VYPR

CVEs

378,628 total · page 191 of 7,573

  • CVE-2026-85624MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identifiers. Authenticated attackers can enumerate sequential note IDs and retrieve complete content of other…

  • CVE-2026-85623HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute shell commands as the user running goose, bypassing the recipe security scan which does not inspect…

  • CVE-2026-85622MedSep 4, 2026
    risk 0.27cvss 5.3epss 0.00

    AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticated users to bind sessions to workspaces they do not belong to. Attackers can send sync Manifest messages…

  • CVE-2026-85621MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) is unauthenticated by design and delegates verification to each adapter; the QQ adapter performs no Ed25519…

  • CVE-2026-85620HigSep 4, 2026
    risk 0.56cvss 8.6epss 0.00

    Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can execute file-reading functions like pg_read_file through FROM-clause syntax to read arbitrary files despite…

  • CVE-2026-85619HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.01

    AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access…

  • CVE-2026-85618MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input directives. Attackers can upload .tex files containing \\input{path} or \\verbatiminput{path} directives to…

  • CVE-2026-85608HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request…

  • CVE-2026-85607HigSep 4, 2026
    risk 0.50cvss 8.8epss 0.00

    Blinko 1.8.7 contains an authorization bypass (IDOR) vulnerability in multiple tRPC procedures (message.list, message.update, message.delete, message.clearAfter in server/routerTrpc/message.ts and conversation.clearMessages in server/routerTrpc/conversation.ts). Although these…

  • CVE-2026-85606HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.01

    firecrawl-mcp-server 3.20.2 contains an arbitrary local file read vulnerability in the firecrawl_parse tool that accepts unconstrained filePath arguments without directory containment validation. Attackers can supply absolute paths or directory traversal sequences to read…

  • CVE-2026-85605MedSep 4, 2026
    risk 0.27cvss 5.3epss 0.00

    Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/comments and server-sent-events subscriptions. Attackers who obtain image IDs out of band can retrieve full…

  • CVE-2026-82729MedSep 4, 2026
    risk 0.34cvss —epss 0.00

    Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the client host and cause a denial of service. parse_hex_prefix/2 in lib/mint/http1/parse.ex folds each hex digit of a chunked response's chunk-size field into an…

  • CVE-2026-82728HigSep 4, 2026
    risk 0.46cvss —epss 0.00

    Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a remote HTTP server to exhaust memory on the client host and cause a denial of service. Two HTTP/1 response-parser states accumulate server data without any cap. In lib/mint/http1.ex,…

  • CVE-2026-81859MedSep 4, 2026
    risk 0.40cvss 6.2epss 0.00

    CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.

  • CVE-2026-81832HigSep 4, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 SAP Adapter is vulnerable to an XML external entity (XXE) attack.

  • CVE-2026-6958HigSep 4, 2026
    risk 0.51cvss 7.8epss 0.00

    Acunetix 25.11.251107123 for Windows contains a local privilege escalation vulnerability in the Web Vulnerability Scanning Engine (wvsc.exe) that allows low-privileged local attackers to execute arbitrary code as SYSTEM by exploiting a missing hardcoded directory path for…

  • CVE-2026-19727MedSep 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML…

  • CVE-2026-19205HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting. This issue affects GastroMenum Web Panel: before 31.08.2026.

  • CVE-2026-14466MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.

  • CVE-2026-85522MedSep 4, 2026
    risk 0.27cvss 5.3epss 0.01

    A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.c of the component Slot Migration. The manipulation of the argument job_name results in out-of-bounds read.…

  • CVE-2026-85517MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL Database Backup File Handler. Executing a manipulation can lead to information disclosure. It is possible to…

  • CVE-2026-77818MedSep 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. …

  • CVE-2026-52691HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module.  This issue affects Apache Griffin Hive Metastore Module: all versions. As this project is retired,…

  • CVE-2026-19081MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.

  • CVE-2026-19057MedSep 4, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. This issue affects Gastromenum Ticket and QR Menu System: before 2026.08.31.

  • CVE-2026-12483HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in the 'learndash_fileupload_process' function, which iterates through an entire array and validates only the…

  • CVE-2026-85649HigSep 4, 2026
    risk 0.44cvss 7.9epss 0.00

    (Holloway) Chew, Kean Ho's Actualizer v1.2.0 and earlier contains a fail-open password validation vulnerability in the Alpha user and root user password loops of Shell/debian-minbase-install.sh. The installer invokes mkpasswd to generate yescrypt password hashes but does not…

  • CVE-2026-85516HigSep 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in code-projects Vehicle Management System 1.0. The affected element is an unknown function of the file /busprofile.php. Performing a manipulation of the argument busid results in sql injection. It is possible to initiate the attack remotely. The…

  • CVE-2026-85514MedSep 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component API Key Handler. Such manipulation of the argument api_key_api.user leads to improper privilege management.…

  • CVE-2026-85513MedSep 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api/controllers/v1/actionexecutions.py of the component NoOp RBAC backend. This manipulation of the argument…

  • CVE-2026-82309MedSep 4, 2026
    risk 0.21cvss 4.3epss 0.00

    Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a forward-confirmation loop that does not bound the names it queries. _check_dns issues one PTR query for the client address, keeps the returned names matching…

  • CVE-2026-74237MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an iperf command using the server and options parameters without sanitization, permitting injection of arbitrary…

  • CVE-2026-74236MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.01

    GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parameters prefixed with v_file_row_ and appends their values directly to a base directory path without…

  • CVE-2026-74235MedSep 4, 2026
    risk 0.32cvss 4.9epss 0.01

    GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() function accepts parameters prefixed with v_del_ and appends their values directly to the base configuration…

  • CVE-2026-18198HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection. This issue affects GOLDENHORN ONEIT: before Göbeklitepe.

  • CVE-2026-85617HigSep 4, 2026
    risk 0.50cvss 8.8epss 0.00

    snipe-it versions before 8.6.3 contain an authorization bypass vulnerability in the bulk delete functionality that allows restricted users to soft-delete users outside their authorized scope. Attackers can include unauthorized user IDs in bulk delete requests to bypass…

  • CVE-2026-85616HigSep 4, 2026
    risk 0.48cvss 8.5epss 0.00

    Snipe-IT versions before 8.6.2 contain an authorization bypass vulnerability in checkout-acceptance report actions when Full Multiple Company Support is enabled. Authenticated users with reports.view permission can enumerate sequential acceptance IDs and soft-delete or trigger…

  • CVE-2026-85615MedSep 4, 2026
    risk 0.42cvss 6.4epss 0.00

    Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboardId to the authorized projectId. Authenticated attackers can supply an arbitrary victim dashboardId with…

  • CVE-2026-85614HigSep 4, 2026
    risk 0.56cvss 8.6epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled URL parameter with no private IP filtering or DNS-rebinding protection. Attackers can make the OpenPanel…

  • CVE-2026-85613HigSep 4, 2026
    risk 0.53cvss 8.2epss 0.00

    OpenPanel before 2.3.0 contains a cross-site scripting vulnerability in the unauthenticated favicon proxy endpoint GET /misc/favicon that allows remote attackers to execute scripts by supplying an SVG file URL. Attackers can host malicious SVG files with embedded scripts that…

  • CVE-2026-85612HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the /misc/favicon and /misc/og endpoints that accept an attacker-supplied url parameter with insufficient validation. Attackers can force the API to fetch arbitrary internal hosts and…

  • CVE-2026-85611MedSep 4, 2026
    risk 0.42cvss 6.4epss 0.00

    OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to scope dashboard queries to the caller's project. Authenticated attackers can supply their own projectId…

  • CVE-2026-85610HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    OpenPanel before 2.3.0 fails to properly validate chart formula expressions, allowing authenticated project members with read access to execute arbitrary code by recovering the native JavaScript Function constructor through mathjs matrix objects. Attackers can use the recovered…

  • CVE-2026-85609HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). The endpoint passes a user-supplied url query parameter to fetchWithRedirects()…

  • CVE-2026-85604HigSep 4, 2026
    risk 0.50cvss 8.8epss 0.00

    Grav before 2.0.18 (affected versions <= 2.0.17) contains a remote code execution vulnerability in the Twig sort filter. The sortFunc wrapper in GravExtension.php hardcodes Twig's isSandboxed argument to false, so unlike |map/|filter/|reduce, |sort accepts a plain function name…

  • CVE-2026-85603MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticated admin user with admin.pages.create permission can supply directory traversal sequences in the lang POST…

  • CVE-2026-85602MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present in the submitted payload. On a site configured for reCAPTCHA v3, an anonymous attacker can place their v3…

  • CVE-2026-85601MedSep 4, 2026
    risk 0.28cvss 5.4epss 0.00

    Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal components. Attackers can inject javascript: URI schemes in plugin or theme changelogs to execute arbitrary…

  • CVE-2026-85600MedSep 4, 2026
    risk 0.28cvss 5.4epss 0.00

    Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), which substitutes untrusted parameters such as usernames into translation templates before parsing the result…

  • CVE-2026-85599HigSep 4, 2026
    risk 0.47cvss 7.2epss 0.00

    Grav Shortcode Core before 6.2.5 contains stored cross-site scripting vulnerabilities in the [lorem] tag parameter and [details] summary parameter that are written to rendered pages without escaping. Attackers with page-edit access can inject arbitrary HTML and JavaScript that…