VYPR

CVEs

37,964 total · page 102 of 760

  • CVE-2026-53662CriJun 23, 2026
    risk 0.55cvss 9.6epss 0.00

    immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (XSS) vulnerability on the /auth/login page allows an attacker to fully compromise any authenticated user's account with a single…

  • CVE-2026-55450CriJun 23, 2026
    risk 0.54cvss 9.3epss 0.01

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space…

  • CVE-2026-55447CriJun 23, 2026
    risk 0.55cvss 9.6epss 0.01

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent…

  • CVE-2026-54307CriJun 23, 2026
    risk 0.55cvss 9.6epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflow could reference credentials they do not own via specific public API endpoints. Credential ownership checks were only enforced…

  • CVE-2026-54305CriJun 23, 2026
    risk 0.57cvss 9.9epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature accepted any authenticated n8n session without performing per-resource ownership or scope checks on the target workflow or…

  • CVE-2026-48519CriJun 23, 2026
    risk 0.55cvss 9.6epss 0.01

    Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by…

  • CVE-2026-44792CriJun 23, 2026
    risk 0.59cvss 9.0epss 0.00

    n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an…

  • CVE-2026-44791CriJun 23, 2026
    risk 0.64cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the…

  • CVE-2026-44789CriJun 23, 2026
    risk 0.64cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with…

  • CVE-2026-54310CriJun 23, 2026
    risk 0.64cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could supply a crafted parameters to the TimescaleDB and/or legacy Postgres v1 node's allowing arbitrary SQL to be injected and…

  • CVE-2026-54309CriJun 23, 2026
    risk 0.65cvss 10.0epss 0.01

    n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint accepts session initialization and tool invocation requests without any authentication. Any network-reachable client, or any…

  • CVE-2026-28496CriJun 23, 2026
    risk 0.56cvss —epss 0.02

    FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnerability in the template rendering system. Administrators with access to features that render Twig templates (email templates, mass…

  • CVE-2026-27604CriJun 23, 2026
    risk 0.58cvss —epss 0.01

    FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypass in the API role handling allows unauthenticated access to privileged `/api/system/*` endpoints. Because `system` resolves to the…

  • CVE-2026-56315CriJun 23, 2026
    risk 0.57cvss 9.8epss 0.01

    picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and imaplib) exposing eight functions that provide direct arbitrary command execution. Attackers can craft malicious pickle files…

  • CVE-2026-56274CriJun 23, 2026
    risk 0.58cvss 9.9epss 0.08

    Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with…

  • CVE-2026-44089CriJun 23, 2026
    risk 0.00cvss —epss 0.00

    Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be exploited to cause the program to crash and to execute code remotely. This allows the attacker to perform actions as root including…

  • CVE-2026-11374CriJun 23, 2026
    risk 0.59cvss 9.0epss 0.03

    In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.

  • CVE-2026-9733CriJun 23, 2026
    risk 0.59cvss 9.1epss 0.01

    Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time…

  • CVE-2026-12866CriJun 23, 2026
    risk 0.64cvss 9.8epss 0.01

    All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are…

  • CVE-2026-48746CriJun 22, 2026
    risk 0.52cvss 9.1epss 0.01

    vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API…

  • CVE-2026-56348CriJun 22, 2026
    risk 0.59cvss 9.1epss 0.00

    n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticated users to bypass Allowed HTTP Request Domains restrictions. Attackers with credential access can cause the n8n server to issue…

  • CVE-2026-48509CriJun 22, 2026
    risk 0.59cvss 9.1epss 0.00

    MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses default serializer options, which resolve to MessagePackSerializerOptions.Standard with MessagePackSecurity.TrustedData. The…

  • CVE-2026-49468CriJun 22, 2026
    risk 0.57cvss 9.8epss 0.03

    LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the…

  • CVE-2026-45034CriJun 22, 2026
    risk 0.53cvss —epss 0.00

    PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohibitWrappers. The helper calls parse_url($filename, PHP_URL_SCHEME) and then checks is_string($scheme) && strlen($scheme) > 1 to…

  • CVE-2026-44179criJun 22, 2026
    risk 0.59cvss —epss —

    ### Summary The excerpt-include macro does not properly escape the title of the included page and executes the content of the excerpt with the macro's rights. Therefore, it is vulnerable to XWiki syntax injection via the included page's title and content, allowing remote code…

  • CVE-2026-12249CriJun 22, 2026
    risk 0.52cvss 9.0epss 0.00

    An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (internal/policies/certificate/python/vendor_samba/gp/gp_cert_auto_enroll_ext.py),…

  • CVE-2026-10789CriJun 22, 2026
    risk 0.62cvss 9.6epss 0.01

    A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the…

  • CVE-2026-7664CriJun 22, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint.

  • CVE-2026-12628CriJun 22, 2026
    risk 0.59cvss 9.1epss 0.01

    IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The…

  • CVE-2026-7166CriJun 22, 2026
    risk 0.00cvss —epss 0.01

    Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ and ‘telefon’ fields. This vulnerability is also present in the local database, as it contains accessible sensitive…

  • CVE-2026-7165CriJun 22, 2026
    risk 0.00cvss —epss 0.00

    The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ information without requiring prior authorization validation. This could enable an authenticated attacker to alter…

  • CVE-2026-6653CriJun 22, 2026
    risk 0.64cvss 9.8epss 0.00

    Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

  • CVE-2026-28381CriJun 22, 2026
    risk 0.62cvss 9.6epss 0.00

    The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files between the local grafana server and the connected Snowflake host.

  • CVE-2026-10561CriJun 22, 2026
    risk 0.58cvss 10.0epss 0.01

    IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise

  • CVE-2026-56422CriJun 22, 2026
    risk 0.54cvss —epss 0.01

    Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys (event_id, org_id, user_id, sharing_group_id, galaxy_cluster_uuid, organisation_uuid, and related nested object…

  • CVE-2026-11373CriJun 22, 2026
    risk 0.00cvss 9.1epss 0.01

    Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a variant of statsd. Newlines are not removed from metric names, allowing metric injections. Values are not sanitised for…

  • CVE-2026-11746CriJun 22, 2026
    risk 0.61cvss —epss 0.00

    A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the…

  • CVE-2026-56397CriJun 21, 2026
    risk 0.55cvss 9.6epss 0.01

    SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads…

  • CVE-2026-56265CriJun 21, 2026
    risk 0.57cvss 9.8epss 0.03

    Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to…

  • CVE-2026-5366CriJun 20, 2026
    risk 0.64cvss 9.9epss 0.01

    Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to…

  • CVE-2024-58351CriJun 20, 2026
    risk 0.57cvss 9.8epss 0.01

    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by default with no allow-list of permitted…

  • CVE-2022-50972CriJun 20, 2026
    risk 0.64cvss 9.8epss 0.01

    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized…

  • CVE-2019-25763CriJun 20, 2026
    risk 0.64cvss 9.8epss 0.01

    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability that allows attackers to gain unauthorized access by exploiting the social media login form functionality. Attackers can submit a POST request to the admin-ajax.php endpoint with…

  • CVE-2026-48939CriKEVJun 20, 2026
    risk 0.78cvss 9.8epss 0.20

    A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

  • CVE-2026-48909CriJun 20, 2026
    risk 0.65cvss —epss 0.05

    SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server.

  • CVE-2026-48908CriKEVJun 20, 2026
    risk 0.83cvss 9.8epss 0.89

    A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

  • CVE-2026-9265CriJun 20, 2026
    risk 0.52cvss 9.1epss 0.01

    Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute value into a heap buffer sized exactly to its declared length via strncpy, leaving no NUL terminator.…

  • CVE-2026-11551CriJun 20, 2026
    risk 0.57cvss 9.8epss 0.01

    The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.4.29. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for…

  • CVE-2026-56081CriJun 19, 2026
    risk 0.59cvss 9.1epss 0.01

    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound to a victim's email address before that email is verified. By enabling two-factor authentication on the pre-registered account, the attacker gains control…

  • CVE-2026-56073CriJun 19, 2026
    risk 0.61cvss 9.4epss 0.00

    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypass email verification by modifying server responses. Attackers can intercept OTP verification requests and manipulate HTTP responses to falsely mark…