VYPR

CVEs

383,148 total · page 324 of 7,663

  • CVE-2026-75758MedAug 28, 2026
    risk 0.31cvss —epss 0.00

    Uncontrolled Recursion vulnerability in the Elixir standard library allows an attacker who controls a list passed to inspect/1, List.to_string/1, or List.to_charlist/1 to exhaust a BEAM node's memory. Inspect.List's charlist branch in lib/elixir/lib/inspect.ex classifies a list…

  • CVE-2026-6176HigAug 28, 2026
    risk 0.40cvss 7.2epss 0.00

    The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review…

  • CVE-2026-5953MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ceviz Informatics Inc. Web Design allows Reflected XSS. This issue affects Web Design: through 25082026.

  • CVE-2026-5934HigAug 28, 2026
    risk 0.40cvss 7.2epss 0.00

    The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for…

  • CVE-2026-5800MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Dayneks Software Industry and Trade Inc. E-Commerce Platform allows Reflected XSS. This issue affects E-Commerce Platform: through 28082026. NOTE: The vendor was contacted…

  • CVE-2026-5096MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    The Everest Forms plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.4.4. This is due to the `load_previous_field_value()` method in `class-evf-form-task.php` accepting arbitrary URL values from `$_POST` data for upload…

  • CVE-2026-58107MedAug 28, 2026
    risk 0.29cvss —epss 0.00

    CodeChecker's massStoreRun processing path performs one-shot decompression of attacker-controlled, Base64-encoded zlib data without enforcing a maximum decompressed size. An authenticated user with permission to store analysis runs can submit a highly compressed payload…

  • CVE-2026-58106LowAug 28, 2026
    risk 0.06cvss —epss 0.00

    CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r  was fixed by replacing unchecked strcpy() with a bounded safe_strcpy() helper. At ldlogger-tool-gcc.c:129 the destination passed to that helper is fullPath + 2, but the size passed down is…

  • CVE-2026-56854HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback,…

  • CVE-2026-50979HigAug 28, 2026
    risk 0.53cvss 8.1epss 0.02

    A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter

  • CVE-2026-4378MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Software Technologies Ltd. E-Commerce Pack allows Stored XSS. This issue affects E-Commerce Pack: from 4.5.001 before 4.6.001.

  • CVE-2026-3423MedAug 28, 2026
    risk 0.35cvss 6.4epss 0.00

    The Envira Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gallery 'description' configuration field in all versions up to, and including, 1.12.4 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-38725MedAug 28, 2026
    risk 0.35cvss 5.4epss 0.00

    xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript via the name and content parameters in ajax.php. The input is stored in the database without HTML sanitization and rendered in Smarty templates without output…

  • CVE-2026-38638HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-38636HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-38093LowAug 28, 2026
    risk 0.14cvss 3.3epss 0.00

    file_picker (aka flutter_file_picker) for Flutter, all versions through 10.3.10, is vulnerable to path traversal (CWE-22) in its Android implementation. The openFileStream() method in FileUtils.kt uses the DISPLAY_NAME obtained from ContentResolver.query() directly in file path…

  • CVE-2026-37751CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.03

    An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2026-37736HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    An issue in the JsonSanitizer.sanitize() component of OWASP json-sanitizer v1.2.3 allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2026-37710MedAug 28, 2026
    risk 0.33cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function

  • CVE-2026-37237HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp and call r.read() without…

  • CVE-2026-37236CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.00

    grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header,…

  • CVE-2026-19412HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit…

  • CVE-2026-15603MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An…

  • CVE-2026-14942Aug 28, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report was withdrawn: the precondition it depends on, an attacker obtaining a review form identifier belonging to a…

  • CVE-2026-13761HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

  • CVE-2026-82261HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become unresponsive while processing the…

  • CVE-2026-82260HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation,…

  • CVE-2026-82259HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating…

  • CVE-2026-82258MedAug 28, 2026
    risk 0.24cvss 4.8epss 0.00

    SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users'…

  • CVE-2026-82257MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.00

    SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling…

  • CVE-2026-82256MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.

  • CVE-2026-82255MedAug 28, 2026
    risk 0.44cvss 6.8epss 0.00

    gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation checks the original URL instead…

  • CVE-2026-82254HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.

  • CVE-2026-82253HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to…

  • CVE-2026-82252HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree,…

  • CVE-2026-82251HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to…

  • CVE-2026-82250MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger an index out of bounds panic,…

  • CVE-2026-82249LowAug 28, 2026
    risk 0.13cvss 3.1epss 0.00

    gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for…

  • CVE-2026-82248MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when…

  • CVE-2026-82247HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong…

  • CVE-2026-82246HigAug 28, 2026
    risk 0.39cvss 7.1epss 0.00

    Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud…

  • CVE-2026-82245HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable…

  • CVE-2026-82244CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.01

    Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the…

  • CVE-2026-82243HigAug 28, 2026
    risk 0.42cvss 7.6epss 0.00

    Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making…

  • CVE-2026-82242HigAug 28, 2026
    risk 0.43cvss 7.7epss 0.00

    Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the…

  • CVE-2026-82241HigAug 28, 2026
    risk 0.39cvss 7.1epss 0.00

    Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews. When the default blacklist is active (i.e., a self-hosted…

  • CVE-2026-82240HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with…

  • CVE-2026-82239HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit…

  • CVE-2026-82238LowAug 28, 2026
    risk 0.20cvss 3.1epss 0.00

    filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass…

  • CVE-2026-82237LowAug 28, 2026
    risk 0.13cvss 3.1epss 0.00

    filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file…