VYPR

CVEs

35,137 total · page 1 of 703

  • CVE-2026-67365CriAug 14, 2026
    risk 0.60cvss epss

    Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

  • CVE-2026-17186CriAug 14, 2026
    risk 0.64cvss 9.9epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

  • CVE-2026-17184CriAug 14, 2026
    risk 0.64cvss 9.8epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

  • CVE-2026-17182CriAug 14, 2026
    risk 0.64cvss 9.8epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

  • CVE-2026-17181CriAug 14, 2026
    risk 0.60cvss 9.3epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

  • CVE-2026-73678CriAug 14, 2026
    risk 0.65cvss 10.0epss

    MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which…

  • CVE-2026-50027CriAug 14, 2026
    risk 0.64cvss 9.8epss

    mcp-memory-service is a semantic memory layer for AI applications. Prior to 10.67.1, all HTTP routes under /api/documents/* in mcp-memory-service are served without any authentication dependency, even when the server is configured with an API key (MCP_API_KEY) or OAuth. An…

  • CVE-2026-49457CriAug 14, 2026
    risk 0.59cvss 9.1epss

    erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4.4, the QUIC client did not authenticate the server during the TLS 1.3 handshake. The CertificateVerify signature was not checked, the certificate chain was not validated, and the hostname was not compared…

  • CVE-2026-19188CriAug 14, 2026
    risk 0.65cvss 10.0epss

    A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input…

  • CVE-2026-73849CriAug 14, 2026
    risk 0.64cvss 9.8epss

    Emlog is an open source website building system. In 2.6.26 and earlier, install.php accepts action=reinstall without authentication and deliberately skips the already-installed check because the guard runs only when $act != 'reinstall'. A remote attacker can submit hostname,…

  • CVE-2026-48528CriAug 14, 2026
    risk 0.64cvss 9.8epss

    Metacat is data repository software that helps researchers preserve, share, and discover data. Metacat versions 2.0.0 through 3.4.0 contain an unauthenticated SQL injection vulnerability in the `/cn/v1/object` and `/cn/v2/object` REST API endpoints due to unsanitized user input…

  • CVE-2026-19682CriAug 14, 2026
    risk 0.64cvss 9.9epss

    A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account.

  • CVE-2026-19681CriAug 14, 2026
    risk 0.64cvss 9.9epss

    An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system.

  • CVE-2026-19626CriAug 14, 2026
    risk 0.64cvss 9.9epss

    A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report…

  • CVE-2026-19871CriAug 14, 2026
    risk 0.53cvss epss

    Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save…

  • CVE-2026-72830CriAug 14, 2026
    risk 0.57cvss 9.8epss

    Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write scheduler configuration. Attackers with a scoped api.config.write key can inject arbitrary commands into scheduler.custom_jobs that…

  • CVE-2026-72829CriAug 14, 2026
    risk 0.57cvss 9.8epss

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. These methods enforce the scope cap only for api.users.write, but gate super-privilege grants on a bare isSuperAdmin() check that…

  • CVE-2026-72826CriAug 14, 2026
    risk 0.57cvss 9.8epss

    The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in createApiKey. The self-target path of requireApiKeyPermission() requires only the baseline api.access scope, and the new key's…

  • CVE-2026-72824CriAug 14, 2026
    risk 0.64cvss 9.8epss

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-toggle check uses a bare isSuperAdmin() gate that does not consult api_key_scopes, so a least-privilege API key scoped only to…

  • CVE-2026-72822CriAug 14, 2026
    risk 0.57cvss 9.8epss

    The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlike the sibling generate2fa endpoint, disable2fa authorizes the admin (non-self) path solely via ACL reads…

  • CVE-2026-72811CriAug 14, 2026
    risk 0.65cvss 10.0epss

    SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates stored block metadata (title, name, alias, anchor text) and the client-supplied keyword into a SQL MATCH/search statement while…

  • CVE-2026-12949CriAug 14, 2026
    risk 0.64cvss 9.8epss

    The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter…

  • CVE-2026-73843CriAug 13, 2026
    risk 0.55cvss 9.6epss

    OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing management APIs on the externally reachable agent listener without authentication, allowing network-reachable attackers to…

  • CVE-2026-73842CriAug 13, 2026
    risk 0.52cvss 9.0epss

    OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token,…

  • CVE-2026-73665CriAug 13, 2026
    risk 0.60cvss epss

    FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socket.IO version 4 applies that middleware only to the default namespace. An unauthenticated client can connect to custom namespaces…

  • CVE-2026-73663CriAug 13, 2026
    risk 0.53cvss epss

    FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted SIP From headers into the missedcalllog INSERT in agi-bin/missedcallnotify.php without escaping or bound parameters. An…

  • CVE-2026-73421CriAug 13, 2026
    risk 0.52cvss epss

    NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for the existence of the auth object returned by the auth() wrapper can fail open when Auth.js has a server configuration error. In…

  • CVE-2026-73420CriAug 13, 2026
    risk 0.52cvss epss

    NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by the email and magic-link sign-in flow validates an address before applying Unicode normalization. An address can contain a Unicode…

  • CVE-2026-73302CriAug 13, 2026
    risk 0.52cvss epss

    Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved an email without getEmailVerified or an email_verified requirement, and packages/backend-core/src/middleware/passport/sso/sso.ts…

  • CVE-2026-72851CriAug 13, 2026
    risk 0.58cvss 10.0epss

    Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured…

  • CVE-2026-72850CriAug 13, 2026
    risk 0.52cvss 9.1epss

    Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace…

  • CVE-2026-72842CriAug 13, 2026
    risk 0.64cvss 9.9epss

    luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape…

  • CVE-2026-72841CriAug 13, 2026
    risk 0.64cvss 9.9epss

    luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code…

  • CVE-2026-72839CriAug 13, 2026
    risk 0.57cvss 9.8epss

    filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and…

  • CVE-2026-72776CriAug 13, 2026
    risk 0.57cvss 9.8epss

    AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arbitrary commands by submitting crafted queries to the unprotected POST /query API endpoint bound to 0.0.0.0:7777 with wildcard…

  • CVE-2026-8715CriAug 13, 2026
    risk 0.55cvss 9.6epss

    Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allow a tenant with limited Kubernetes RBAC permissions to read files from the operator pod's filesystem and…

  • CVE-2026-19297CriAug 13, 2026
    risk 0.59cvss 9.1epss

    IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts.

  • CVE-2026-17482CriAug 13, 2026
    risk 0.64cvss 9.8epss

    IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

  • CVE-2026-73656CriAug 13, 2026
    risk 0.57cvss 9.9epss

    Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers calls CreateDeploymentBackgroundWorkerServiceV4.call() in apps/webapp/app/v3/services/createDeploymentBackgroundWo…

  • CVE-2026-19747CriAug 13, 2026
    risk 0.64cvss 9.8epss

    A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the function CAte::HandleCmd of the file Kylin of the component ATE Module. This manipulation causes command injection. The attack is…

  • CVE-2026-14525CriAug 13, 2026
    risk 0.61cvss 9.4epss

    IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypass when the rtcomm-1.0 or rtcommGateway-1.0 feature is enabled.

  • CVE-2026-73653CriAug 13, 2026
    risk 0.54cvss 9.4epss

    Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without…

  • CVE-2026-73649CriAug 13, 2026
    risk 0.57cvss 9.8epss

    Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in…

  • CVE-2026-73644CriAug 13, 2026
    risk 0.55cvss 9.6epss

    OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy…

  • CVE-2026-73567CriAug 13, 2026
    risk 0.52cvss 9.1epss

    sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by [email protected], which…

  • CVE-2026-67614CriAug 13, 2026
    risk 0.57cvss 9.8epss

    CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a…

  • CVE-2026-58508CriAug 13, 2026
    risk 0.59cvss 9.1epss

    Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

  • CVE-2026-58443CriAug 13, 2026
    risk 0.59cvss 9.1epss

    Public-only repository tokens can update private PR head branches

  • CVE-2026-58433CriAug 13, 2026
    risk 0.59cvss 9.1epss

    Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

  • CVE-2026-56750CriAug 13, 2026
    risk 0.52cvss 9.1epss

    Gitea Remember-Me Token Theft Not Invalidating Attacker Session