VYPR

CVEs

378,628 total · page 209 of 7,573

  • CVE-2026-84477MedSep 1, 2026
    risk 0.35cvss 5.4epss 0.00

    AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without…

  • CVE-2026-84476HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited…

  • CVE-2026-84423HigSep 1, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-84208HigSep 1, 2026
    risk 0.42cvss 7.5epss 0.00

    AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement…

  • CVE-2026-84642HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended hostnames to also match and serve remote attachments. This vulnerability was…

  • CVE-2026-84641HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84640HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84639CriSep 1, 2026
    risk 0.59cvss 9.1epss 0.00

    Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

  • CVE-2026-84637CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.00

    Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new invitation display enabled, the attachment could also appear under a misleading…

  • CVE-2026-84375HigSep 1, 2026
    risk 0.42cvss 7.5epss 0.00

    js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An attacker can alias a large sequence of empty mappings into…

  • CVE-2026-84374HigSep 1, 2026
    risk 0.42cvss 7.5epss 0.01

    Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export->store(), or storeExcel()…

  • CVE-2026-84373MedSep 1, 2026
    risk 0.31cvss 5.9epss 0.00

    Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest:interceptor:register handler on Vite's unauthenticated HMR…

  • CVE-2026-84372CriSep 1, 2026
    risk 0.57cvss 9.8epss 0.00

    Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by…

  • CVE-2026-84289MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulation results in uncontrolled memory allocation. It is possible to initiate the…

  • CVE-2026-84288MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from…

  • CVE-2026-83549HigKEVSep 1, 2026
    risk 0.66cvss 7.8epss 0.09

    Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated…

  • CVE-2026-83548CriKEVSep 1, 2026
    risk 0.77cvss 10.0epss 0.05

    A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and…

  • CVE-2026-76851HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.01

    A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed remote code execution on the instance. Insufficient network isolation allowed malicious pre-receive hook code to impersonate an internal service and redirect trusted…

  • CVE-2026-75604CriSep 1, 2026
    risk 0.55cvss 9.0epss 0.02

    Next.js is a React framework for building full-stack web applications. From 13.4.0 until 15.5.24 and 16.3.3, Next.js applications using Pages Router or App Router without Cache Components on Windows-hosted servers do not consistently escape backslashes in route segments before…

  • CVE-2026-19118HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.01

    A time-of-check time-of-use race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution. Exploitation required an authenticated user with write access to a repository and precise timing of concurrent upload requests. This…

  • CVE-2026-18730HigSep 1, 2026
    risk 0.48cvss 7.4epss 0.00

    A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send crafted outbound requests to an attacker-controlled host. An unauthenticated endpoint parsed an…

  • CVE-2023-54391CriSep 1, 2026
    risk 0.64cvss 9.8epss 0.02

    Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary…

  • CVE-2026-84470MedSep 1, 2026
    risk 0.42cvss 6.4epss 0.00

    A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level…

  • CVE-2026-84371MedSep 1, 2026
    risk 0.28cvss 5.4epss 0.00

    ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer with a clear API. From version 1.9.0 until version 2.17.7, packages/sanitize-html/index.js validates an animation value attribute as one flat URL and does not…

  • CVE-2026-84370HigSep 1, 2026
    risk 0.46cvss 8.2epss 0.00

    SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3, incompletely filters executable…

  • CVE-2026-84369MedSep 1, 2026
    risk 0.33cvss 6.1epss 0.00

    SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.4, 3.3.5, and 4.1.0, the opt-in removeScripts plugin, named removeScriptElement in versions 2 and 3 and implemented in…

  • CVE-2026-84368LowSep 1, 2026
    risk 0.17cvss 3.7epss 0.00

    joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/joi package through 17.1.1 and the successor joi package contain prototype pollution in lib/messages.js, where exports.compile() and exports.merge() reuse…

  • CVE-2026-84367LowSep 1, 2026
    risk 0.17cvss 3.7epss 0.00

    joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/types/keys.js internals.rename() implementation used by object().rename() permits a schema that renames keys with a regular-expression source and a…

  • CVE-2026-84366HigSep 1, 2026
    risk 0.41cvss 7.4epss 0.00

    Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless…

  • CVE-2026-84365MedSep 1, 2026
    risk 0.35cvss 6.5epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. From 4.12.12 until 4.13.5, the fix released for CVE-2026-39408 does not cover every traversal sequence, and toSSG() can still write files outside the configured output directory when a route…

  • CVE-2026-84364MedSep 1, 2026
    risk 0.27cvss 5.3epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, when parseBody() expands dot-separated form field names into nested objects with dot-notation parsing enabled, it does not limit the nesting depth or the total number of…

  • CVE-2026-84363MedSep 1, 2026
    risk 0.31cvss 5.9epss 0.00

    Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.13.5, Hono's query helpers treat a question mark after a literal hash fragment as the start of a query string, so the application can read request parameters that browsers, new…

  • CVE-2026-84361HigSep 1, 2026
    risk 0.43cvss —epss 0.00

    Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url to an rsh: or jsh: P4PORT value. When the…

  • CVE-2026-84311MedSep 1, 2026
    risk 0.24cvss —epss 0.00

    pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a…

  • CVE-2026-84310MedSep 1, 2026
    risk 0.24cvss —epss 0.00

    pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_doc_common.py _get_outline to consume long runtimes and large amounts of memory when retrieving document outlines with large numbers of entries or deeply…

  • CVE-2026-84287MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried…

  • CVE-2026-73783MedSep 1, 2026
    risk 0.32cvss 4.9epss 0.00

    Stack overflow vulnerabilities exist in an API endpoint of AOS-CX. Successful exploitation could allow an authenticated malicious actor to cause a denial-of-service condition on the affected system.

  • CVE-2026-73782HigSep 1, 2026
    risk 0.57cvss 8.8epss 0.00

    A format string vulnerability exists in the command line interface of AOS-CX that could lead to unauthenticated remote code execution. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating…

  • CVE-2026-73781HigSep 1, 2026
    risk 0.55cvss 8.4epss 0.00

    A vulnerability in the web-based management interface of AOS-CX could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack against an administrative user of the interface. A successful exploit allows an attacker to execute arbitrary script…

  • CVE-2026-73780HigSep 1, 2026
    risk 0.54cvss 8.3epss 0.00

    A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker…

  • CVE-2026-73779HigSep 1, 2026
    risk 0.53cvss 8.2epss 0.00

    Vulnerabilities have been identified in the operating system of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls. Successful exploitation could compromise system integrity and further expose sensitive…

  • CVE-2026-73778HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.00

    A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured…

  • CVE-2026-73777HigSep 1, 2026
    risk 0.53cvss 8.1epss 0.00

    Vulnerabilities have been identified in the API endpoint of AOS-CX switches that could potentially allow an unauthenticated remote actor to circumvent existing authentication controls.

  • CVE-2026-73776HigSep 1, 2026
    risk 0.51cvss 7.9epss 0.00

    A signature verification bypass vulnerability exists in the command line interface of AOS-CX. Successful exploitation could allow an authenticated malicious actor with administrative privileges to execute arbitrary code on the underlying operating system, when certain…

  • CVE-2026-73775HigSep 1, 2026
    risk 0.50cvss 7.7epss 0.00

    Vulnerabilities in the API endpoint of AOS-CX could allow a remote attacker authenticated with low privileges to access sensitive information. A successful exploit allows an attacker to retrieve information which could be used to potentially gain further access to network…

  • CVE-2026-73774HigSep 1, 2026
    risk 0.49cvss 7.6epss 0.00

    A buffer overflow vulnerability exists in the underlying operating system of AOS-CX that could lead to unauthenticated disclosure of sensitive information by sending specially crafted packets to the affected system. Successful exploitation of this vulnerability could result in…

  • CVE-2026-73773HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated Denial-of-Service (DoS) vulnerability exists in the API endpoint of AOS-CX. Successful exploitation of this vulnerability results in the ability to interrupt the normal operation of the affected service.

  • CVE-2026-73772MedSep 1, 2026
    risk 0.42cvss 6.5epss 0.00

    Buffer overflow vulnerabilities exist in an underlying service of AOS-CX that could lead to an unauthenticated denial-of-service condition by sending specially crafted packets to the affected device. Successful exploitation of these vulnerabilities results in a disruption of…

  • CVE-2026-73771HigSep 1, 2026
    risk 0.49cvss 7.5epss 0.00

    An authentication vulnerability exists in the AOS-CX management interface and API that may allow improper authentication processing. An unauthenticated remote attacker could exploit this vulnerability under specific conditions to bypass authentication controls or exhaust system…

  • CVE-2026-73770HigSep 1, 2026
    risk 0.47cvss 7.3epss 0.00

    An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary…