VYPR

CVEs

383,724 total · page 362 of 7,675

  • CVE-2026-65183HigAug 25, 2026
    risk 0.46cvss 8.1epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through…

  • CVE-2026-65182CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1…

  • CVE-2026-63404HigAug 25, 2026
    risk 0.40cvss —epss 0.00

    Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an insecure temporary file flaw that lets a local unprivileged user hijack the Redis configuration and escalate to root. It writes its startup…

  • CVE-2026-63403HigAug 25, 2026
    risk 0.50cvss —epss 0.00

    Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauthenticated denial of service in which a single malformed command crashes the entire process. Its wire protocol is line-based, and several command handlers slice…

  • CVE-2026-62865HigAug 25, 2026
    risk 0.50cvss —epss 0.00

    Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integration block allows arbitrary reading of local files on the server. The block builds Nodemailer attachments from a typebot variable, and its parseAttachments…

  • CVE-2026-62862CriAug 25, 2026
    risk 0.52cvss —epss 0.01

    Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless email magic-link authentication is vulnerable to login-code brute forcing that leads to account takeover. The email provider overrides NextAuth's default…

  • CVE-2026-62861MedAug 25, 2026
    risk 0.35cvss —epss 0.00

    TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another workspace's public custom domain and make typebots on that domain unavailable. The custom-domain delete handler in handleDeleteCustomDomain.ts authorizes a caller…

  • CVE-2026-38474MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulnerability in the IP lock manager, which allows remote authenticated users to add, modify, or delete IP lock entries for arbitrary accounts via…

  • CVE-2026-38473Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via a crafted subtitle filename, which is stored during upload and later…

  • CVE-2026-38472Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote attackers to inject arbitrary JavaScript via the c parameter in /forums.php?action=ajax_get_jf which is later rendered in the…

  • CVE-2026-38470Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows unprivileged, authenticated users to enable or disable arbitrary user accounts via the req=disable or req=enable action using a…

  • CVE-2026-38469Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the title parameter in /bonus.php and /user.php?action=staff_tool.

  • CVE-2026-38468Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_view_ips privileges to execute arbitrary SQL commands via the ip parameter in a crafted…

  • CVE-2026-38467MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with users_mod privileges to execute arbitrary SQL commands via the tagid or type parameter in a crafted POST…

  • CVE-2026-38466Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the remaster_custom_title parameter, which is stored…

  • CVE-2026-38465Aug 25, 2026
    risk 0.00cvss —epss 0.00

    A Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users to inject arbitrary JavaScript via the avatar_mouse_over_text parameter, which is stored and…

  • CVE-2026-32637MedAug 25, 2026
    risk 0.31cvss —epss 0.01

    Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-directory paths that…

  • CVE-2026-80104CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py takes file.filename as given and writes the request body to…

  • CVE-2026-80101MedAug 25, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validates the image width and bytes-per-line parameters independently rather than ensuring their combined values are consistent with the allocated buffer size. This…

  • CVE-2026-79793MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/sumit_form.php. Such manipulation of the argument Success leads to cross site scripting. The attack may be launched remotely.…

  • CVE-2026-79792MedAug 25, 2026
    risk 0.36cvss 5.6epss 0.02

    A flaw has been found in zackees transcribe-anything up to 4.1.0. Affected is the function ytdlp_download of the file src/transcribe_anything/ytldp_download.py of the component Yt-dlp Download. This manipulation of the argument url causes os command injection. The attack may be…

  • CVE-2026-79293MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79292HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.00

    Integer overflow in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79291MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79290CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-79289LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79288MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79287MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79286HigAug 25, 2026
    risk 0.48cvss 7.4epss 0.00

    Missing authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to potentially execute arbitrary code outside the sandbox via a co-installed app. (Chromium security severity: Medium)

  • CVE-2026-79285MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79284MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    UI misrepresentation in Core in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79283MedAug 25, 2026
    risk 0.35cvss 5.4epss 0.00

    UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79282CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-79276MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper privilege management in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79275CriAug 25, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79274MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Information leak in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-79273MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect reference resolution in WebView in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79272LowAug 25, 2026
    risk 0.20cvss 3.1epss 0.00

    Improper input validation in FindInPage in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79271MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79270MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79269MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79267MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Race condition in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79266HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in DevTools in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted Chrome extension. (Chromium security severity: Medium)

  • CVE-2026-79265MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79264MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect reference resolution in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79263HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.00

    Race condition in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via crafted network traffic. (Chromium security severity: Low)

  • CVE-2026-79262MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-79261MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect authorization in Controls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79260MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2026-79259MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper input validation in Safebrowsing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass system access restrictions via a crafted file. (Chromium security severity: Medium)