VYPR

CVEs

378,628 total · page 491 of 7,573

  • CVE-2026-17663HigJul 30, 2026
    risk 0.54cvss 8.3epss 0.00

    Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17662MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17661HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.01

    Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17660HigJul 30, 2026
    risk 0.54cvss 8.3epss 0.00

    Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17659MedJul 30, 2026
    risk 0.27cvss 4.2epss 0.00

    Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17658HigJul 30, 2026
    risk 0.57cvss 8.8epss 0.01

    Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17657HigJul 30, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-17656CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.01

    Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-17655CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.01

    Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-17654HigJul 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)

  • CVE-2026-17653HigJul 30, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-17652CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.01

    Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-17651CriJul 30, 2026
    risk 0.62cvss 9.6epss 0.01

    Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-17650HigJul 30, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-64685MedJul 30, 2026
    risk 0.27cvss 5.3epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been…

  • CVE-2026-62946MedJul 30, 2026
    risk 0.26cvss 5.1epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This…

  • CVE-2026-62363MedJul 30, 2026
    risk 0.26cvss 5.0epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

  • CVE-2026-62343MedJul 30, 2026
    risk 0.24cvss 4.7epss 0.00

    ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied…

  • CVE-2026-16339Jul 29, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-67595HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.01

    VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template…

  • CVE-2026-18060Jul 29, 2026
    risk 0.00cvss —epss —

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-15157MedJul 29, 2026
    risk 0.20cvss 4.2epss 0.00

    undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a…

  • CVE-2026-14643MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.00

    undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field…

  • CVE-2025-69949HigJul 29, 2026
    risk 0.00cvss 7.3epss 0.00

    kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.

  • CVE-2025-69945HigJul 29, 2026
    risk 0.00cvss 7.3epss 0.00

    kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.

  • CVE-2025-69944HigJul 29, 2026
    risk 0.00cvss 7.3epss 0.00

    kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.

  • CVE-2025-69943CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.

  • CVE-2025-69942CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.

  • CVE-2025-67408HigJul 29, 2026
    risk 0.00cvss 7.3epss 0.00

    Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.

  • CVE-2025-67407HigJul 29, 2026
    risk 0.00cvss 7.3epss 0.00

    Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.

  • CVE-2025-67406HigJul 29, 2026
    risk 0.00cvss 7.3epss 0.00

    https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the…

  • CVE-2025-67405HigJul 29, 2026
    risk 0.00cvss 7.3epss 0.00

    Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.

  • CVE-2025-67404CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.

  • CVE-2025-67403CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

  • CVE-2026-67439MedJul 29, 2026
    risk 0.21cvss 4.3epss 0.00

    OliveTin gives safe and simple access to predefined shell commands from a web interface. Prior to 3000.17.0, the service/internal/api/api.go StartActionAndWait and StartActionByGetAndWait endpoints return full LogEntry output after execution without enforcing the logs…

  • CVE-2026-67438MedJul 29, 2026
    risk 0.36cvss 6.6epss 0.01

    OliveTin gives access to predefined shell commands from a web interface. From 3000.2.0 until 3000.17.0, the service/internal/executor/arguments.go checkShellArgumentSafety function does not treat regex: custom argument types as unsafe for Shell mode actions, allowing values that…

  • CVE-2026-67437HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without…

  • CVE-2026-65975MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.88.0 up to but not including 1.107.1 and 2.0.0b1 up to but not including 2.5.0, the UI adapters (AG-UI via Agent.to_ag_ui()/AGUIAdapter, and Vercel AI via…

  • CVE-2026-54249MedJul 29, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.65.0 through 1.105.0, and 2.0.0b1 through 2.0.0b5, a client that submits message history to a Pydantic AI UI adapter (such as the Vercel AI adapter) can reference arbitrary files in…

  • CVE-2026-50782HigJul 29, 2026
    risk 0.00cvss 7.5epss 0.00

    Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an…

  • CVE-2026-46678MedJul 29, 2026
    risk 0.37cvss 6.8epss 0.00

    Pydantic AI is a Python agent framework for building Generative AI applications. In versions 1.56.0 through 1.98.0, when an application opts a URL into force_download='allow-local' (disabling the default block on private/internal IPs), the cloud-metadata blocklist could be…

  • CVE-2026-16728MedJul 29, 2026
    risk 0.24cvss 4.8epss 0.00

    undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a…

  • CVE-2026-13309MedJul 29, 2026
    risk 0.00cvss 6.8epss 0.00

    Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is…

  • CVE-2026-13308HigJul 29, 2026
    risk 0.00cvss 8.1epss 0.01

    Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to…

  • CVE-2026-13307MedJul 29, 2026
    risk 0.00cvss 6.8epss 0.00

    Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not…

  • CVE-2026-13306MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authentication on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this…

  • CVE-2026-13305MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home…

  • CVE-2025-65340CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.00

    kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

  • CVE-2025-65337MedJul 29, 2026
    risk 0.00cvss 6.1epss 0.00

    Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.

  • CVE-2026-6336MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing…