VYPR

CVEs

378,628 total · page 464 of 7,573

  • CVE-2026-66065HigAug 3, 2026
    risk 0.48cvss —epss 0.00

    Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Several execution-routing keys of the same RCE class were omitted, so a malicious…

  • CVE-2026-52521HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.00

    A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.

  • CVE-2026-52520MedAug 3, 2026
    risk 0.35cvss 5.4epss 0.00

    Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the…

  • CVE-2026-52102CriAug 3, 2026
    risk 0.57cvss 9.8epss 0.02

    An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.

  • CVE-2026-51775CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component

  • CVE-2026-51190CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.01

    The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in ".git" bypasses the only input check, allowing OS command injection when a user runs "s init" with an attacker-controlled…

  • CVE-2026-49132MedAug 3, 2026
    risk 0.28cvss 5.4epss 0.00

    OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScript by embedding payloads in the certificate description field via the trust certificate API. The unsanitized description value is…

  • CVE-2026-49131MedAug 3, 2026
    risk 0.28cvss 5.4epss 0.00

    OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privileges to inject arbitrary HTML or JavaScript by embedding payloads in the firewall rule description field via the filter API…

  • CVE-2026-48113HigAug 3, 2026
    risk 0.48cvss —epss 0.00

    Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL restrictions and tunnel traffic to arbitrary destinations reachable from the server. The ACL is enforced only during the initial…

  • CVE-2026-48063CriAug 3, 2026
    risk 0.53cvss —epss 0.00

    Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a malicious payload via the placeholderResendMessage and trigger a fake messages.upsert event with a fake message key and payload. This…

  • CVE-2026-48061MedAug 3, 2026
    risk 0.31cvss 5.9epss 0.00

    Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validation by omitting the Host header and supplying an X-Forwarded-Host header set to a whitelisted domain. The AllowedHostsMiddleware…

  • CVE-2026-41447HigAug 3, 2026
    risk 0.51cvss 7.8epss 0.00

    FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafted openssl.cnf file in the unvalidated C:\Program Files (x86)\Common Files\SSL\ directory path. Attackers can write a malicious…

  • CVE-2026-18738MedAug 3, 2026
    risk 0.24cvss 4.7epss 0.00

    Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote attackers to plant spreadsheet formulas into exported visit data by supplying malicious values in User-Agent, Referer, or request path headers beginning with…

  • CVE-2026-18737MedAug 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an unvalidated direction value in the orderBy query parameter of the tag statistics endpoint. Attackers can craft a malicious direction…

  • CVE-2026-18736MedAug 3, 2026
    risk 0.33cvss 5.0epss 0.00

    Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET requests by supplying a crafted long URL during short URL creation with title auto-resolution enabled. Attackers can submit URLs…

  • CVE-2026-18733HigAug 3, 2026
    risk 0.50cvss 8.8epss 0.00

    A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands on the agent's host via a crafted prompt that sets the non_interactive parameter to true, bypassing the human…

  • CVE-2026-18648MedAug 3, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFileFromUri of the component react-native-receive-sharing-intent. The manipulation of the argument _display_name results in path…

  • CVE-2026-18647HigAug 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidTLD of the file /backend/functions/src/cloud-functions/crawler.ts of the component Crawler/Puppeteer. The manipulation leads to…

  • CVE-2026-18646MedAug 3, 2026
    risk 0.34cvss 5.3epss 0.01

    A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component Author Name Handler. Executing a manipulation of the argument Name can lead to path traversal. The attack may be launched remotely.…

  • CVE-2026-18645MedAug 3, 2026
    risk 0.35cvss 5.4epss 0.00

    A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the component Admin Content Endpoint. Performing a manipulation of the argument oldfile results in path traversal. The attack may be…

  • CVE-2026-69198MedAug 3, 2026
    risk 0.38cvss —epss 0.00

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classification method is built on isInSubnet, which short-circuits to false whenever the address's own subnet mask is shorter than the…

  • CVE-2026-69192HigAug 3, 2026
    risk 0.43cvss —epss 0.01

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as…

  • CVE-2026-69185HigAug 3, 2026
    risk 0.42cvss 7.5epss 0.01

    Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO packet can make the server wait for a large number of binary attachments and buffer them, which can be exploited to make the server…

  • CVE-2026-68981HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.01

    Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforced a configurable maximum request size on the compressed payload rather than the decompressed output, allowing a malicious client…

  • CVE-2026-68980CriAug 3, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framework authorizes asset deletion against the owning Parameter Context using the supplied Parameter Context Identifier and Asset…

  • CVE-2026-68979CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components referencing Parameter values. Updating a Parameter Context can change parameter values that affect referencing components, but…

  • CVE-2026-67599HigAug 3, 2026
    risk 0.00cvss 7.2epss 0.02

    ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary commands by submitting unsanitized input through the filter parameter, which is interpolated directly into a shell command in File.php.…

  • CVE-2026-67598HigAug 3, 2026
    risk 0.48cvss 7.4epss 0.00

    Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as…

  • CVE-2026-66296MedAug 3, 2026
    risk 0.33cvss 6.1epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default HTML error handler. Oaskit.ErrorHandler.Default.format_reason/4 and Oaskit.ErrorHandler.Default.reason_to_html/1 in…

  • CVE-2026-62354MedAug 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit proposed Parameter values. The proposed values override current configuration, enabling users with read access to invoke predefined…

  • CVE-2026-58139MedAug 3, 2026
    risk 0.35cvss 6.5epss 0.00

    The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false,…

  • CVE-2026-48031CriAug 3, 2026
    risk 0.52cvss 9.1epss 0.00

    go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secret is hardcoded to the known string "random", letting any attacker who reads the public repository forge tokens for arbitrary…

  • CVE-2026-47211HigAug 3, 2026
    risk 0.48cvss —epss 0.00

    Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versions prior to 0.39.0, if a user clones a malicious repository and runs Ouroboros commands within that directory, it can lead to…

  • CVE-2026-18655MedAug 3, 2026
    risk 0.00cvss 6.5epss 0.00

    Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a remote unauthenticated actor (via prompt injection) to obtain Amazon MQ for RabbitMQ broker credentials or…

  • CVE-2026-18654MedAug 3, 2026
    risk 0.00cvss 6.8epss 0.00

    Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow man-in-the-middle attackers to intercept SSHsessions and file transfers via network positioning between the client and the EMR…

  • CVE-2026-18644MedAug 3, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the component Delete Username Endpoint. Such manipulation of the argument File leads to path traversal. The attack can be launched…

  • CVE-2026-18641HigAug 3, 2026
    risk 0.48cvss 7.3epss 0.02

    A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation…

  • CVE-2026-18632MedAug 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code_executor/jinja2/jinja2_transformer.py of the component Jinja2 Handler. The manipulation results in improper neutralization of…

  • CVE-2026-18631MedAug 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/src/main/java/com/jeequan/jeepay/mgr/ctrl/sysuser/SysLogController.java of the component PreAuthorize Handler. The manipulation…

  • CVE-2026-59913HigAug 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2026-59912HigAug 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code…

  • CVE-2026-38447CriAug 3, 2026
    risk 0.57cvss 9.8epss 0.00

    osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and…

  • CVE-2026-38446MedAug 3, 2026
    risk 0.33cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without…

  • CVE-2026-38444MedAug 3, 2026
    risk 0.33cvss 6.1epss 0.00

    osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a…

  • CVE-2026-18616CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the component wg-server.so Native Plugin. The manipulation of the argument public_key leads to command injection. Remote exploitation…

  • CVE-2026-18615CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-bin/glc of the component wg-server.so Native Plugin. Executing a manipulation of the argument private_key can lead to command…

  • CVE-2026-18614CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component s2s.so Native Plugin. Performing a manipulation of the argument port results in command injection. The attack may be initiated…

  • CVE-2025-15631MedAug 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide sufficient protection. An attacker who obtains access to stored credential data may be able to recover valid credentials…

  • CVE-2025-15630MedAug 3, 2026
    risk 0.38cvss 5.9epss 0.00

    A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a legitimate device completes registration, resulting in provisioning information being delivered to an attacker. …

  • CVE-2025-15629HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and managed devices may be predictable due to insufficient entropy in session key generation. An attacker who successfully…