A malicious SIP server can send a crafted 401 or 407 challenge to corrupt the stack and crash the client…

  • CVE-2026-90778HigSep 13, 2026
    risk 0.42cvss 7.5epss 0.01

    SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers with tag parameters of 2049 bytes or more. Unauthenticated remote attackers can send crafted SIP messages with oversized tag parameters to overflow the static…

  • CVE-2026-90777HigSep 13, 2026
    risk 0.50cvss 8.8epss 0.01

    ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitrary code execution from attacker-supplied files. Attackers can craft malicious checkpoint files that execute code during deserialization when loaded through…

  • CVE-2026-90776HigSep 13, 2026
    risk 0.42cvss 7.5epss 0.00

    Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing email addresses with RFC 5322 comments. Attackers can craft malicious email headers with comment-separated atoms to consume excessive CPU and…

  • CVE-2026-90775MedSep 13, 2026
    risk 0.35cvss 6.5epss 0.00

    PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables before using it as an array index. Attackers can craft malicious rule rows with out-of-range Weight values to trigger out-of-bounds reads in the load_value array,…

  • CVE-2026-90518MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of the file sidebar.php. The manipulation of the argument UserType results in improper access controls. The attack may be launched remotely. The exploit has been…

  • CVE-2026-90517MedSep 13, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the file /blms/view-assign-locker.php. The manipulation of the argument ltid leads to authorization bypass. The attack may be initiated remotely. The exploit is…

  • CVE-2026-90516HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown function of the file /bilal/normal/pay_report.php. Performing a manipulation of the argument period results in sql injection. The attack can be initiated…

  • CVE-2026-90515HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unknown function of the file /bilal/normal/delete_stud.php. Executing a manipulation of the argument selector[] can lead to sql injection. The attack can be…

  • CVE-2026-90774HigSep 13, 2026
    risk 0.42cvss 7.5epss 0.00

    rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowing attackers to bypass directory-escape checks. Attackers can supply path traversal sequences in the filename header to write files outside the configured…

  • CVE-2026-90773LowSep 13, 2026
    risk 0.14cvss 3.2epss 0.00

    procs through 0.14.12 fails to sanitize escape sequences in process command lines before displaying them in the Command column. Local attackers can execute processes with malicious ANSI or OSC escape sequences in their command line arguments, which are written unmodified to…

  • CVE-2026-90772HigSep 13, 2026
    risk 0.42cvss 7.6epss 0.00

    Amundsen frontend through 4.3.0 renders table, dashboard, and feature descriptions with dangerouslySetInnerHTML without HTML sanitization in ResourceListItem components. Attackers can inject malicious markup like img elements with onerror handlers into descriptions via the…

  • CVE-2026-90771LowSep 13, 2026
    risk 0.17cvss 3.7epss 0.00

    joi before versions 17.13.8 and 18.2.9 contains a prototype pollution vulnerability in the messages compilation function that accepts __proto__ as an error code. Attackers can supply __proto__ keys in custom messages to replace the returned object's prototype, breaking…

  • CVE-2026-90770HigSep 13, 2026
    risk 0.50cvss 8.8epss 0.01

    Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supplied monitor addresses directly into shell commands without validation. Authenticated users with monitor permissions can inject shell metacharacters via the…

  • CVE-2026-90769HigSep 13, 2026
    risk 0.43cvss 7.7epss 0.00

    Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated users to perform server-side requests to internal services. Attackers can supply arbitrary URLs to read cloud metadata, internal network services, and…

  • CVE-2026-90768HigSep 13, 2026
    risk 0.53cvss 8.1epss 0.00

    CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to read and delete analyses submitted by other users. Attackers can enumerate all tasks in the system and delete arbitrary analyses by sending requests to task view…

  • CVE-2026-90767MedSep 13, 2026
    risk 0.35cvss 6.5epss 0.00

    Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing customers to inject arbitrary lines into authorized_keys files. Attackers can inject malicious SSH key entries with option directives to gain persistent…

  • CVE-2026-90562HigSep 13, 2026
    risk 0.46cvss 8.1epss 0.00

    LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the unauthenticated reset-password endpoint. Remote attackers knowing the administrator email can exhaust the keyspace through concurrent requests to reset the…

  • CVE-2026-90561HigSep 13, 2026
    risk 0.50cvss 8.7epss 0.00

    Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields…

  • CVE-2026-90514HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function of the file /bilal/normal/save_stud.php. Such manipulation of the argument Status leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-90513MedSep 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw has been found in simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d. This issue affects the function SES.sendEmail of the file template.yml of the component API Gateway Endpoint. This manipulation of the argument…

  • CVE-2026-90511MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in GongShengyue OnlineBooks up to dfc5eacc08d3b0396c266049548618f6fb9587ea. This vulnerability affects unknown code of the file src/cn/ylcto/book/servlet/BooksServlet.java of the component listSplit Interface. The manipulation of the argument column…

  • CVE-2026-90510HigSep 13, 2026
    risk 0.54cvss 8.3epss 0.00

    A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceImpl.encryptKey of the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/im…

  • CVE-2026-90509HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The…

  • CVE-2026-90508LowSep 13, 2026
    risk 0.22cvss 3.4epss 0.00

    A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing…