VYPR

CVEs

383,790 total · page 373 of 7,676

  • CVE-2026-16234HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI…

  • CVE-2026-16233HigAug 25, 2026
    risk 0.51cvss 7.8epss 0.00

    There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI…

  • CVE-2026-13478MedAug 25, 2026
    risk 0.29cvss 5.5epss 0.00

    The Zephyr ext2 filesystem driver validates the on-disk block bitmap in ext2_init_fs() (subsys/fs/ext2/ext2_impl.c) by passing fs_blocks = s_blocks_count - s_first_data_block to ext2_bitmap_count_set(). That helper (subsys/fs/ext2/ext2_bitmap.c) treats its argument as a number…

  • CVE-2026-13217MedAug 25, 2026
    risk 0.31cvss 5.9epss 0.01

    The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLRESULT message. In ocpp_process_server_msg() the code calls atoi(strtok_r(uid, "-", &tmp)) without checking the strtok_r return value. When the server-supplied…

  • CVE-2026-13216MedAug 25, 2026
    risk 0.33cvss 6.1epss 0.00

    The virtio PCI driver (drivers/virtio/virtio_pci.c) parses a device's PCI capability list during driver initialization. In virtio_pci_read_cap() the device-supplied capability length byte cap_len (read from PCI config space via pcie_conf_read()) was only checked with…

  • CVE-2026-79785MedAug 25, 2026
    risk 0.31cvss 5.9epss 0.00

    X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto_labeling/model.py built a context with ssl._create_unverified_context() and passed it to urllib.request.urlopen, so neither the certificate chain nor the…

  • CVE-2026-79784HigAug 25, 2026
    risk 0.57cvss 8.8epss 0.01

    Vocos instantiates a class named by a configuration file without restricting which class may be named. instantiate_class in vocos/pretrained.py takes the class_path value from the configuration, splits it into a module and an attribute, imports the module with __import__,…

  • CVE-2026-79783LowAug 25, 2026
    risk 0.16cvss 3.6epss 0.00

    rclone before 1.74.4 fails to mask special permission bits when applying source-supplied mode metadata in the local backend, allowing attackers to set setuid/setgid bits on attacker-controlled files. When copying with metadata preservation from an untrusted remote, attackers can…

  • CVE-2026-79782LowAug 25, 2026
    risk 0.13cvss 3.1epss 0.00

    rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.

  • CVE-2026-79781MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.00

    rclone serve s3 before 1.74.4 contains a path traversal vulnerability that allows attackers to read and overwrite root-level files by using dot-dot segments in S3 object keys. Attackers can send requests with object keys like ../root-secret.txt to escape the bucket namespace and…

  • CVE-2026-79780MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, allowing credentials to be preserved across scheme or host changes. Attackers observing network traffic from a trusted endpoint can capture reusable IBM IAM…

  • CVE-2026-79779MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization and Cookie headers to be replayed over plaintext HTTP after same-host HTTPS-to-HTTP redirects. An on-path attacker observing the plaintext hop can capture and…

  • CVE-2026-79778MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a nil response before checking for transport errors. A malicious or compromised configured endpoint can reset connections during TUS uploads to trigger a panic…

  • CVE-2026-79777LowAug 25, 2026
    risk 0.11cvss 2.7epss 0.00

    rclone before v1.75.0 includes full Go stack traces in RC API error responses when panics occur. Attackers can trigger panics to leak internal file paths, module versions, goroutine states, and memory addresses.

  • CVE-2026-79776MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication rule in the main handler. Attackers can access the /debug/pprof/cmdline endpoint unauthenticated to retrieve the full process argv including backend credentials.

  • CVE-2026-79775MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain multiple denial-of-service vulnerabilities in the archive backend's SquashFS parser, which relies on the github.com/diskfs/go-diskfs dependency. The parser fails to validate attacker-controlled superblock and…

  • CVE-2026-79774HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.01

    Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding…

  • CVE-2026-79773MedAug 25, 2026
    risk 0.25cvss 4.9epss 0.00

    Winter CMS before 1.2.13 contains a local file inclusion vulnerability in the JavascriptImporter filter that allows authenticated users with cms.manage_assets permission to disclose arbitrary server-readable files by placing =include or =require directives in theme JavaScript…

  • CVE-2026-79772MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning an empty string on failure instead of raising an exception. Attackers can exploit this to bypass signature validation in downstream SAML libraries by…

  • CVE-2026-79771MedAug 25, 2026
    risk 0.27cvss 5.3epss 0.00

    Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strings containing null bytes. Attackers can exploit this by passing attacker-controlled input with null bytes to transform parameters, causing heap allocations to…

  • CVE-2026-79770HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.00

    Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and…

  • CVE-2026-79769MedAug 25, 2026
    risk 0.29cvss 5.5epss 0.00

    Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bounds) memory read in the protected internal Node#initialize_copy_with_args helper behind Node#dup and #clone, which unwrapped its source argument as an xmlNode without a type check. If application code calls…

  • CVE-2026-79676MedAug 25, 2026
    risk 0.31cvss 5.9epss 0.00

    NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths using built-in open() instead of nltk.pathsec.open(), allowing symlinks to escape trusted roots. Attackers who stage symlinked corpus files under a trusted data…

  • CVE-2026-79675CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like -agentpath, -javaagent, or @argfile to Stanford wrapper classes to…

  • CVE-2026-79674HigAug 25, 2026
    risk 0.46cvss 8.2epss 0.00

    NLTK versions before 3.10.3 contain a path sandbox bypass vulnerability in corpus-reader constructors that allows attackers to read files outside the intended data root. Attackers can supply arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCorpusReader…

  • CVE-2026-70550MedAug 25, 2026
    risk 0.42cvss 6.5epss 0.00

    An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under specific conditions, to read package metadata from repositories they are not authorized to read. The issue affects confidentiality and has been addressed in fixed…

  • CVE-2026-70548LowAug 25, 2026
    risk 0.23cvss 3.5epss 0.00

    Under specific circumstances, low-level user can run request to remote CocoaPods repos via JFrog Artifactory External Dependency.

  • CVE-2026-55640CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults…

  • CVE-2026-55582HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.00

    mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShellConstructs and applies no per-executable…

  • CVE-2026-55581HigAug 25, 2026
    risk 0.48cvss 8.4epss 0.00

    mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and checkBlockedPatternsAndCommands does not…

  • CVE-2026-55580HigAug 25, 2026
    risk 0.49cvss —epss 0.00

    mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-binary deployment without a security policy.…

  • CVE-2026-55546CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to…

  • CVE-2026-55539HigAug 25, 2026
    risk 0.49cvss 8.6epss 0.01

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs without authentication. Any reachable caller can submit jobs, read results, cancel runs, or delete jobs using operator credentials. The fix adds…

  • CVE-2026-55536CriAug 25, 2026
    risk 0.52cvss 9.1epss 0.01

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, Browser Server _handle_connection() checks Chrome extension origins with re.match() and the unanchored expression chrome-extension://[a-z0-9]{32}. Extra trailing characters pass before websocket.accept(),…

  • CVE-2026-55533HigAug 25, 2026
    risk 0.46cvss 8.2epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST…

  • CVE-2026-55532HigAug 25, 2026
    risk 0.42cvss 7.6epss 0.00

    PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type:…

  • CVE-2025-71407Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2025-71406Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2025-71346Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2024-58378Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2024-58377MedAug 25, 2026
    risk 0.29cvss 5.5epss 0.00

    Nokogiri versions before 1.16.5 bundle libxml2 2.12.6, which is affected by CVE-2024-34459 in libxml2's xmllint tool. Nokogiri 1.16.5 upgrades the bundled libxml2 to 2.12.7 to address this. Per the maintainers, there is no impact to Nokogiri users because Nokogiri does not…

  • CVE-2023-54354Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2022-51000Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2022-50999Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2022-50998Aug 25, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2021-47996Aug 25, 2026
    risk 0.00cvss —epss 0.01

    Rejected reason: This CVE ID has been rejected as a duplicate.

  • CVE-2026-79717MedAug 25, 2026
    risk 0.42cvss 6.4epss 0.00

    A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including internal networks, loopback, or…

  • CVE-2026-70551HigAug 25, 2026
    risk 0.55cvss 8.5epss 0.00

    A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data URL.

  • CVE-2026-69104HigAug 25, 2026
    risk 0.49cvss 7.6epss 0.00

    An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.

  • CVE-2026-55624MedAug 25, 2026
    risk 0.27cvss —epss 0.00

    MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8, players can take items like barrier blocks or duplicate items from the GUI. Commit 88c920b05042929db334ba06d57f052b42d6b3f8 fixes the issue.