VYPR

CVEs

384,311 total · page 409 of 7,687

  • CVE-2025-52182HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    The Library Corporation LS2 Admin v5.7 to v5.8.0 was discovered to contain an information disclosure vulnerability.

  • CVE-2026-77641MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.00

    tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() was ignored, so a send failure (which calls circuit_mark_for_close() and removes the leg via cfx_del_leg()) would go…

  • CVE-2026-77640LowAug 20, 2026
    risk 0.24cvss 3.7epss 0.00

    tor before 0.4.9.9 was prone to an infinite loop when decompressing a truncated zlib/gzip stream with done=1. A truncated stream never reaches Z_STREAM_END, causing zlib to return Z_BUF_ERROR with no input remaining, which buf_add_compress() mistook for a full output buffer…

  • CVE-2026-77639MedAug 20, 2026
    risk 0.34cvss 5.3epss 0.00

    Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-stream detection threshold, to avoid the compression bomb check entirely. This is TROVE-2026-022.

  • CVE-2026-77638HigAug 20, 2026
    risk 0.58cvss 8.9epss 0.00

    Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the onion service that the client was trying to reach.

  • CVE-2026-77587MedAug 20, 2026
    risk 0.38cvss 5.9epss 0.00

    Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.

  • CVE-2026-77584HigAug 20, 2026
    risk 0.46cvss 7.0epss 0.00

    Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a RELAY_COMMAND_BEGIN before the CONFLUX_LINK on the same circuit, attaching an exit stream that would later end up orphan leaving a…

  • CVE-2026-77506MedAug 20, 2026
    risk 0.31cvss 4.8epss 0.00

    Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

  • CVE-2026-76023HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.00

    Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76022HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.00

    Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76021HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76020HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76019HigAug 20, 2026
    risk 0.53cvss 8.1epss 0.00

    Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-76018HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.00

    Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)

  • CVE-2026-76017HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.00

    Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Critical)

  • CVE-2026-75484MedAug 20, 2026
    risk 0.38cvss —epss 0.01

    Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR, LF, or NUL characters into application-visible request headers via HTTP/2. Bandit.HTTP2.Stream.read_headers/1 validates…

  • CVE-2026-74836HigAug 20, 2026
    risk 0.50cvss —epss 0.01

    Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded number of HTTP/2 stream processes indefinitely via connection-level flow control. When a stream's response body outruns the HTTP/2…

  • CVE-2026-73137HigAug 20, 2026
    risk 0.50cvss 7.7epss 0.01

    A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create permissions can exploit this vulnerability by manipulating the `secretRef.Namespace` field. This allows the `GetSecret()` function…

  • CVE-2026-73040HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0-9_-]+$, is reached from save() alone, while the path getter returns path.join(this.server.stacksDir, this.name) and…

  • CVE-2026-71485CriAug 20, 2026
    risk 0.52cvss 9.1epss 0.01

    Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.headers map through OnClientConnecting in internal/client/handler.go, ConnectEvent.Headers, and SetEmulatedHeadersToContext. The…

  • CVE-2026-70654MedAug 20, 2026
    risk 0.31cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources and use them to process untrusted uncompressed PPM images can trigger a max/min error in vips_source_read_to_memory in…

  • CVE-2026-70653MedAug 20, 2026
    risk 0.24cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, the old-style Radiance RLE decoder in libvips/foreign/radiance.c can process a repeat marker at the beginning of a scanline in scanline_read_old and read q[-1] before any prior pixel…

  • CVE-2026-70652LowAug 20, 2026
    risk 0.06cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built with libultrahdr support can incorrectly size an output buffer in libvips/foreign/uhdrsave.c within vips_foreign_save_uhdr_set_raw_hdr when a pipeline enlarges an incoming…

  • CVE-2026-70651MedAug 20, 2026
    risk 0.38cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick support can overflow the combined frame height while loading a crafted multi-page TIFF through VipsForeignLoadMagick. The…

  • CVE-2026-69242HigAug 20, 2026
    risk 0.48cvss —epss 0.00

    libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoadTiff can evade scanline validation in libvips/iofuncs/image.c and cause an integer overflow in vips_image_sanity. The resulting…

  • CVE-2026-68921MedAug 20, 2026
    risk 0.24cvss 4.7epss 0.00

    DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate option into an SVG transform attribute without XML escaping in addRotate in packages/@dicebear/core/src/utils/svg.ts, while @dicebear/initials similarly emits…

  • CVE-2026-67567CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates…

  • CVE-2026-67446MedAug 20, 2026
    risk 0.27cvss 5.3epss 0.01

    Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster before checking decoded dimensions, pixel count, or memory use in the GET /api/v1/message/{id}/part/{partID}/thumb endpoint. The…

  • CVE-2026-67445MedAug 20, 2026
    risk 0.27cvss 5.3epss 0.01

    Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLine() using bufio.Reader.ReadString before session.parseLine() parses the verb or the RFC 5321 512-octet command-line limit is…

  • CVE-2026-53804HigAug 20, 2026
    risk 0.47cvss 7.2epss 0.02

    OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options.…

  • CVE-2026-52021HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30) allows a remote attacker to obtain sensitive information via the src/middleware.ts, and src/app/api/mobile/search/route.ts components.

  • CVE-2026-43798CriAug 20, 2026
    risk 0.64cvss 9.8epss 0.00

    A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controlled length and content against any application built on swift-nio-ssh. This vulnerability is addressed in swift-nio-ssh version 0.14.1.

  • CVE-2026-19755MedAug 20, 2026
    risk 0.45cvss —epss 0.00

    NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath values.This issue affects NoSleep: 1.5.1.

  • CVE-2026-18420HigAug 20, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arbitrary code on the server via a crafted JSON payload to the metrics visualization API endpoint. This issue is a form of prototype…

  • CVE-2026-77151LowAug 20, 2026
    risk 0.17cvss 3.7epss 0.00

    A security flaw has been discovered in lin-snow Ech0 up to 5.4.1. Affected by this issue is the function MD5Encrypt of the file internal/util/crypto/crypto.go. Performing a manipulation results in risky cryptographic algorithm. Remote exploitation of the attack is possible. The…

  • CVE-2026-75910MedAug 20, 2026
    risk 0.42cvss 6.5epss 0.01

    Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's…

  • CVE-2026-72861MedAug 20, 2026
    risk 0.38cvss 5.8epss 0.00

    The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-issue-bot/src/github.js and in node-typescript/github-issue-bot/src/github.ts returns "typeof signature !== 'string' || (await…

  • CVE-2026-63723Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-9033MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.00

    An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, including forcing logout of specific users or clearing all active sessions. Affected users must re-authenticate to regain access.  …

  • CVE-2026-8717Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-77148CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_channel of the component Web Management. The manipulation results in stack-based buffer overflow. The attack can be launched…

  • CVE-2026-75526MedAug 20, 2026
    risk 0.22cvss 4.4epss 0.00

    django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 until 5.0.9, ContentRenderer.render_placeholder in cms/plugin_rendering.py can pass stored, attacker-controlled values to ContentRenderer.render_exception when…

  • CVE-2026-75514MedAug 20, 2026
    risk 0.31cvss 5.9epss 0.01

    BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/core/blacklist/blacklist.lua, src/common/core/greylist/greylist.lua, and src/common/core/antibot/antibot.lua trust PTR suffix…

  • CVE-2026-72854MedAug 20, 2026
    risk 0.34cvss 5.3epss 0.00

    msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an unchecked size_t addition of the requested size and the amount already used. The doubling loop guards its own multiplication…

  • CVE-2026-72852HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked 32-bit int arithmetic. In src-lib/convolutional_layer.cpp, l.nweights is computed as (c / groups) * n * size * size and l.outputs…

  • CVE-2026-6822Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-6260Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-66788LowAug 20, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or annotation on the broker object. This allows the attacker to…

  • CVE-2026-66787MedAug 20, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient validation of advertised IP addresses within EndpointSlice objects. A compromised spoke cluster can exploit this by creating…

  • CVE-2026-66785LowAug 20, 2026
    risk 0.16cvss 2.5epss 0.00

    A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided…