VYPR

Data Management Center

by Datiphy

CVEs (4)

  • CVE-2026-76156CriAug 21, 2026
    risk 0.61cvss epss

    OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execute arbitrary operating system commands as root.

  • CVE-2026-76158CriAug 21, 2026
    risk 0.60cvss epss

    External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to write files to arbitrary locations outside the intended upload directory via relative or absolute path sequences.

  • CVE-2026-76155CriAug 21, 2026
    risk 0.60cvss epss

    Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the management platform by logging in with default administrator credentials.

  • CVE-2026-76157HigAug 21, 2026
    risk 0.57cvss epss

    Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unauthenticated remote attacker to upload arbitrary files to the server's configured upload directory.