VYPR

CVEs

35,153 total · page 11 of 704

  • CVE-2026-70478CriAug 4, 2026
    risk 0.60cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The endpoint decrypts the stored credential,…

  • CVE-2026-70477CriAug 4, 2026
    risk 0.55cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypasses the blocklist validator and executes in…

  • CVE-2026-69703CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke…

  • CVE-2026-49435CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.01

    Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

  • CVE-2026-0163CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.00

    In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2017-20242CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.01

    Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.

  • CVE-2017-20241CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.01

    Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.

  • CVE-2026-70470CriAug 4, 2026
    risk 0.55cvss epss 0.01

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python…

  • CVE-2026-69264CriAug 4, 2026
    risk 0.54cvss epss 0.01

    Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js exposes eval…

  • CVE-2026-24254CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and…

  • CVE-2026-69259CriAug 4, 2026
    risk 0.54cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it…

  • CVE-2026-69256CriAug 4, 2026
    risk 0.54cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could…

  • CVE-2026-69255CriAug 4, 2026
    risk 0.53cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into…

  • CVE-2026-64633CriAug 4, 2026
    risk 0.65cvss epss 0.00

    A vulnerability allowing remote unauthenticated code execution on the agent host.

  • CVE-2026-63456CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…

  • CVE-2026-63455CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify…

  • CVE-2026-58073CriAug 4, 2026
    risk 0.62cvss epss 0.00

    A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

  • CVE-2026-58072CriAug 4, 2026
    risk 0.59cvss epss 0.00

    A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

  • CVE-2025-29296CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.02

    H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in the /api/esps…

  • CVE-2026-69254CriAug 4, 2026
    risk 0.54cvss epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions and merged them over the default NodeVM security settings in packages/components/src/utils.ts. An authenticated…

  • CVE-2026-69253CriAug 4, 2026
    risk 0.52cvss epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool, ChatflowTool, and ExecuteFlow — ran code in the in-process  vm2  sandbox. To build that code, they…

  • CVE-2026-69110CriAug 4, 2026
    risk 0.52cvss 9.1epss 0.01

    OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files within the temp and static/music directories by directly accessing the GET /api/tmp/:tmpFile and GET /api/music/:fileName endpoints.…

  • CVE-2026-69098CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to…

  • CVE-2026-25289CriAug 4, 2026
    risk 0.62cvss 9.6epss 0.00

    Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

  • CVE-2026-18801CriAug 4, 2026
    risk 0.00cvss epss 0.00

    OpenMeter contains a stored, or second-order, SQL injection vulnerability in the handling of customer usage-attribution values. An attacker who can create or update a customer can store a malicious value in the usageAttribution.key or usageAttribution.subjectKeys fields. When…

  • CVE-2026-69251CriAug 4, 2026
    risk 0.00cvss epss 0.01

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to set arbitrary TypeORM DataSource options through the additionalConfig input in…

  • CVE-2026-61515CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.02

    Puwell IP Camera firmware versions 2.x through 4.x contains an unauthenticated command injection vulnerability that allows remote attackers to execute arbitrary operating system commands by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567.…

  • CVE-2026-61514CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Puwell IP Camera firmware versions 2.x through 4.x contains an authentication bypass vulnerability that allows unauthenticated attackers to access device functions by sending protocol-conforming packets over TCP port 23456 without credentials. Attackers can exploit the…

  • CVE-2026-10050CriAug 4, 2026
    risk 0.52cvss 9.1epss 0.00

    In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initial specification for HTTP did not specify explicitly a charset, and it was assumed to be ISO-8859-1 for historical reasons. If…

  • CVE-2026-15721CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows SQL Injection. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

  • CVE-2026-14804CriAug 4, 2026
    risk 0.00cvss 9.1epss 0.00

    Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sensitive Constants Within an Executable. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

  • CVE-2026-14175CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.

  • CVE-2026-18754CriAug 4, 2026
    risk 0.00cvss 9.1epss 0.00

    The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and…

  • CVE-2026-18753CriAug 4, 2026
    risk 0.00cvss 9.1epss 0.00

    The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private key allows malicious actors to breach the confidentiality and integrity of HTTPS communications, enabling traffic decryption and…

  • CVE-2026-64564CriAug 4, 2026
    risk 0.57cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in…

  • CVE-2026-16618CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable…

  • CVE-2026-15958CriAug 4, 2026
    risk 0.00cvss 9.3epss 0.00

    The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary…

  • CVE-2026-18686CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.03

    A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The…

  • CVE-2026-18685CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the component modem.so. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-48333CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exploit this vulnerability to gain elevated privileges. Exploitation of this issue does not require user interaction.

  • CVE-2026-48331CriAug 3, 2026
    risk 0.65cvss 10.0epss 0.00

    Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.

  • CVE-2026-48330CriAug 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to…

  • CVE-2026-48326CriAug 3, 2026
    risk 0.64cvss 9.9epss 0.00

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this…

  • CVE-2026-48323CriAug 3, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary…

  • CVE-2026-48317CriAug 3, 2026
    risk 0.62cvss 9.6epss 0.00

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this…

  • CVE-2026-18684CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.02

    A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the component modem.so. This manipulation causes command injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-18667CriAug 3, 2026
    risk 0.62cvss 9.6epss 0.00

    A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sensor to an attacker-controlled host.

  • CVE-2026-46713CriAug 3, 2026
    risk 0.53cvss epss 0.00

    Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD signature validation and compaction process that allows spoofed activities to be accepted as valid. This issue has been fixed in…

  • CVE-2026-69240CriAug 3, 2026
    risk 0.57cvss 9.8epss 0.00

    Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a…

  • CVE-2026-52102CriAug 3, 2026
    risk 0.57cvss 9.8epss 0.01

    An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.