VYPR

DYMO ID

by Newell Brands

CVEs (2)

  • CVE-2026-102262HigOct 5, 2026
    risk 0.47cvss 7.3epss —

    Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file,…

  • CVE-2026-101893MedOct 5, 2026
    risk 0.29cvss 4.4epss —

    Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture…