VYPR

CVEs

37,387 total · page 5 of 748

  • CVE-2026-54618CriSep 17, 2026
    risk 0.54cvss 9.4epss 0.00

    Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authorization code without a login, consent, or session check, and /oauth/token can exchange that code for the static VAULT_MCP_TOKEN without authenticating a client.…

  • CVE-2026-54617CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.01

    GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote actor can send a raw HTTP request target without a leading slash to the default LaunchServer file server on port 9274. FileServerHandler.channelRead0 in…

  • CVE-2026-47252CriSep 17, 2026
    risk 0.52cvss 9.0epss 0.00

    Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access to affected macOS virtual tables can execute operating-system commands because the Chrome plugin and equivalent Brave, Edge, and Safari variants interpolate a…

  • CVE-2026-54053CriSep 17, 2026
    risk 0.55cvss 9.6epss 0.01

    Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import implemented in app/Actions/ProcessImportedVault.php accepts archive filenames containing parent-directory traversal segments. An authenticated user can write…

  • CVE-2026-92489CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output() A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless…

  • CVE-2026-90414CriSep 17, 2026
    risk 0.52cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was received isert_recv_done() hands each received PDU to the opcode handlers without ever looking at wc->byte_len, the number of bytes the HCA actually placed in…

  • CVE-2026-90413CriSep 17, 2026
    risk 0.52cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data than was received isert_login_recv_done() records how many bytes the HCA actually placed in the login buffer, but nothing compares that against the length the…

  • CVE-2026-90235CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE xprtsock replaces and restores sk->sk_data_ready and sk->sk_write_space on live sockets with plain stores, and…

  • CVE-2026-90230CriSep 17, 2026
    risk 0.52cvss 9.1epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with the host-supplied transfer length (tl) and hands it to…

  • CVE-2026-90173CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_free_cq() smbdirect_connection_destroy_qp() creates the send and receive completion queues with ib_alloc_cq_any(), which for IB_POLL_WORKQUEUE arms an internal…

  • CVE-2026-90151CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocation failure nfs4_alloc_client() allocates an NFSv4.0 callback identifier before it finishes setting up the client. If any later initialization step fails, the…

  • CVE-2026-90110CriSep 17, 2026
    risk 0.54cvss 9.4epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using SipHash The inetpeer rate limiting system stores peer entries in a Red-Black tree keyed deterministically on the remote IP address. Because tree lookups walk…

  • CVE-2026-90104CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding decode_cb_sequence_args() allocates csa_rclists with kmalloc_objs(), so each referring_call_list starts uninitialized. decode_rc_list() assigns rcl_refcalls…

  • CVE-2026-91039CriSep 17, 2026
    risk 0.52cvss —epss 0.00

    Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one identity-provider connection of a dynamic_oidc strategy to be signed in as a local user established through a different connection. The strategy is meant to…

  • CVE-2026-86863CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.00

    pgAdmin 4's Webserver authentication source is intended to accept an identity asserted by the web server or reverse proxy in front of pgAdmin, delivered through the WSGI/CGI environment. WebserverAuthentication.get_user() read config.WEBSERVER_REMOTE_USER from request.environ…

  • CVE-2026-88952CriSep 17, 2026
    risk 0.52cvss —epss 0.00

    Improper Authentication vulnerability in team-alembic AshAuthentication allows an attacker to be signed in as another user by linking an OAuth2 identity to an account that is not theirs. AshAuthentication.Strategy.OAuth2.UserResolver.resolve/3 matches an existing account using…

  • CVE-2026-79752CriSep 17, 2026
    risk 0.53cvss —epss 0.00

    CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsBuilder::cast, FunctionsBuilder::extract, FunctionsBuilder::datePart, and FunctionsBuilder::dateAdd in src/Database/FunctionsBuilder.php accept user-controlled dataType,…

  • CVE-2026-63472CriSep 17, 2026
    risk 0.52cvss 9.1epss 0.00

    Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and…

  • CVE-2026-92960CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.00

    vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host process DNS resolver globally, redirecting…

  • CVE-2026-92957CriSep 17, 2026
    risk 0.57cvss 9.9epss 0.00

    vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the `node:` prefix during require() resolution, negative wildcard entries are matched by…

  • CVE-2026-92956CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.00

    vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that rejects with a host-realm error object;…

  • CVE-2026-92955CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.01

    vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigger process events to execute code with…

  • CVE-2026-92953CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.00

    vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, and ArrayBuffer.prototype, causing…

  • CVE-2026-92951CriSep 17, 2026
    risk 0.57cvss 9.9epss 0.00

    vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. Attackers can bypass the allowlist by requiring a colliding package name that…

  • CVE-2026-92948CriSep 17, 2026
    risk 0.57cvss 9.9epss 0.00

    vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test'] }). On Node.js 24+, module.builtinModules…

  • CVE-2026-92947CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.00

    vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring ArrayBuffers from small allocations,…

  • CVE-2026-92946CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.01

    vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM instance, and execute arbitrary host OS…

  • CVE-2026-92944CriSep 17, 2026
    risk 0.57cvss 9.8epss 0.01

    vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploit this by creating an async function that…

  • CVE-2026-92941CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.00

    vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and url builtins can use URLSearchParams to…

  • CVE-2026-92940CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.00

    vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method calls such as Agent.prototype.on() are…

  • CVE-2026-92939CriSep 17, 2026
    risk 0.57cvss 9.9epss 0.01

    vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process authority. Sandboxed JavaScript can…

  • CVE-2026-92938CriSep 17, 2026
    risk 0.57cvss 9.9epss 0.00

    vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents property assignment but leaves…

  • CVE-2026-92937CriSep 17, 2026
    risk 0.58cvss 10.0epss 0.01

    vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when deciding whether to rebuild/sanitise a…

  • CVE-2026-92935CriSep 17, 2026
    risk 0.52cvss 9.0epss 0.01

    vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require` value (for example `require: []`)…

  • CVE-2026-92934CriSep 17, 2026
    risk 0.52cvss 9.0epss 0.01

    vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle detection bypass in handleException to…

  • CVE-2026-86533CriSep 17, 2026
    risk 0.52cvss —epss 0.01

    Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and require_token_presence_for_authentication? disabled…

  • CVE-2026-85500CriSep 17, 2026
    risk 0.52cvss —epss 0.01

    Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.check_user/2 decides whether the attribute…

  • CVE-2026-82761CriSep 17, 2026
    risk 0.52cvss —epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as the target subject. A magic link configured with single_use_token?, which is the…

  • CVE-2026-62108CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

  • CVE-2026-62104CriSep 17, 2026
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

  • CVE-2026-62101CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

  • CVE-2026-92860CriSep 17, 2026
    risk 0.52cvss 9.1epss 0.00

    A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper…

  • CVE-2026-90823CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.01

    FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticated remote attacker with access to the affected management interface can submit a crafted…

  • CVE-2026-90822CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.01

    FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management interface can submit crafted input to…

  • CVE-2026-15688CriSep 17, 2026
    risk 0.60cvss —epss 0.00

    Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the…

  • CVE-2026-88795CriSep 17, 2026
    risk 0.59cvss 9.0epss 0.00

    The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, deriving it from data the requester controls and creating it as a side effect of the check that is supposed to validate it, allowing unauthenticated attackers…

  • CVE-2026-86710CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.00

    The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.

  • CVE-2026-86709CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.00

    The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.

  • CVE-2026-86707CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.00

    The Private Feed Key WordPress plugin through 0.1 does not verify that the key used to authenticate a feed request is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.

  • CVE-2026-87796CriSep 17, 2026
    risk 0.64cvss 9.8epss 0.01

    The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.1.9 via the move_file function. This is due to insufficient file type validation during chunked upload handling. This makes it possible for…