VYPR

CVEs

382,879 total · page 305 of 7,658

  • CVE-2026-82833MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. Affected by this issue is the function ExampleDetail of the file /v1/projects/1/examples/…

  • CVE-2026-81267MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.

  • CVE-2026-52730MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module…

  • CVE-2026-51740CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51739MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51738Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51737MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51736CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51735HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51734CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51733Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51732MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51731CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-14697MedAug 31, 2026
    risk 0.35cvss 6.5epss 0.00

    net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pending_queue is already non-empty (an NS is already outstanding), the function…

  • CVE-2026-13732HigAug 31, 2026
    risk 0.46cvss 7.0epss 0.00

    A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to…

  • CVE-2026-83589impAug 31, 2026
    risk 0.40cvss 6.1epss —

    oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect

  • CVE-2026-83497HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.01

    Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql…

  • CVE-2026-82821MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The attack may be initiated remotely. The exploit…

  • CVE-2026-82820MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit…

  • CVE-2026-82818MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing a manipulation of the argument tenantId can lead to improper access controls. The attack…

  • CVE-2026-72001HigAug 31, 2026
    risk 0.46cvss 8.1epss 0.00

    Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by supplying an attacker-controlled URL parameter to the share-link authentication endpoint that omits the expected resource identifier…

  • CVE-2026-53553HigAug 31, 2026
    risk 0.43cvss 7.7epss 0.00

    Goploy is an open-source automation deployment system. Prior to version 1.18.0, a severe path traversal vulnerability exists in its backend API endpoints, specifically /deploy/fileDiff (File Compare), when handling file paths provided by the client. This issue has been patched…

  • CVE-2026-53552CriAug 31, 2026
    risk 0.62cvss 9.6epss 0.00

    Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id from the JSON body and act on it without…

  • CVE-2026-53508MedAug 31, 2026
    risk 0.32cvss —epss 0.01

    oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRefsAllowed = false) when loading a spec from…

  • CVE-2026-53507HigAug 31, 2026
    risk 0.47cvss —epss 0.01

    oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the oasdiff actions resolved external $refs in the OpenAPI spec by default (allow-external-refs: true). When an action runs on a pull…

  • CVE-2026-14696MedAug 31, 2026
    risk 0.35cvss 6.5epss 0.00

    When Ethernet bridging is enabled (CONFIG_NET_ETHERNET_BRIDGE), eth_bridge_input_process() in subsys/net/l2/ethernet/bridge/bridge_input.c decides how each frame received on a bridge member interface is handled. For frames that must also be delivered to the local stack, the code…

  • CVE-2026-14368MedAug 31, 2026
    risk 0.28cvss 5.4epss 0.00

    The LwM2M JSON content formatter's get_string() in subsys/net/lib/lwm2m/lwm2m_rw_json.c copies a parsed JSON string into a caller-supplied buffer and NUL-terminates it. The length guard used if (string_length > buflen), which accepts a string whose length is exactly buflen.…

  • CVE-2026-14367LowAug 31, 2026
    risk 0.13cvss 3.1epss 0.00

    The I3C IBI subsystem in drivers/i3c/i3c_ibi_workq.c hands out statically-allocated work nodes through a free-list i3c_ibi_work_nodes_free implemented as a plain sys_slist_t, which provides no synchronization. The allocation helpers (i3c_ibi_work_enqueue,…

  • CVE-2023-31308LowAug 31, 2026
    risk 0.21cvss 3.3epss 0.00

    A malicious virtual function can invoke the certain command handlers in the SMU, causing a denial of service due to out-of-bounds memory read.

  • CVE-2023-20511MedAug 31, 2026
    risk 0.42cvss 6.4epss 0.00

    Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow a privileged attacker to create a double free condition potentially leading to arbitrary code execution.

  • CVE-2026-82817MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in dibo-software diboot 3.8.0. Affected by this issue is some unknown functionality of the file /admin/ of the component Tenant Administrator Management API. Performing a manipulation of the argument tenantId results in improper access controls. The…

  • CVE-2026-82816MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in dibo-software diboot 3.8.0. Affected by this vulnerability is an unknown functionality of the file /api/ai-session/ of the component AI Session Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The…

  • CVE-2026-82815HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.01

    A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated…

  • CVE-2026-82813MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was detected in BEN Group TubeBuddy for YouTube Extension up to 5.8.4 on Chrome. This impacts the function TBGlobal.GetToken of the file tubebuddymaster1.js. The manipulation of the argument t/c/r results in insufficient verification of data authenticity. It is…

  • CVE-2026-82811MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-79750HigAug 31, 2026
    risk 0.43cvss 7.7epss 0.00

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.30, MCPHub scopes non-admin users to servers they own (list views and config edits enforce…

  • CVE-2026-79749HigAug 31, 2026
    risk 0.42cvss —epss 0.00

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, MCPHub's SSRF guard in src/utils/ssrf.ts uses a custom isBlockedIpv6 function that only…

  • CVE-2026-79748CriAug 31, 2026
    risk 0.57cvss 9.9epss 0.01

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endpoints in MCPHub create/update MCP…

  • CVE-2026-79747HigAug 31, 2026
    risk 0.39cvss 7.1epss 0.00

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, an authenticated non-admin user can register a server pointing at an arbitrary URL and make…

  • CVE-2026-79746HigAug 31, 2026
    risk 0.46cvss 8.1epss 0.00

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.31, when a bearer key with accessType: 'servers' (or 'custom') is used against a group route,…

  • CVE-2026-79745HigAug 31, 2026
    risk 0.39cvss 7.1epss 0.00

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.32, the built-in prompt and resource controllers perform no role checking. The mutating POST/PUT…

  • CVE-2026-79744HigAug 31, 2026
    risk 0.50cvss 8.8epss 0.01

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 1.0.29, MCPHub's PUT /api/system-config endpoint (handler updateSystemConfig) performs no…

  • CVE-2026-79743MedAug 31, 2026
    risk 0.38cvss —epss 0.01

    MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.13, MCPB File Upload Handler extracts a ZIP file and reads manifest.json from it. The name field…

  • CVE-2026-51730CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51729CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delDevice function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to request deletion of a managed slave device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51728Aug 31, 2026
    risk 0.00cvss —epss 0.01

    Incorrect access control in the UploadFirmwareFile function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to upload a crafted firmware image via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51727MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the SystemSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve administrative import and export endpoint information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51726CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the delParentalRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove parental-control rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51725CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the NTPSyncWithHost function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the device clock via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-19953MedAug 31, 2026
    risk 0.35cvss 6.5epss 0.00

    URI versions before 5.36 for Perl encode non-NFC host names to non-standard punycode labels via missing normalization in nameprep. nameprep lowercases each host label but performs no Unicode normalization. IDNA requires a label to be normalized to Form C before it is encoded…