VYPR

CVEs

384,359 total · page 412 of 7,688

  • CVE-2026-63381MedAug 20, 2026
    risk 0.31cvss —epss 0.00

    Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_reference processes an output buffer whose out_total_len is zero. evbuffer_free_all_chains frees the initial empty chain without…

  • CVE-2026-63380MedAug 20, 2026
    risk 0.30cvss —epss 0.00

    Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters its error path after evhttp_start_ws_ succeeds but bufferevent_enable_locking_ fails. evws_connection_free sees a non-null…

  • CVE-2026-63379MedAug 20, 2026
    risk 0.34cvss —epss 0.01

    Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_trailer and merges them into request headers. The fix introduces evhttp_parse_headers_impl_ and a temporary trailer header list. An…

  • CVE-2026-54625MedAug 20, 2026
    risk 0.24cvss 4.8epss 0.00

    django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in cms/cache/page.py ignores request headers declared by plugins through get_vary_cache_on(). The _page_cache_key function includes the cache prefix, site,…

  • CVE-2026-54623HigAug 20, 2026
    risk 0.39cvss 7.1epss 0.00

    django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint in cms/admin/placeholderadmin.py accepts an attacker-controlled plugin_parent value without rejecting a plugin’s own identifier…

  • CVE-2026-53425HigAug 20, 2026
    risk 0.49cvss —epss 0.00

    Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/samly/sp_handler.ex validates a SAML…

  • CVE-2026-53424CriAug 20, 2026
    risk 0.59cvss —epss 0.01

    Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose…

  • CVE-2026-2334CriAug 20, 2026
    risk 0.61cvss —epss 0.01

    An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "Import via CSV" component due to a lack of server-side validation. This allows the upload of an arbitrary file, which can lead to…

  • CVE-2026-77176HigAug 20, 2026
    risk 0.53cvss 8.1epss 0.00

    A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs…

  • CVE-2026-77025MedAug 20, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-77022CriAug 20, 2026
    risk 0.64cvss 9.9epss 0.01

    A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component SSID Configuration. The manipulation of the argument ssid results in stack-based…

  • CVE-2026-77020HigAug 20, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file password-recovery.php. The manipulation of the argument email leads to sql injection. Remote exploitation of the attack is…

  • CVE-2026-77019HigAug 20, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/forgotpw.php. Executing a manipulation of the argument secode can lead to sql injection. The attack may be launched remotely. The…

  • CVE-2026-72845Aug 20, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-71492MedAug 20, 2026
    risk 0.32cvss —epss 0.00

    Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py interpolates attacker-controlled Prompt.name and Prompt.version values into a Path without canonicalization or…

  • CVE-2026-71428CriAug 20, 2026
    risk 0.53cvss 9.3epss 0.00

    The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. From 0.4.7 until 0.24.0, the url argument of partition, partition_html, and partition_md is fetched without host…

  • CVE-2026-69183HigAug 20, 2026
    risk 0.49cvss 7.5epss 0.00

    Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/rate-limit.ts uses client-controlled cf-connecting-ip and x-forwarded-for headers before the trust-proxy-derived req.ip value. An…

  • CVE-2026-65842HigAug 20, 2026
    risk 0.46cvss 8.2epss 0.01

    Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled HTML through htmlToDocxBlob in a server-side or privileged environment. The converter can make requests to internal network…

  • CVE-2026-64846LowAug 20, 2026
    risk 0.11cvss 2.8epss 0.00

    Nix is a package manager for Linux and other Unix systems. Prior to 2.35.0, a malicious derivation executed with the recursive-nix experimental feature can exploit a time-of-check/time-of-use race involving final symlink handling in the LocalStore restore path. The race can…

  • CVE-2026-63481MedAug 20, 2026
    risk 0.38cvss —epss 0.01

    Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in packages/hurl/src/http/client.rs strips Authorization and Cookie headers and basic-auth credentials when a redirect changes host, but…

  • CVE-2026-61704HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.01

    Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetches the original hostname, allowing an attacker-controlled DNS server to return a public address during validation and a loopback…

  • CVE-2026-61625MedAug 20, 2026
    risk 0.37cvss 6.8epss 0.00

    VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not validate backup part path components before using lib/backup/actions/restore.go and lib/backup/fslocal/fslocal.go to write restored…

  • CVE-2026-55642CriAug 20, 2026
    risk 0.57cvss 9.8epss 0.01

    dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/auth.rs passes every protected request to the handler chain when password_hash is None. A fresh deployment reaches that state when DBX_PASSWORD is unset and no…

  • CVE-2026-55586MedAug 20, 2026
    risk 0.36cvss 6.6epss 0.00

    SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, a crafted CHM file can supply malformed LZX Huffman code lengths to make_decode_table in ext/CHMLib/lzx.c. In the long-code branch, the function writes new internal nodes through next_symbol before validating…

  • CVE-2026-55095MedAug 20, 2026
    risk 0.34cvss —epss 0.00

    OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-admin project member can request the inplace-edit dialog for a raw custom_field_ project attribute. The dialog path resolves the project custom field by its raw…

  • CVE-2026-54770MedAug 20, 2026
    risk 0.33cvss 6.1epss 0.00

    WebOb provides objects for HTTP requests and responses. Prior to 1.8.11, Response._make_location_absolute() in src/webob/response.py checks a Location value for a URI scheme or leading double slash before urllib.parse.urljoin() strips leading C0 control characters and spaces. An…

  • CVE-2026-54616HigAug 20, 2026
    risk 0.39cvss 7.1epss 0.00

    NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 1.0.88.0 until stable version 6.0.1698.0 and preview version 6.5.1742.0, the Lz4Decode function in NanaZip.Core/SevenZip/CPP/7zip/Archive/SquashfsHandler.cpp rejects only a zero return from…

  • CVE-2026-54449HigAug 20, 2026
    risk 0.50cvss 8.8epss 0.01

    LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization boundary. In src/langbot/pkg/provider/tools/loaders/mcp.py, StdioServerParameters…

  • CVE-2026-54136MedAug 20, 2026
    risk 0.26cvss —epss 0.00

    Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{workspace}/scripts/list_search. The route-level…

  • CVE-2026-40345HigAug 20, 2026
    risk 0.46cvss —epss 0.01

    deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs when recursively merging records. When two…

  • CVE-2026-18309HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP APNG File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18308HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18307HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-18306HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP SGI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18305HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18304HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18303HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-18302HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP TIF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit…

  • CVE-2026-18301HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18300HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2026-18299HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. Interaction with this library is required to exploit this vulnerability but attack vectors may…

  • CVE-2026-18298HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GStreamer PNG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2026-18297HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GStreamer OGG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2026-18296HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GStreamer MRF File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2026-18295HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    GStreamer MRF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GStreamer. User interaction is required to exploit this vulnerability in that the target must…

  • CVE-2026-18294HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab Origin Viewer OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability…

  • CVE-2026-18293HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab Origin Viewer OPJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab Origin Viewer. User interaction is required to exploit this vulnerability…

  • CVE-2026-18292HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab OriginPro OGG File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro . User interaction is required to exploit this vulnerability in that…

  • CVE-2026-18291HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab OriginPro OGW File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that…

  • CVE-2026-18290HigAug 20, 2026
    risk 0.51cvss 7.8epss 0.00

    OriginLab OriginPro OGG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OriginLab OriginPro. User interaction is required to exploit this vulnerability in that…