VYPR

CVEs

378,628 total · page 190 of 7,573

  • CVE-2026-19283HigSep 4, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information, caused by missing destination namespace validation when copying etcd mTLS client credentials from the…

  • CVE-2026-19274CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed…

  • CVE-2026-18905HigSep 4, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a DNS rebinding vulnerability during tool invocation.

  • CVE-2026-18887MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access information about process they shouldn't be permitted to access.

  • CVE-2026-18858LowSep 4, 2026
    risk 0.21cvss 3.3epss 0.00

    IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.

  • CVE-2026-18658CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web…

  • CVE-2026-18567MedSep 4, 2026
    risk 0.29cvss 4.4epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world-writable directory.

  • CVE-2022-35499HigSep 4, 2026
    risk 0.46cvss 7.1epss 0.00

    In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.

  • CVE-2022-35497MedSep 4, 2026
    risk 0.35cvss 5.4epss 0.00

    In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the external document viewer endpoint.

  • CVE-2026-9186MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to IDE config files (~/.cursor/mcp.json, etc.).

  • CVE-2026-9138MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFileComponent. The application constructs local file paths using attacker‑controlled input without…

  • CVE-2026-8447MedSep 4, 2026
    risk 0.40cvss 6.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.

  • CVE-2026-85700MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with basic authentication can call GET /tool/{tool_id} or GET /tool endpoints to retrieve plaintext…

  • CVE-2026-85699HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network addresses or cloud metadata…

  • CVE-2026-85698MedSep 4, 2026
    risk 0.29cvss 5.5epss 0.00

    Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft a malicious database file with a modified cell count value to trigger an…

  • CVE-2026-85697MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on…

  • CVE-2026-85696CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted…

  • CVE-2026-85695CriSep 4, 2026
    risk 0.61cvss 9.4epss 0.00

    FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to…

  • CVE-2026-85694HigSep 4, 2026
    risk 0.53cvss 8.1epss 0.01

    LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious Python code through web pages using indirect prompt…

  • CVE-2026-85693MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses…

  • CVE-2026-85692MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tools/http.go, the SSRF guard for the http_fetch AI-agent tool. The function only unwraps standard IPv4-mapped…

  • CVE-2026-85691HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authentication to read their responses…

  • CVE-2026-85690HigSep 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model output through poisoned repository files or attacker-controlled context to write to arbitrary…

  • CVE-2026-85689MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses without parameterization or escaping, in both the SQLite and PostgreSQL backends.…

  • CVE-2026-85688CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious…

  • CVE-2026-85687HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying arbitrary file paths to Image.open or…

  • CVE-2026-85686HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated attackers can supply arbitrary image_url, audio_url, or video_url parameters…

  • CVE-2026-85685HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. Attackers can supply any directory path in the skill_path request…

  • CVE-2026-85684CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location…

  • CVE-2026-85676MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers can append the redir_url parameter to any short link to redirect visitors to arbitrary external URLs…

  • CVE-2026-85675HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can inject malicious URLs through prompt injection to make the server…

  • CVE-2026-85674HigSep 4, 2026
    risk 0.51cvss 7.8epss 0.00

    aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (executed at startup) or lint-cmd (executed on the first file edit), which aider runs through a shell…

  • CVE-2026-85673HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass SSRF validation. The check_ssrf_url guard validates URLs once but requests.get follows redirects and…

  • CVE-2026-85672CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with…

  • CVE-2026-85671HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through…

  • CVE-2026-85670MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    tokenizers (Hugging Face) is affected by an out-of-bounds buffer access in BpeBuilder::build (tokenizers/src/models/bpe/model.rs). When loading a tokenizer.json via Tokenizer::from_file/from_str, the builder sizes a scratch buffer to the longest vocabulary key, then writes each…

  • CVE-2026-85669MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary file changes into other users' conversations by supplying their conversation IDs, allowing unauthorized…

  • CVE-2026-85668HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accepts a caller-supplied model_path parameter without authentication or path confinement. The endpoint reads…

  • CVE-2026-85667CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.00

    xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit…

  • CVE-2026-85666HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses endpoint. MCP tool definitions accept a server_url parameter (along with headers and authorization values)…

  • CVE-2026-85665MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.01

    Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal segments. When a collection is executed, attackers can craft a request with a body:file path containing ../…

  • CVE-2026-85664HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attackers can supply arbitrarily large parameter values to exhaust server memory and cause denial of service during…

  • CVE-2026-85663CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete…

  • CVE-2026-85662MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs by supplying malicious media field values. Attackers can exploit download_image_from_url and…

  • CVE-2026-85661CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.

  • CVE-2026-85660HigSep 4, 2026
    risk 0.53cvss 8.1epss 0.00

    cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can use shell command substitution syntax like $(...) or backticks to execute non-allowlisted commands that…

  • CVE-2026-85651HigSep 4, 2026
    risk 0.48cvss 8.5epss 0.00

    Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary environments. Attackers can replay their own runs into other organizations' or projects' environments to…

  • CVE-2026-85650MedSep 4, 2026
    risk 0.28cvss 5.4epss 0.00

    Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection. Authenticated users with organization membership can create alert channels with URLs targeting internal…

  • CVE-2026-85626HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validation. Attackers can inject git command-line options like --output= to write files outside the repository to…

  • CVE-2026-85625HigSep 4, 2026
    risk 0.53cvss 8.1epss 0.01

    sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where operation compiles a string value into a function using new Function unless CSP_ENABLED is set (not set by…