VYPR

by Mygardyn

Source repositories

CVEs (5)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2026-28766Cri0.609.30.00Apr 3, 2026A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.
CVE-2026-25197Cri0.599.10.00Apr 3, 2026A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.
CVE-2026-32646Hig0.497.50.00Apr 3, 2026A specific administrative endpoint is accessible without proper authentication, exposing device management functions.
CVE-2026-32662Med0.345.30.00Apr 3, 2026Development and test API endpoints are present that mirror production functionality.
CVE-2026-28767Med0.345.30.00Apr 3, 2026A specific administrative endpoint notifications is accessible without proper authentication.