VYPR

CVEs

378,628 total · page 208 of 7,573

  • CVE-2026-84484HigSep 2, 2026
    risk 0.42cvss 7.5epss 0.00

    ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a…

  • CVE-2026-84438LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the argument firstname causes cross site scripting. The attack can be…

  • CVE-2026-84437LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation of the argument address_1 results in cross site scripting. It is…

  • CVE-2026-84431MedSep 2, 2026
    risk 0.29cvss 4.4epss 0.00

    A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of the argument _display_name results in path traversal. The…

  • CVE-2026-82968MedSep 2, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly bound to the specific upstream identity being verified. This…

  • CVE-2026-84702HigSep 2, 2026
    risk 0.42cvss 7.5epss 0.00

    facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter through the unauthenticated HTTP API to create files at…

  • CVE-2026-84701MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API that executes in the browsers of all users viewing the…

  • CVE-2026-84700HigSep 2, 2026
    risk 0.56cvss 8.6epss 0.00

    PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a…

  • CVE-2026-84699CriSep 2, 2026
    risk 0.59cvss 9.1epss 0.00

    Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.

  • CVE-2026-84698MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute…

  • CVE-2026-84697MedSep 2, 2026
    risk 0.27cvss 5.3epss 0.00

    Mailpit's IsInternalIP deny list function fails to block the Azure WireServer address 168.63.129.16 and the RFC 2765/6145 IPv4-translated IPv6 prefix, allowing server-side request forgery to internal destinations. Attackers can supply hostnames resolving to these addresses in…

  • CVE-2026-84696HigSep 2, 2026
    risk 0.53cvss 8.2epss 0.00

    Phison PS3111-S11 controller firmware versions through SBFQT1.3 expose privileged vendor unique commands over the ATA interface with absent or defeatable authentication mechanisms. Attackers can bypass the weak CRC-16 based unlock handshake or exploit builds with no VUC lock to…

  • CVE-2026-84695HigSep 2, 2026
    risk 0.50cvss 8.7epss 0.00

    BookStack before 26.05.4 contains a stored cross-site scripting vulnerability in the drawing upload endpoint that accepts unvalidated base64 content and stores it without content inspection. Attackers with editor permissions can upload SVG files containing scripts that execute…

  • CVE-2026-84694HigSep 2, 2026
    risk 0.50cvss 8.8epss 0.00

    Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbitrary commands on the server host outside…

  • CVE-2026-84430MedSep 2, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability affects the function update of the file app/home/controller/Index.php of the component edit_personal Endpoint. Such manipulation of the argument position_id leads to…

  • CVE-2026-84427MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been…

  • CVE-2026-84425MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser Tool. Performing a manipulation results in denial of service. The attack can be initiated remotely. The…

  • CVE-2026-84359LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84358MedSep 2, 2026
    risk 0.27cvss 4.2epss 0.00

    Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84357MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Omnibox in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass web origin policy via crafted network traffic. (Chromium security severity: High)

  • CVE-2026-84356MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-84355LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84354CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84353CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-84352CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-84351HigSep 2, 2026
    risk 0.54cvss 8.3epss 0.00

    Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84350HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: Low)

  • CVE-2026-84349HigSep 2, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Browser in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84348MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in MediaCapture in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to potentially leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84347HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in WebRTC in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84335HigSep 2, 2026
    risk 0.54cvss 8.3epss 0.00

    Incorrect authorization in TabStrip in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security…

  • CVE-2026-84334HigSep 2, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.75 allowed a local attacker to execute arbitrary code outside the sandbox via a local program. (Chromium security severity: Medium)

  • CVE-2026-84333CriSep 2, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84332MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in SiteSettings in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84331LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-84330MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in FullScreen in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84329MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    Confused deputy in CredentialProvider in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-84328LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-84327MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Incorrect authorization in Autofill in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-84326HigSep 2, 2026
    risk 0.57cvss 8.8epss 0.00

    Uninitialized resource in V8 in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-84325CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)

  • CVE-2026-84324CriSep 2, 2026
    risk 0.59cvss 9.0epss 0.00

    Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)

  • CVE-2026-84323MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-81928HigSep 2, 2026
    risk 0.49cvss 7.5epss 0.00

    Net::DNS versions before 1.57 for Perl allow memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record. sig_data signs a message by re-encoding it, and removes TSIG records only from the additional section. A TSIG decoded into…

  • CVE-2026-84483MedSep 1, 2026
    risk 0.34cvss 5.3epss 0.00

    WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge authentication tokens by computing…

  • CVE-2026-84482HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to…

  • CVE-2026-84481MedSep 1, 2026
    risk 0.45cvss —epss 0.00

    WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to…

  • CVE-2026-84480CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's…

  • CVE-2026-84479CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.00

    WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp")…

  • CVE-2026-84478HigSep 1, 2026
    risk 0.47cvss 7.3epss 0.00

    WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit this to destroy audit logs and…