VYPR

CVEs

383,779 total · page 370 of 7,676

  • CVE-2026-78893MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    Information leak in QUIC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive information via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-78892HigAug 25, 2026
    risk 0.46cvss 7.1epss 0.00

    Incorrect authorization in Chromoting in Google Chrome on on Windows prior to 152.0.7977.65 allowed a local attacker to bypass system access restrictions via a local program. (Chromium security severity: Medium)

  • CVE-2026-78891HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-77680MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge…

  • CVE-2026-77357HigAug 25, 2026
    risk 0.50cvss —epss 0.01

    Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running in debug mode expose a GET /hot-reload endpoint whose unbounded loop depends on the user-supplied counter parameter, allowing an unauthenticated attacker to…

  • CVE-2026-75465HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.01

    The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote attacker can send a crafted HTTP GET request with limit and…

  • CVE-2026-75421MedAug 25, 2026
    risk 0.19cvss 4.0epss 0.00

    aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.

  • CVE-2026-72924LowAug 25, 2026
    risk 0.07cvss —epss 0.00

    GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created by gh codespace ports forward to all available network interfaces by default. While port forwarding is active, a service in a Codespace can therefore become…

  • CVE-2026-65105HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.00

    NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

  • CVE-2026-65099HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

  • CVE-2026-65098HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

  • CVE-2026-65097HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure,…

  • CVE-2026-65096HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data…

  • CVE-2026-65093CriAug 25, 2026
    risk 0.64cvss 9.9epss 0.01

    NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-65092HigAug 25, 2026
    risk 0.55cvss 8.5epss 0.01

    NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

  • CVE-2026-65091HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.03

    NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

  • CVE-2026-65090HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

  • CVE-2026-65089HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

  • CVE-2026-65088MedAug 25, 2026
    risk 0.36cvss 5.5epss 0.00

    NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-65087MedAug 25, 2026
    risk 0.36cvss 5.6epss 0.00

    NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.

  • CVE-2026-65086MedAug 25, 2026
    risk 0.44cvss 6.8epss 0.02

    NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.

  • CVE-2026-65085MedAug 25, 2026
    risk 0.34cvss 5.2epss 0.00

    NVIDIA OpenShell for Linux contains a vulnerability in its inference proxy, where an attacker could cause an improper encoding or escaping of output. A successful exploit of this vulnerability might lead to information disclosure and data tampering.

  • CVE-2026-65084HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.01

    NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of…

  • CVE-2026-65083CriAug 25, 2026
    risk 0.64cvss 9.9epss 0.01

    NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure,…

  • CVE-2026-65082HigAug 25, 2026
    risk 0.46cvss 7.0epss 0.00

    NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.

  • CVE-2026-65081HigAug 25, 2026
    risk 0.53cvss 8.1epss 0.00

    NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure,…

  • CVE-2026-55588MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.01

    ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registry that returns a cyclic referrer graph…

  • CVE-2026-53965MedAug 25, 2026
    risk 0.38cvss —epss 0.01

    The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to an in-memory buffer with no upper bound.…

  • CVE-2026-52491HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.00

    An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

  • CVE-2026-52489HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary code via the svgNameToImplementationName() function

  • CVE-2026-51368CriAug 25, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint

  • CVE-2026-39113MedAug 25, 2026
    risk 0.19cvss 4.0epss 0.00

    Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d (Git mirror 169f68ed88b34cb68f720191c64c058f2ccec508, 2026-03-11) and later snapshots/builds allows an…

  • CVE-2026-77585MedAug 25, 2026
    risk 0.34cvss 5.3epss 0.00

    The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.

  • CVE-2026-74932HigAug 25, 2026
    risk 0.49cvss 7.5epss 0.00

    The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using it to build the URLs of the asset files it embeds in the pages it caches, and does not include that header in the cache key, allowing unauthenticated attackers to poison cached…

  • CVE-2026-68515HigAug 25, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two…

  • CVE-2026-68514MedAug 25, 2026
    risk 0.29cvss 5.5epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13, the PyOpenEXR Python bindings contain a heap out-of-bounds write triggered when reading…

  • CVE-2026-68513HigAug 25, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 contain a heap buffer overflow in PyOpenEXR triggered by a channel-name key collision between…

  • CVE-2026-66153HigAug 25, 2026
    risk 0.46cvss 7.0epss 0.00

    The NEService auto-upgrade process insecurely handles temporary files in SonicWall NetExtender Linux client which allows an attacker to manipulate file paths.

  • CVE-2026-66152HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    A Path traversal vulnerability in the SonicWall NetExtender Linux client file extractor component allows an attacker to write arbitrary file as root.

  • CVE-2026-65367MedAug 25, 2026
    risk 0.36cvss 5.5epss 0.00

    A null pointer dereference was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5. An app may be able to cause unexpected system termination.

  • CVE-2026-64705MedAug 25, 2026
    risk 0.36cvss 5.5epss 0.00

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.

  • CVE-2026-59981HigAug 25, 2026
    risk 0.39cvss 7.1epss 0.00

    OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the…

  • CVE-2026-55099HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.01

    icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 7.1.0 until 7.1.3, the Component equality method in src/icalendar/cal/component.py compares nested subcomponents with two membership loops, and each membership test invokes the same…

  • CVE-2026-45019HigAug 25, 2026
    risk 0.40cvss 7.2epss 0.00

    Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For sse…

  • CVE-2026-45018CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint without requiring authentication. For stdio…

  • CVE-2026-43670HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.00

    A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security…

  • CVE-2026-43657LowAug 25, 2026
    risk 0.21cvss 3.3epss 0.00

    A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.5 and iPadOS 26.5. A malicious app may be able to enumerate installed apps.

  • CVE-2026-80050MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    ContiNew Admin fails to apply file-upload permission checks or file-type allowlist validation to multipart upload endpoints, allowing authenticated users to store files with arbitrary extensions. Attackers can initialize chunked uploads, send file parts, and complete uploads to…

  • CVE-2026-80049HigAug 25, 2026
    risk 0.50cvss 8.8epss 0.00

    Airbyte Platform resolves the workspace used for its authorization decision from a field the caller supplies. AuthorizationServerHandler copies recognised identifiers out of the raw JSON request body into X-Airbyte-* headers, and AuthenticationHeaderResolver.resolveWorkspace…

  • CVE-2026-79788HigAug 25, 2026
    risk 0.39cvss 7.1epss 0.00

    In Dradis Community Edition, the ProvidersController and AgentsController gate their admin_required before_action on `defined?(Dradis::Pro)`, a constant that is never defined in CE, so the authorization check is never applied. As a result, any authenticated (non-admin) user can…