VYPR

CVEs

37,805 total · page 1 of 757

  • CVE-2026-105105CriOct 3, 2026
    risk 0.57cvss 9.8epss —

    CWE-306: Missing Authentication for Critical Function in the ait.core.server telemetry and command broker (ait-server) in NASA-AMMOS AIT-Core through 3.1.1 allows an unauthenticated remote attacker with network access to the ZeroMQ message bus to inject spacecraft command data,…

  • CVE-2026-71885CriOct 3, 2026
    risk 0.53cvss —epss —

    In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 9420) implementation did not bind an X.509 credential to a LeafNode's signature_key. LeafNode.verify() checked a leaf's signature against the signature_key carried in the leaf itself, while the…

  • CVE-2026-92084CriOct 3, 2026
    risk 0.52cvss 9.1epss —

    The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.11.0.5. This is due to the software allowing users to execute an action that does not properly…

  • CVE-2026-87115CriOct 3, 2026
    risk 0.59cvss 9.1epss —

    The VikAppointments Services Booking Calendar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the extract function in all versions up to, and including, 1.2.21. This makes it possible for unauthenticated attackers to…

  • CVE-2026-105080CriOct 3, 2026
    risk 0.57cvss 9.9epss —

    In ConvertX before 0.19.0, converters/calibre.ts does not block recipe files, and instead passes them to the ebook-convert program from Calibre. This affects executable code in a .recipe or .downloaded_recipe file.

  • CVE-2026-73802criOct 2, 2026
    risk 0.59cvss —epss —

    ### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags, capability expansion, and security…

  • CVE-2026-84411CriOct 2, 2026
    risk 0.64cvss 9.8epss —

    The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause…

  • CVE-2026-95102CriOct 2, 2026
    risk 0.61cvss 9.4epss —

    WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is…

  • CVE-2026-82042CriOct 2, 2026
    risk 0.57cvss 9.8epss —

    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts…

  • CVE-2026-82041CriOct 2, 2026
    risk 0.57cvss 9.9epss —

    UTMStack before 11.2.16 contains a missing authorization vulnerability in UTMIncidentCommandWebsocket.processCommand(), the handler mapped to the /command/{hostname} STOMP destination, where no role check or command allowlist is applied before forwarding supplied commands. Any…

  • CVE-2026-75937CriOct 2, 2026
    risk 0.61cvss —epss —

    A specially crafted HTTP POST request to the web administration interface allows an unauthenticated attacker to execute arbitrary operating system commands with root privileges on the affected device. Disable the web server when not configuring the device.

  • CVE-2026-104019CriOct 2, 2026
    risk 0.52cvss 9.0epss —

    OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker…

  • CVE-2026-103956CriOct 2, 2026
    risk 0.58cvss 10.0epss —

    Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and…

  • CVE-2023-54405CriOct 2, 2026
    risk 0.64cvss 9.8epss —

    H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied…

  • CVE-2026-102795CriOct 2, 2026
    risk 0.60cvss 9.3epss —

    Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. This CVE supersedes…

  • CVE-2026-104849CriOct 2, 2026
    risk 0.55cvss —epss —

    Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.2, Tinypool reads filename from a caller-supplied options object in pool.run(task, options) without requiring an own property, so a polluted Object.prototype.filename can replace the intended worker…

  • CVE-2026-104848CriOct 2, 2026
    risk 0.55cvss —epss —

    Tinypool is a minimal Node.js worker thread pool implementation. Prior to 2.1.1, Tinypool constructs ThreadPool.options from a normal options object and reads the execArgv and env worker options in dist/index.js, allowing values inherited from a polluted Object.prototype to be…

  • CVE-2026-104846CriOct 2, 2026
    risk 0.57cvss 9.8epss —

    Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. From 0.12.0 until 1.6.2, fromJSON deserialization of a fulfilled Promise control node can pass a plugin-produced callable-bearing thenable to a native Promise resolver.…

  • CVE-2026-103648CriOct 2, 2026
    risk 0.52cvss 9.1epss —

    Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.

  • CVE-2026-103628CriOct 2, 2026
    risk 0.62cvss 9.6epss —

    Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-103626CriOct 2, 2026
    risk 0.62cvss 9.6epss —

    Incorrect authorization in FileSystem in Google Chrome on on Windows prior to 154.0.8037.97 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-90970CriOct 2, 2026
    risk 0.57cvss 9.9epss —

    GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent…

  • CVE-2026-19652CriOct 2, 2026
    risk 0.64cvss 9.8epss —

    The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()`…

  • CVE-2026-83632CriOct 2, 2026
    risk 0.53cvss —epss —

    Allocation of resources without limits or throttling, Integer overflow or wraparound, Heap-based buffer overflow vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.

  • CVE-2026-104611CriOct 2, 2026
    risk 0.59cvss 9.1epss —

    A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is…

  • CVE-2026-104610CriOct 2, 2026
    risk 0.65cvss 10.0epss —

    A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The…

  • CVE-2026-91135CriOct 2, 2026
    risk 0.53cvss —epss —

    Heap-based buffer overflow vulnerability in Apache Thrift C++ THeaderTransport. When an application enables the ZLIB transform for the frames it sends, THeaderTransport::transform() copies the compressed frame into the write buffer without making sure it fits. Data that does…

  • CVE-2026-86325CriOct 2, 2026
    risk 0.61cvss —epss —

    A stack-based buffer overflow vulnerability exists in protocol gateways' account management interface. The vulnerability is caused by insufficient length validation of the `account_name` parameter when processing account management requests. An attacker authenticated as a…

  • CVE-2026-94541CriOct 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The WPMobile.App – Android and iOS App Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.82 This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-97637CriOct 2, 2026
    risk 0.64cvss 9.8epss 0.01

    The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass via Cached Session Cookie Disclosure in all versions up to, and including, 3.1.2. The vulnerability exists because the required PI-Media/json-api parent plugin caches controller dispatch results in…

  • CVE-2026-93698CriOct 2, 2026
    risk 0.64cvss 9.9epss 0.00

    Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.

  • CVE-2026-93697CriOct 2, 2026
    risk 0.59cvss 9.0epss 0.00

    There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.

  • CVE-2026-93029CriOct 2, 2026
    risk 0.59cvss 9.0epss 0.00

    There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Manage SSL Hosts interface.

  • CVE-2026-63569CriOct 2, 2026
    risk 0.52cvss —epss 0.00

    Improper input validation in DHAgreement.CalculateAgreement (MTI/A0 two-pass Diffie-Hellman) in Legion of the Bouncy Castle Inc. bc-csharp before 2.7.0 allows an on-path attacker to make the local party compute an agreed value the attacker already knows, defeating the key…

  • CVE-2026-15896CriOct 2, 2026
    risk 0.52cvss 9.1epss 0.01

    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on…

  • CVE-2026-19660CriOct 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The Divi Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.0. The `process_paypal_callback` function, hooked to the `init` action, accepts a base64-encoded `paypal_param` GET parameter with no IPN validation, no…

  • CVE-2026-14378CriOct 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The DevKit Pro plugin for WordPress is vulnerable to Authentication Bypass Leading to Administrator Account Takeover in all versions up to, and including, 2.3.0 This is due to the `revert_switch` handler trusting the attacker-controlled `original_user_id` cookie as the…

  • CVE-2026-104480CriOct 2, 2026
    risk 0.54cvss —epss 0.00

    Discord libdave before 1.2.0 did not reject an MLS Welcome message when the resulting group roster contained an unrecognized participant. An attacker in control of the DAVE signaling path (the voice gateway, or an equivalent position able to add, alter, or withhold signaling…

  • CVE-2026-86345CriOct 2, 2026
    risk 0.59cvss 9.0epss 0.00

    A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS upgrade and whose response is delivered…

  • CVE-2026-103765CriOct 2, 2026
    risk 0.54cvss 9.4epss 0.01

    Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticated attackers to read, overwrite, and delete transfer engine metadata keys. Attackers can poison segment descriptors such as…

  • CVE-2026-103764CriOct 2, 2026
    risk 0.57cvss 9.8epss 0.01

    Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to read and write arbitrary process memory via the TCP transport data port. Attackers can send a crafted SessionHeader with…

  • CVE-2026-71449CriOct 1, 2026
    risk 0.60cvss —epss 0.00

    : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.

  • CVE-2026-18397CriOct 1, 2026
    risk 0.61cvss —epss 0.00

    This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect native host component. The attack leverages an unrestricted messaging interface…

  • CVE-2026-55395CriOct 1, 2026
    risk 0.61cvss —epss 0.00

    Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords…

  • CVE-2026-55393CriOct 1, 2026
    risk 0.65cvss —epss 0.00

    Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software…

  • CVE-2026-56662CriOct 1, 2026
    risk 0.62cvss 9.6epss 0.00

    GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the UpdateCE update form contained no anti-CSRF token, and the POST handler performed no token or request-origin verification. A remote attacker…

  • CVE-2026-56660CriOct 1, 2026
    risk 0.59cvss 9.1epss 0.01

    GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. Prior to version 1.5, the update handler in UpdateCE.php downloads a ZIP archive and extracts its contents into the web root without validating file types or extraction…

  • CVE-2026-53953CriOct 1, 2026
    risk 0.59cvss 9.1epss 0.00

    GetSimple CMS is a content management system (CMS), and GetSimple CMS CE is the community edition of that CMS. In version 3.3.22, the password reset endpoint can be accessed without authentication. When a reset request is submitted for an existing user, the application generates…

  • CVE-2026-14984CriOct 1, 2026
    risk 0.61cvss —epss 0.00

    Cleartext transmission in the primary control endpoints of Teledyne FLIR Aware2 versions through 6.9.0.2 allows remote unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking…

  • CVE-2026-104286CriKEVOct 1, 2026
    risk 0.76cvss 9.8epss 0.02

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write…