VYPR

CVEs

378,628 total · page 459 of 7,573

  • CVE-2026-16792MedAug 4, 2026
    risk 0.40cvss 6.1epss 0.00

    An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive communications by performing a machine-in-the-middle attack against HTTPS…

  • CVE-2026-16791LowAug 4, 2026
    risk 0.25cvss 3.9epss 0.00

    A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local files with program-generated data when OneCLI is executed with elevated…

  • CVE-2026-70474HigAug 4, 2026
    risk 0.53cvss 8.1epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The authorize, callback, and refresh handlers query…

  • CVE-2026-70473HigAug 4, 2026
    risk 0.48cvss 8.5epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requesting user, tenant, or workspace. The response…

  • CVE-2026-70472HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without checking whether that credential belongs…

  • CVE-2026-70471MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protected Variables API. Variables for the active…

  • CVE-2026-69704MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. Attackers can inject malicious SQL syntax via the vulnerable GET parameter to…

  • CVE-2026-69703CriAug 4, 2026
    risk 0.00cvss 9.8epss 0.00

    Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw HTTP requests that ignore redirects. Attackers can invoke…

  • CVE-2026-69702MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payload with an inflated frame_content_size field in the frame header. Attackers can…

  • CVE-2026-68743MedAug 4, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket,…

  • CVE-2026-66300MedAug 4, 2026
    risk 0.26cvss 5.0epss 0.00

    SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target user navigating to a crafted, malicious link. Fixed in 10.12.2 and 10.9.3.

  • CVE-2026-49435CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

  • CVE-2026-47781HigAug 4, 2026
    risk 0.48cvss —epss 0.00

    PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during initialization, allowing an attacker-controlled file in an untrusted repository checkout to execute…

  • CVE-2026-47764HigAug 4, 2026
    risk 0.48cvss —epss 0.00

    pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDestination.write_to_fs() in src/pdm/installers/installers.py overrides the base class to add…

  • CVE-2026-13229HigAug 4, 2026
    risk 0.46cvss —epss 0.00

    Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.

  • CVE-2026-0163CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2017-20242CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.

  • CVE-2017-20241CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code.

  • CVE-2026-70470CriAug 4, 2026
    risk 0.57cvss 9.8epss 0.01

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/pythonCodeValidator.ts can be bypassed with Unicode homoglyph identifiers, allowing arbitrary Python…

  • CVE-2026-69264CriAug 4, 2026
    risk 0.57cvss 9.8epss 0.01

    Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to globalThis, which on Node.js exposes eval…

  • CVE-2026-47763MedAug 4, 2026
    risk 0.37cvss —epss 0.00

    pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration files without symlink protection. If a malicious repository places those files as symlinks, local PDM…

  • CVE-2026-47623HigAug 4, 2026
    risk 0.53cvss 8.2epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2026-47622MedAug 4, 2026
    risk 0.34cvss 5.3epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that contain sensitive information. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47621MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2026-47620MedAug 4, 2026
    risk 0.42cvss 6.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager singleton initialization. A successful exploit of this vulnerability might lead to data tampering and denial of service.

  • CVE-2026-47619MedAug 4, 2026
    risk 0.43cvss 6.6epss 0.00

    NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

  • CVE-2026-47618HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the Rust multimodal media fetcher where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47617HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery via DNS rebinding. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47616HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal media fetcher where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47615HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery by supplying a crafted URL in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47614HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47613HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47612HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.01

    NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-47487MedAug 4, 2026
    risk 0.29cvss 4.4epss 0.00

    NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might…

  • CVE-2026-24255HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal embedding cache, where an attacker could cause a hash collision by submitting images that share an identical pixel byte sequence but have different dimensions. A successful exploit of this vulnerability might…

  • CVE-2026-24254CriAug 4, 2026
    risk 0.64cvss 9.8epss 0.01

    NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and…

  • CVE-2026-24253HigAug 4, 2026
    risk 0.53cvss 8.2epss 0.00

    NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service and data tampering.

  • CVE-2026-18830HigAug 4, 2026
    risk 0.53cvss 8.1epss 0.01

    Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer…

  • CVE-2026-18790LowAug 4, 2026
    risk 0.21cvss 3.3epss 0.00

    A weakness has been identified in Systerel S2OPC up to 1.7.3. This affects the function LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse of the file src/ClientServer/frontend/client_wrapper/internal/state_machine.c of the component DeleteMonitoredItemsRequest Handler. This…

  • CVE-2026-18788HigAug 4, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been…

  • CVE-2026-69263CriAug 4, 2026
    risk 0.57cvss 9.8epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/nodes/tools/MCP/core.ts denied only PATH, LD_LIBRARY_PATH, DYLD_LIBRARY_PATH, and…

  • CVE-2026-69262HigAug 4, 2026
    risk 0.46cvss 8.1epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,agentflows:delete'), so possession of either permission was sufficient to reach…

  • CVE-2026-69259HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.01

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/SQLiteRecordManager.ts accepted user-controlled additionalConfig and spread it…

  • CVE-2026-69258CriAug 4, 2026
    risk 0.52cvss 9.1epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in…

  • CVE-2026-69257HigAug 4, 2026
    risk 0.49cvss 8.6epss 0.00

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses such as ::ffff:127.0.0.1 and ::ffff:169.254.169.254 before checking them against…

  • CVE-2026-69256HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.01

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; although a denylist blocked dangerous Python constructs, pandas.read_pickle() could…

  • CVE-2026-69255HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.01

    Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-controlled CSV data with file.split(',').pop() and interpolated it directly into…

  • CVE-2026-64634HigAug 4, 2026
    risk 0.55cvss —epss 0.00

    A vulnerability allowing local privilege escalation to the Reporter service context.

  • CVE-2026-64633CriAug 4, 2026
    risk 0.65cvss —epss 0.00

    A vulnerability allowing remote unauthenticated code execution on the agent host.

  • CVE-2026-64631HigAug 4, 2026
    risk 0.56cvss —epss 0.00

    A vulnerability allowing a low-privileged user to inject SQL and extract database contents.