VYPR

CVEs

383,178 total · page 325 of 7,664

  • CVE-2026-37236CriAug 28, 2026
    risk 0.57cvss 9.8epss 0.00

    grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header,…

  • CVE-2026-19412HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded HTTP Digest authentication credentials in the firmware that are identical across all devices running the affected firmware. An attacker with access to the local network could exploit…

  • CVE-2026-15603MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    morgan is an HTTP request logger middleware for Node.js. In versions prior to 1.12.0, the internal helper that escapes log token values did not neutralize the Unicode line separator characters U+0085 (Next Line), U+2028 (Line Separator), and U+2029 (Paragraph Separator). An…

  • CVE-2026-14942Aug 28, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID was assigned to a reported vulnerability in the Customer Reviews for WooCommerce WordPress plugin and was never published. The report was withdrawn: the precondition it depends on, an attacker obtaining a review form identifier belonging to a…

  • CVE-2026-13761HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    Pega Platform versions 7.1.0 through 25.1.2 are affected by an improper validation of inputs that are used for loop conditions, potentially leading to a denial of service or other consequences because of excessive looping.

  • CVE-2026-82261HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions and form enabled contain a CPU exhaustion vulnerability in form deserialization. An attacker can send malformed form data to cause the server to become unresponsive while processing the…

  • CVE-2026-82260HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experimental remote functions (experimental.remoteFunctions) and form enabled contain a memory exhaustion vulnerability in remote form deserialization. Malformed form data can cause excessive memory allocation,…

  • CVE-2026-82259HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    SvelteKit versions from 2.49.0 through 2.53.2 (fixed in 2.53.3) contain a deserialization expansion issue in the experimental form remote function. When an application enables experimental.remoteFunctions and uses the form function to process the files array without validating…

  • CVE-2026-82258MedAug 28, 2026
    risk 0.24cvss 4.8epss 0.00

    SvelteKit versions from 2.38.0 before 2.60.1 contain a race condition in query.batch that allows concurrent requests from different users to merge under a single request context. Attackers can exploit specific timing conditions to access sensitive data from other users'…

  • CVE-2026-82257MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.00

    SvelteKit versions before 2.69.1 contain a prototype pollution vulnerability in remote form functions with file input fields that accept arbitrary user-controlled path names. Attackers can manipulate the deletion path to remove methods on the prototype, potentially disabling…

  • CVE-2026-82256MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    SvelteKit before 2.69.1 fails to properly validate remote form function payload sizes, allowing attackers to crash the Node process by sending large payloads. Repeated exploitation causes denial of service by repeatedly crashing the application process.

  • CVE-2026-82255MedAug 28, 2026
    risk 0.44cvss 6.8epss 0.00

    gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where credentials are sent to attacker-controlled servers after HTTP redirects. The vulnerability occurs because credential validation checks the original URL instead…

  • CVE-2026-82254HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    gitoxide before 0.69.0 contains unchecked array indexing in delta application and uncapped allocation from attacker-controlled size headers in gix-pack. Attackers can send crafted pack data during clone or fetch operations to trigger panics or out-of-memory process kills.

  • CVE-2026-82253HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contains a path traversal vulnerability. The submodule name validation function in gix-validate only checks the first occurrence of '..' via name.find(b".."), allowing crafted names such as 'a..b/../../../.git/' to…

  • CVE-2026-82252HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    gitoxide before 0.52.1 follows symlinks when reading the worktree .gitmodules file, allowing attackers to inject out-of-repository bytes into submodule metadata. Attackers can create a malicious repository with a symlinked .gitmodules pointing outside the repository tree,…

  • CVE-2026-82251HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    gitoxide before 0.52.1 fails to validate submodule names from .gitmodules configuration, allowing path traversal when deriving submodule git directories. Attackers can craft malicious submodule names with traversal segments to redirect state() and open() functions to…

  • CVE-2026-82250MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs when processing side-band packet lines with empty payloads. A malicious Git server can send a crafted side-band packet to trigger an index out of bounds panic,…

  • CVE-2026-82249LowAug 28, 2026
    risk 0.13cvss 3.1epss 0.00

    gitoxide before 0.38.2 fails to validate carriage return characters in URL values passed to credential helpers. Attackers can supply URLs containing bare carriage returns to inject additional helper protocol fields and cause credential helpers to return credentials for…

  • CVE-2026-82248MedAug 28, 2026
    risk 0.27cvss 5.3epss 0.00

    gix-worktree-state before 0.33.0 (part of gitoxide) allows writing files outside the worktree on Windows. gix_worktree_state::checkout() follows an existing terminal symlink during non-exclusive (incremental) materialization (destination_is_initially_empty: false) when…

  • CVE-2026-82247HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-rolled URL parser that does not treat '?' or '#' as terminating the authority component, contrary to RFC 3986. As a consequence, gix-transport's HTTP redirect identity guard (can_reuse_identity) compares the wrong…

  • CVE-2026-82246HigAug 28, 2026
    risk 0.39cvss 7.1epss 0.00

    Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the query import endpoint that fails to validate user-supplied URLs before fetching content. Attackers can submit arbitrary URLs to retrieve responses from internal services including cloud…

  • CVE-2026-82245HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Budibase before 3.41.3 fails to enforce role-based authorization on license management endpoints, allowing any authenticated user to delete license keys or manipulate offline tokens. Attackers with basic user privileges can access /api/global/license/* endpoints to disable…

  • CVE-2026-82244CriAug 28, 2026
    risk 0.52cvss 9.1epss 0.01

    Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the…

  • CVE-2026-82243HigAug 28, 2026
    risk 0.42cvss 7.6epss 0.00

    Budibase Server before 3.41.3 contains a server-side request forgery vulnerability in the datasource verify endpoint that allows builder-level users to supply arbitrary URLs without SSRF validation. Attackers can exploit this to leak internal CouchDB credentials by making…

  • CVE-2026-82242HigAug 28, 2026
    risk 0.43cvss 7.7epss 0.00

    Budibase versions before 3.41.3 contain a missing authorization vulnerability in the POST /api/resources/duplicate endpoint that allows authenticated builders to inject tables, automations, queries, and screens into any other application without holding any role in the…

  • CVE-2026-82241HigAug 28, 2026
    risk 0.39cvss 7.1epss 0.00

    Budibase backend-core (@budibase/backend-core, as used by @budibase/server) omits the shared address space range 100.64.0.0/10 from its default SSRF blacklist (DEFAULT_BLACKLIST) used by REST datasource query previews. When the default blacklist is active (i.e., a self-hosted…

  • CVE-2026-82240HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Budibase before 3.41.3 fails to validate app-scoped builder role assignments in the public user create and update endpoints, allowing an authenticated app-scoped builder to grant builder access to unrelated apps. Attackers can submit crafted requests to the user update API with…

  • CVE-2026-82239HigAug 28, 2026
    risk 0.46cvss 8.1epss 0.00

    Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit…

  • CVE-2026-82238LowAug 28, 2026
    risk 0.20cvss 3.1epss 0.00

    filebrowser from version 2.24.0 contains a race condition in the TUS upload handler that allows authenticated users to write past the declared Upload-Length by sending concurrent PATCH requests. Attackers can send multiple simultaneous PATCH requests at the same offset to bypass…

  • CVE-2026-82237LowAug 28, 2026
    risk 0.13cvss 3.1epss 0.00

    filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path is empty). When any new, unrelated file…

  • CVE-2026-82236LowAug 28, 2026
    risk 0.13cvss 3.1epss 0.00

    File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.

  • CVE-2026-82235MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.01

    filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing attackers to trigger blocking open syscalls. Authenticated users or anonymous visitors with public share links can repeatedly request archives containing named…

  • CVE-2026-82234HigAug 28, 2026
    risk 0.46cvss 8.2epss 0.00

    SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard…

  • CVE-2026-82233MedAug 28, 2026
    risk 0.30cvss 5.7epss 0.00

    SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary validation. Attackers can induce the AI Agent to upload sensitive files such as SSH keys or credentials from outside…

  • CVE-2026-82222CriAug 28, 2026
    risk 0.65cvss 10.0epss 0.02

    Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.

  • CVE-2026-82111MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was detected in iswalle getnote-mcp up to 1.5.0. The affected element is the function fs.readFileSync of the file src/index.ts of the component upload_image. Performing a manipulation of the argument image_path results in path traversal. The attack can be…

  • CVE-2026-81777MedAug 28, 2026
    risk 0.34cvss 5.3epss 0.00

    Authentication Bypass by Spoofing vulnerability in WPDeveloper Essential Addons for Elementor allows Identity Spoofing. This issue affects Essential Addons for Elementor: from n/a through 6.8.0.

  • CVE-2026-81733MedAug 28, 2026
    risk 0.33cvss —epss 0.00

    WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from…

  • CVE-2026-81732MedAug 28, 2026
    risk 0.45cvss —epss 0.01

    WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative…

  • CVE-2026-78073MedAug 28, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors

  • CVE-2026-78072HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    Joomla Extension - Jefferson49 - Unauthenticated blind SQLi in Sexy Polling Reloaded < 5.6.1

  • CVE-2026-78071HigAug 28, 2026
    risk 0.49cvss —epss 0.00

    Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0-8.19.5, 9.0.0-10.12.0 - Location title is rendered in data attribute without escaping leads to XSS, needs create permission in DPCalendar.

  • CVE-2026-78070MedAug 28, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - digital-peak.com - Authenticated, privileged blind SQL injection in DP Calendar 5.5.0 - 10.11.2 - Saving an article can trigger a blind SQL injection with content plugin, needs update permission for articles.

  • CVE-2026-73209MedAug 28, 2026
    risk 0.42cvss 6.5epss 0.00

    An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its stack and crash. The affected process is terminated, which can cause degradation or denial of service for IMAP. Update to non-vulnerable version. No publicly…

  • CVE-2026-73208HigAug 28, 2026
    risk 0.48cvss 7.4epss 0.00

    An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and…

  • CVE-2026-6128MedAug 28, 2026
    risk 0.42cvss 6.4epss 0.00

    The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ai1wm_backups_path' parameter in all versions up to, and including, 2.84. This is due to insufficient input sanitization and output escaping on…

  • CVE-2026-5510MedAug 28, 2026
    risk 0.35cvss 6.4epss 0.00

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'give_form' shortcode in all versions up to, and including, 4.14.4. This is due to insufficient input sanitization and output escaping on the…

  • CVE-2026-52687MedAug 28, 2026
    risk 0.42cvss 6.5epss 0.00

    An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression state requires a large amount of memory, and open several such connections. The memory limit of the process is reached with only a few connections, terminating…

  • CVE-2026-52681LowAug 28, 2026
    risk 0.20cvss 3.1epss 0.00

    Sieve CPU resource usage is tracked in the compiled script, so an attacker that has valid credentials can reset the accounting by repeatedly changing the active script. Compiled script files are also not removed when a script is deleted or renamed. The configured Sieve CPU limit…

  • CVE-2026-42395MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    A host listed as a trusted proxy can send forwarding information containing a NUL byte, which crashes the login process on the following login attempt. The login process is terminated, which can cause degradation or denial of service for logins. Deployments that do not configure…