VYPR

Cloud API

by Mygardyn

CVEs (5)

  • CVE-2026-28766CriApr 3, 2026
    risk 0.60cvss 9.3epss 0.00

    A specific endpoint exposes all user account information for registered Gardyn users without requiring authentication.

  • CVE-2026-25197CriApr 3, 2026
    risk 0.59cvss 9.1epss 0.00

    A specific endpoint allows authenticated users to pivot to other user profiles by modifying the id number in the API call.

  • CVE-2026-32646HigApr 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A specific administrative endpoint is accessible without proper authentication, exposing device management functions.

  • CVE-2026-32662MedApr 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Development and test API endpoints are present that mirror production functionality.

  • CVE-2026-28767MedApr 3, 2026
    risk 0.34cvss 5.3epss 0.00

    A specific administrative endpoint notifications is accessible without proper authentication.