VYPR

CVEs

386,555 total · page 607 of 7,732

  • CVE-2026-18991HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The…

  • CVE-2026-18990HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and…

  • CVE-2026-18980MedAug 6, 2026
    risk 0.34cvss 6.3epss 0.02

    A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might…

  • CVE-2026-18976MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be…

  • CVE-2026-18974MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The…

  • CVE-2026-18973HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack…

  • CVE-2026-67873CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the…

  • CVE-2026-67872HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling

  • CVE-2026-67871HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server

  • CVE-2026-67870CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing…

  • CVE-2026-67869HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

  • CVE-2026-67531CriAug 6, 2026
    risk 0.53cvss —epss 0.01

    FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own…

  • CVE-2026-52466CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not…

  • CVE-2026-19028MedAug 6, 2026
    risk 0.44cvss —epss 0.00

    H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 prior to 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows…

  • CVE-2026-19027MedAug 6, 2026
    risk 0.45cvss —epss 0.00

    The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 prior to 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows…

  • CVE-2026-18970HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to…

  • CVE-2026-18969HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to…

  • CVE-2026-18968MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting. The attack may be performed from…

  • CVE-2023-54389Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54388Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54387Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54386Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54385Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54384Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54383Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54382Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54381Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54380Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54379Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54378Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54377Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54376Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54375Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2026-67867HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when processing PublishResponse EventNotificationList data

  • CVE-2026-67866HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMonitoredItemsResponse and SOPC_StaMac_NewDeleteMonitoredItems in the client wrapper DeleteMonitoredItems path

  • CVE-2026-67863HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish continues to use the current UA_Notification after a callback invokes UA_Server_deleteMonitoredItem for the current local…

  • CVE-2026-19026MedAug 5, 2026
    risk 0.44cvss —epss 0.00

    H5Z__filter_nbit in H5Znbit.c in HDF5 prior to 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or that cd_nelmts is at least 5, the fixed size of the filter's header. This allows attackers to cause a denial of service via a…

  • CVE-2026-19025MedAug 5, 2026
    risk 0.44cvss —epss 0.00

    H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows…

  • CVE-2026-19024HigAug 5, 2026
    risk 0.53cvss —epss 0.00

    NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's…

  • CVE-2026-19023MedAug 5, 2026
    risk 0.44cvss —epss 0.00

    Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride…

  • CVE-2026-71321HigAug 5, 2026
    risk 0.42cvss 7.5epss 0.01

    Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_island/...` decodes and hashes attacker-controlled JSON body input with destr and ohash before validating the URL-resident hash. An…

  • CVE-2026-71320HigAug 5, 2026
    risk 0.46cvss 8.1epss 0.01

    Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nuxt_island/ props into a dynamic component when `vue.runtimeCompiler: true` is enabled, causing template execution in the Nitro…

  • CVE-2026-71319CriAug 5, 2026
    risk 0.55cvss 9.6epss 0.01

    Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client…

  • CVE-2026-71318MedAug 5, 2026
    risk 0.31cvss 4.8epss 0.00

    Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply a top-level `as` prop to the /__nuxt_island/ endpoint and drive dynamic component resolution through , resolveDynamicComponent, or h(). This…

  • CVE-2026-71316HigAug 5, 2026
    risk 0.42cvss 7.5epss 0.01

    Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for //_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR…

  • CVE-2026-67865HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service

  • CVE-2026-67864HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic component

  • CVE-2025-63823CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.01

    My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.

  • CVE-2025-63822HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to…

  • CVE-2026-71315HigAug 5, 2026
    risk 0.46cvss 8.2epss 0.00

    Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-folded lookups when router.options.sensitive is false and drop appMiddleware authorization gates. This is caused by an incomplete…