VYPR

CVEs

378,628 total · page 672 of 7,573

  • CVE-2026-41579LowJul 1, 2026
    risk 0.21cvss 3.3epss 0.00

    runc is a CLI tool for spawning and running containers according to the OCI specification. In versions prior to 1.3.6, 1.4.0-rc.1, 1.4.0-rc.12, 1.5.0-rc.1, and 1.5.0-rc.1, when setting up the container rootfs, setupPtmx and setupDevSymlinks call os.Remove and os.Symlink with a…

  • CVE-2026-54903MedJul 1, 2026
    risk 0.41cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corruption when parsing a JSON string longer than 2 GB. An integer overflow in buf_append_string (buf.h:61) converts the string length to…

  • CVE-2026-54902MedJul 1, 2026
    risk 0.41cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerable to Use-After-Free when in SAJ mode. The Oj::Parser does not protect cached object keys (≥ 35 bytes) from garbage collection, and a Ruby callback that…

  • CVE-2026-54901MedJul 1, 2026
    risk 0.41cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Parser in usual mode does not mark array_class and hash_class references during garbage collection, leading to Use-After-Free. If GC runs after the class is…

  • CVE-2026-54900MedJul 1, 2026
    risk 0.41cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in usual mode with create_id enabled, Oj::Parser#parse is vulnerable to heap corruption via a negative-size memcpy. When a JSON object key is exactly 65,535 bytes…

  • CVE-2026-54899MedJul 1, 2026
    risk 0.41cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling symbol_keys on a reused Oj::Parser instance triggers a heap use-after-free. When symbol_keys is toggled from true to false, opt_symbol_keys_set frees the…

  • CVE-2026-54898LowJul 1, 2026
    risk 0.14cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parser#parse is vulnerable to a heap use-after-free when a SAJ/SAJ2 callback mutates the input JSON string during parsing. The C engine holds a raw const byte *…

  • CVE-2026-54897LowJul 1, 2026
    risk 0.14cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (each_value, each_child, each_leaf) were vulnerable to a heap use-after-free. When a Ruby block yielded during iteration calls doc.close or d.close, the…

  • CVE-2026-54896LowJul 1, 2026
    risk 0.14cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in object mode, Oj.dump is vulnerable to a heap buffer overflow when serializing Exception objects with a large :indent value. The serializer allocates a buffer…

  • CVE-2026-54592HigJul 1, 2026
    risk 0.49cvss 7.5epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#each_child, when invoked recursively over a deeply nested JSON document, overflows a fixed-size stack buffer and aborts the process, leading to DoS. In a…

  • CVE-2026-54502MedJul 1, 2026
    risk 0.41cvss —epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-based buffer overflow when a large :indent value is provided by the developer. fill_indent in dump.h calls memset(indent_str, ' ',…

  • CVE-2026-54500MedJul 1, 2026
    risk 0.34cvss 5.3epss 0.00

    Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uninitialized stack memory (and, for long keys, reads out of bounds) when parsing a JSON object whose key is 254 bytes or longer. The…

  • CVE-2026-57995HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to grant arbitrary rights to groups without verifying they hold those rights themselves. A delegated administrator can exploit this by…

  • CVE-2026-56777MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the validator and access the task…

  • CVE-2026-56700CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.03

    Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Cache\Adapter\FileCache, and Session - deserialize untrusted data without restricting allowed classes, enabling PHP object injection…

  • CVE-2026-56415CriJun 30, 2026
    risk 0.65cvss 10.0epss 0.04

    Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A remote attacker can submit a specially crafted HTTP request containing a malicious payload that is processed without adequate input…

  • CVE-2026-56413CriJun 30, 2026
    risk 0.65cvss 10.0epss 0.04

    Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default and accepts custom network packets to perform device actions. An unauthenticated remote attacker can send a specially crafted…

  • CVE-2026-56399MedJun 30, 2026
    risk 0.00cvss 5.0epss 0.00

    Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpoint that allows authenticated users to bypass SSRF protections. Attackers can manipulate URL parameters with location redirect headers to access internal…

  • CVE-2026-56377LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended…

  • CVE-2026-56369LowJun 30, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to AES-CTR nonce reuse. Attackers can exploit nonce reuse in the cipher implementation to recover plaintext information from encrypted images.

  • CVE-2026-56365LowJun 30, 2026
    risk 0.17cvss 3.7epss 0.00

    ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service.

  • CVE-2026-56364LowJun 30, 2026
    risk 0.05cvss 1.9epss 0.00

    ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing malformed OpenCL device profile XML files with unclosed device elements. Attackers with write access to the OpenCL cache directory can place malicious XML files…

  • CVE-2026-56363LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. An attacker can supply a large binomial kernel value causing integer overflow, resulting in division by zero and application…

  • CVE-2026-56361LowJun 30, 2026
    risk 0.14cvss 3.3epss 0.00

    ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

  • CVE-2026-56356MedJun 30, 2026
    risk 0.00cvss 5.4epss 0.00

    n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfiguration of the sanitize-html library. Affected releases are those before 1.123.27, the 2.0.0 through 2.13.2 line, and 2.14.0 (fixed in 1.123.27, 2.13.3, and…

  • CVE-2026-56350MedJun 30, 2026
    risk 0.00cvss 6.3epss 0.00

    n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforcement through the API. Attackers can create local password credentials to authenticate directly, bypassing organizational SSO policies and…

  • CVE-2026-56334MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and anonymous access from persisting builder status updates. Attackers can exploit this missing policy to cause build status and error details to remain unpersisted,…

  • CVE-2026-56333MedJun 30, 2026
    risk 0.00cvss 4.3epss 0.00

    Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allows authenticated org admins to persist invalid security policy state. Attackers can bypass backend validation by directly updating the public.orgs table from…

  • CVE-2026-56331MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors when magic_invite_string is invalid. Attackers can trigger this vulnerability using only the public key by submitting malformed…

  • CVE-2026-56328MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly resolve to a single hidden winner channel. An authorized app or channel manager can create ambiguous…

  • CVE-2026-56327MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function…

  • CVE-2026-56320HigJun 30, 2026
    risk 0.00cvss 7.1epss 0.00

    Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validating it matches the target app's owner organization. Authenticated attackers can create device records for an application using a…

  • CVE-2026-56318MedJun 30, 2026
    risk 0.00cvss 5.3epss 0.00

    Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different error responses for malformed, non-existent, and existing organization IDs. Unauthenticated attackers can enumerate valid…

  • CVE-2026-56300HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity oracles and user UUID disclosure. Unauthenticated attackers using the public API key can validate leaked keys, enumerate users and…

  • CVE-2026-56286HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.01

    Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authentication or secondary verification. Attackers can delete user accounts via session hijacking, CSRF attacks, or parameter…

  • CVE-2026-56278CriJun 30, 2026
    risk 0.00cvss 9.1epss 0.01

    Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the express-session middleware when the EXPRESS_SESSION_SECRET environment variable is not set (packages/server/src/enterprise/middleware/passport/index.ts). Because…

  • CVE-2026-56277MedJun 30, 2026
    risk 0.00cvss 6.5epss 0.00

    Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation endpoint (packages/server/src/controllers/text-to-speech/index.ts), independent of the server's configured CORS policy. This bypasses the server's otherwise…

  • CVE-2026-56264HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.00

    Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security enabled. An attacker can…

  • CVE-2026-56249HigJun 30, 2026
    risk 0.00cvss 7.6epss 0.00

    Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite existing channels by reusing their names. Attackers with app.create_channel permission can exploit a logic mismatch between…

  • CVE-2026-56247HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pending invitees. Attackers can pre-seed malformed high-privilege bindings that survive invite acceptance, enabling accepted…

  • CVE-2026-56233HigJun 30, 2026
    risk 0.00cvss 8.3epss 0.01

    Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated users with build permissions to bypass upload restrictions. Attackers can append traversal sequences to the upload path, which are normalized by the WHATWG URL…

  • CVE-2026-56230HigJun 30, 2026
    risk 0.00cvss 8.8epss 0.00

    Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-id header without validating ownership, allowing authenticated users to adopt cross-tenant limited keys. Attackers can supply…

  • CVE-2026-56224MedJun 30, 2026
    risk 0.00cvss 5.4epss 0.00

    Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers can craft malicious links to force victims into attacker-controlled sessions, exposing tokens in…

  • CVE-2026-56219HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.00

    Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that allows unauthenticated attackers to retrieve RBAC role bindings and member email addresses. Attackers can exploit improper NULL comparison in the authorization…

  • CVE-2026-55721CriJun 30, 2026
    risk 0.60cvss 9.3epss 0.01

    Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie value is incorporated directly into database queries without adequate sanitization, allowing an unauthenticated remote attacker to…

  • CVE-2026-55223MedJun 30, 2026
    risk 0.34cvss —epss 0.00

    c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the…

  • CVE-2026-54696LowJun 30, 2026
    risk 0.17cvss 3.7epss 0.00

    Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past…

  • CVE-2026-54673MedJun 30, 2026
    risk 0.35cvss 6.5epss 0.00

    electron-updater allows for automatic updates for Electron apps. Prior to 9.7.0, the HTTP redirect handler (HttpExecutor.prepareRedirectUrlOptions) only stripped a credential header whose key string matched exactly lowercase "authorization", exposing credentials. Other…

  • CVE-2026-54672HigJun 30, 2026
    risk 0.44cvss 7.8epss 0.00

    electron-updater allows for automatic updates for Electron apps. Prior to 26.15.0, AppImage targets built by app-builder-lib could use an empty path component when setting the LD_LIBRARY_PATH environment variable at runtime. This causes the current working directory to be added…

  • CVE-2026-52198HigJun 30, 2026
    risk 0.00cvss 7.5epss 0.01

    Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_425994 component