VYPR

Security

by Tenable

CVEs (12)

  • CVE-2026-64879CriJul 21, 2026
    risk 0.65cvss 9.9epss 0.02

    A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality.

  • CVE-2026-64881HigJul 21, 2026
    risk 0.57cvss 8.8epss 0.02

    The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability.

  • CVE-2026-64880HigJul 21, 2026
    risk 0.46cvss 7.1epss 0.00

    Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.

  • CVE-2023-5847MedNov 1, 2023
    risk 0.44cvss 6.7epss 0.00

    Under certain conditions, a low privileged attacker could load a specially crafted file during installation or upgrade to escalate privileges on Windows and Linux hosts.

  • CVE-2023-3252MedAug 29, 2023
    risk 0.44cvss 6.8epss 0.01

    An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges could alter logging variables to overwrite arbitrary files on the remote host with log data, which could lead to a denial of service condition.

  • CVE-2024-0971MedFeb 7, 2024
    risk 0.42cvss 6.5epss 0.01

    A SQL injection vulnerability exists where an authenticated, low-privileged remote attacker could potentially alter scan DB content.

  • CVE-2022-3499MedOct 31, 2022
    risk 0.42cvss 6.5epss 0.01

    An authenticated attacker could utilize the identical agent and cluster node linking keys to potentially allow for a scenario where unauthorized disclosure of agent logs and data is present.

  • CVE-2026-19636MedAug 14, 2026
    risk 0.34cvss 5.3epss 0.00

    An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation.

  • CVE-2026-5022MedMar 27, 2026
    risk 0.34cvss 5.3epss 0.00

    The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by knowing (or guessing) the flow ID and file name.

  • CVE-2026-19639MedAug 14, 2026
    risk 0.28cvss 4.3epss 0.00

    An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope.

  • CVE-2023-3253MedAug 29, 2023
    risk 0.28cvss 4.3epss 0.01

    An improper authorization vulnerability exists where an authenticated, low privileged remote attacker could view a list of all the users available in the application.

  • CVE-2025-0760LowFeb 26, 2025
    risk 0.18cvss 2.7epss 0.00

    A Credential Disclosure vulnerability exists where an administrator could extract the stored SMTP account credentials due to lack of encryption.