VYPR

CVEs

386,593 total · page 638 of 7,732

  • CVE-2026-54715HigJul 30, 2026
    risk 0.39cvss —epss 0.00

    GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, parse_browser assumes the matched browser token begins with Opera and moves a trailing version substring to match plus five,…

  • CVE-2026-52539CriJul 30, 2026
    risk 0.00cvss 9.1epss 0.01

    Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this…

  • CVE-2026-35847CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

  • CVE-2025-69947CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

  • CVE-2025-69941CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

  • CVE-2025-69938CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

  • CVE-2025-69937CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

  • CVE-2025-69936CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

  • CVE-2025-69935CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

  • CVE-2025-69934CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

  • CVE-2025-69933CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

  • CVE-2025-69931CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

  • CVE-2025-69930CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

  • CVE-2025-65342MedJul 30, 2026
    risk 0.40cvss 6.1epss 0.00

    code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

  • CVE-2025-65341MedJul 30, 2026
    risk 0.40cvss 6.1epss 0.00

    Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.

  • CVE-2025-65336CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.00

    Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

  • CVE-2026-67594CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes by exploiting the unattached CipiAuth middleware, which is registered but never applied to any route in the API routing…

  • CVE-2026-67550MedJul 30, 2026
    risk 0.30cvss 5.7epss 0.00

    re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced…

  • CVE-2026-67530MedJul 30, 2026
    risk 0.35cvss 6.4epss 0.00

    WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its validation in src/lib/automations/validate.ts allowed an authenticated user with automation privileges to submit an arbitrary…

  • CVE-2026-67529MedJul 30, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/time_entries and GET /api/v3/cost_entries rendered _links.workPackage.title and _links.workPackage.href through associated_resource in modules/costs/lib/api/v3/time_entries/time_entry_…

  • CVE-2026-67528MedJul 30, 2026
    risk 0.21cvss 4.3epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.6.0, GET /api/v3/custom_options/:id resolved CustomOption records by global numeric id and allowed UserCustomField and GroupCustomField options without checking visible(current_user), so authenticated…

  • CVE-2026-67527HigJul 30, 2026
    risk 0.42cvss 7.6epss 0.00

    OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and allowed authenticated users with edit_work_packages but without manage_file_links to resolve Storages::FileLink records by raw id,…

  • CVE-2026-67208CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.04

    Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by connecting to the exposed H2 database web console using default shipped credentials. Attackers can access the unprotected…

  • CVE-2026-67207HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.01

    Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users to access restricted backup functionality due to a PHP operator precedence flaw in the permission check expression. Attackers can…

  • CVE-2026-67206HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.02

    Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitrary PHP files by exploiting missing file extension validation in the create_file() and save() functions. Attackers with the…

  • CVE-2026-66756CriJul 30, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users are recommended to upgrade to version 4.0.0-beta-1, which fixes the issue.

  • CVE-2026-66755HigJul 30, 2026
    risk 0.49cvss 7.5epss 0.01

    Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker who can place files in a directory that the application subsequently parses to read arbitrary files accessible to the Tika…

  • CVE-2026-65835MedJul 30, 2026
    risk 0.36cvss 6.6epss 0.00

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not…

  • CVE-2026-65834MedJul 30, 2026
    risk 0.37cvss 6.8epss 0.00

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by the configuration admission webhook,…

  • CVE-2026-12946CriJul 30, 2026
    risk 0.00cvss 9.9epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

  • CVE-2026-11536HigJul 30, 2026
    risk 0.55cvss 8.5epss 0.01

    IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

  • CVE-2026-10569MedJul 30, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 is susceptible to an Exposure of Sensitive Information Vulnerability in plugin output logs. This…

  • CVE-2025-51684MedJul 30, 2026
    risk 0.40cvss 6.1epss 0.00

    CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml,…

  • CVE-2026-66416HigJul 30, 2026
    risk 0.00cvss 8.8epss 0.00

    Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in…

  • CVE-2026-66415HigJul 30, 2026
    risk 0.00cvss 8.5epss 0.00

    Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path…

  • CVE-2026-66066CriJul 30, 2026
    risk 0.60cvss —epss 0.28

    Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not disable libvips operations marked unsafe for untrusted content, allowing a crafted upload to invoke such an operation. Consuming…

  • CVE-2026-64870MedJul 30, 2026
    risk 0.27cvss —epss 0.00

    MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied download_url and download_callback_url values to requests.get without equivalent trusted-host and redirect validation, allowing an…

  • CVE-2026-61536HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.01

    Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves their import_path field through importlib.import_module(...) + getattr(...) to…

  • CVE-2026-59881MedJul 30, 2026
    risk 0.38cvss —epss 0.01

    AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated, allowing a malicious server to cause…

  • CVE-2026-51272Jul 30, 2026
    risk 0.00cvss —epss —

    Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-48499CriJul 30, 2026
    risk 0.53cvss —epss 0.00

    Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an authenticated flow author reach read-write cached flow and code files belonging to other tenants on the same worker, exposing…

  • CVE-2026-18245CriJul 30, 2026
    risk 0.52cvss 9.0epss 0.01

    Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrary code in end-user browsers, developer machines, CI/CD environments, and server-side rendering contexts via crafted Studio…

  • CVE-2026-18140HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via…

  • CVE-2026-15978HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.01

    SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two endpoints that allow a remote attacker to trigger distributed weight broadcasting using NCCL and then triggering data transfer, attackers can exfiltrate all model…

  • CVE-2026-15977HigJul 30, 2026
    risk 0.00cvss 7.5epss 0.00

    SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyfile information when only the --admin-api-key is configured.

  • CVE-2026-15976CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fallback enables pickle deserialization of .bin files.

  • CVE-2026-15974MedJul 30, 2026
    risk 0.00cvss 6.5epss 0.00

    SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitized image_url, allowing access to internal metadata, secrets, and services.

  • CVE-2026-15971CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.

  • CVE-2026-15969CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.01

    SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle payloads.

  • CVE-2026-14227MedJul 30, 2026
    risk 0.32cvss 4.9epss 0.00

    An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivity timeouts or user‑group changes. As a…