VYPR
Vendor

Sbaresearch

Products
2
CVEs
6
Across products
6
Status
Private

Products

2

Recent CVEs

6
  • CVE-2025-41259HigJun 3, 2026
    risk 0.40cvss epss 0.00

    SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using a signed update.

  • CVE-2026-18362MedJul 30, 2026
    risk 0.00cvss 5.9epss 0.00

    The IRIS web application in version 2.4.26 and possibly others does not protect its user authentication against brute-force attacks.

  • CVE-2026-18361HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the datastore upload function.

  • CVE-2026-18360HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the custom attributes function.

  • CVE-2026-16970MedJul 30, 2026
    risk 0.00cvss 4.2epss 0.00

    The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Stolen session cookies can therefore be misused for a long time.

  • CVE-2026-16969HigJul 30, 2026
    risk 0.00cvss 7.6epss 0.00

    The IRIS web application in version 2.4.26 and possibly others is vulnerable to stored cross-site scripting (XSS) in the assets function.