VYPR

CVEs

378,283 total · page 71 of 7,566

  • CVE-2026-89022HigSep 15, 2026
    risk 0.48cvss 7.4epss 0.00

    BookStack before 26.05.5 contains an authentication bypass vulnerability in its social login implementation that allows unauthenticated attackers to sign in as arbitrary users by authenticating through a different social provider sharing the same driver_id namespace. Attackers…

  • CVE-2026-81897MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not validate the anti-CSRF token. By causing an authenticated administrator to submit a forged cross-site request, a remote attacker without credentials could write…

  • CVE-2026-81896MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering them as column headers in the Dashboard Form Submissions report (concrete/single_pages/dashboard/reports/forms/legacy.php). a rogue editor could store markup…

  • CVE-2026-81895HigSep 15, 2026
    risk 0.40cvss 7.2epss 0.00

    In Concrete CMS before 9.5.3, the Document Library block stored the file-set identifiers submitted through fsID[] without validating them as integers, and when the block was configured with setMode set to any it concatenated each stored identifier directly into the file-set…

  • CVE-2026-81894MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-image Caption field because the bundled Magnific Popup lightbox script (concrete/js/features/imagery/frontend.js) re-parses the attribute-decoded caption as HTML…

  • CVE-2026-79705MedSep 15, 2026
    risk 0.29cvss 4.5epss 0.00

    A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot…

  • CVE-2026-79699MedSep 15, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer,…

  • CVE-2026-63443HigSep 15, 2026
    risk 0.47cvss 8.3epss 0.00

    Coder allows organizations to provision remote development environments via Terraform. Prior to 2.29.19, 2.32.9, 2.33.10, and 2.34.4, agentConn.apiClient() follows redirects while its custom transport accepts the host from the redirected request URL when the port is the…

  • CVE-2026-59160HigSep 15, 2026
    risk 0.50cvss 8.8epss 0.00

    Yeger is a monorepo for npm packages maintained under the yeger scope. Prior to 2.8.9, the turbo-graph package starts its embedded Next.js server from packages/turbo-graph/src/index.ts on all interfaces, including 0.0.0.0:29312 by default, while the GET handler for /api/run in…

  • CVE-2026-58201HigSep 15, 2026
    risk 0.50cvss epss 0.00

    Lokka is a Model Context Protocol server for Microsoft 365, including Microsoft Graph and other services. Prior to 2.1.2, the Lokka-Microsoft tool in src/mcp/src/main.ts uses direct URL string concatenation to append the user-controlled path value to the management.azure.com…

  • CVE-2026-58200HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Payload Plugins is a collection of plugins designed to enhance Payload CMS. From 0.3.0 until 0.4.0, @jhb.software/payload-cloudinary-plugin deployments with clientUploads enabled expose POST /api/cloudinary-generate-signature, whose handler in…

  • CVE-2026-55863MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, the ActionHandler.post() method in motioneye/handlers/action.py lacks the BaseHandler.auth() decorator, allowing an…

  • CVE-2026-55692HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled,…

  • CVE-2026-55691HigSep 15, 2026
    risk 0.49cvss 8.6epss 0.00

    The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the…

  • CVE-2026-55690HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php…

  • CVE-2026-55149HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Vouch Proxy is an SSO and OAuth/OIDC login solution for Nginx using the auth_request module. Prior to 0.48.0, Cookie in pkg/cookie/cookie.go parses the total part count from an attacker-controlled multipart cookie name and passes the value to make([]string, numParts) without…

  • CVE-2026-54561MedSep 15, 2026
    risk 0.33cvss 6.2epss 0.00

    MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_import in src/index.ts passes the caller-controlled filePath directly to fs.readFileSync without restricting the path to an export directory. An MCP client,…

  • CVE-2026-54503MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type. Prior to 2.0.2, 3.0.2, and 4.0.1, depending on the release line, RichTextValue.output returns an unsanitized stored RichText value when mimeType equals…

  • CVE-2026-53710CriSep 15, 2026
    risk 0.58cvss 10.0epss 0.01

    MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr through safe_builtins, omits a…

  • CVE-2026-53658MedSep 15, 2026
    risk 0.34cvss epss 0.00

    Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP backend, Client.GetUser in lib/server/ldap/client.go inserts the username from HTTP Basic authentication into the LDAP uid search UserFilter without escaping…

  • CVE-2026-46488CriSep 15, 2026
    risk 0.52cvss epss 0.00

    motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Prior to 0.44.0, motionEye accepts the client-controlled meye_username and meye_password_hash cookies as authentication material without…

  • CVE-2026-44778LowSep 15, 2026
    risk 0.12cvss epss 0.00

    Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. From 0.28.0 until 0.53.1, the USDT note parser in pkg/uprobetracer/usdt.go can allow an unprivileged container to crash or exhaust the…

  • CVE-2026-21588HigSep 15, 2026
    risk 0.46cvss epss 0.00

    This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an…

  • CVE-2026-21587HigSep 15, 2026
    risk 0.46cvss epss 0.00

    This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to gain unintended access and can lead to…

  • CVE-2026-21586HigSep 15, 2026
    risk 0.46cvss epss 0.00

    This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1,…

  • CVE-2026-19780HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Koha. Authentication is required to exploit this vulnerability. The specific flaw exists within the web service, which…

  • CVE-2026-18111HigSep 15, 2026
    risk 0.48cvss epss 0.00

    Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image, and Image blocks and before Concrete 8.5.21 in the feature and Image blocks because the external link URL was insufficiently validated by the link filter and…

  • CVE-2026-18110HigSep 15, 2026
    risk 0.57cvss epss 0.00

    Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint (/ccm/system/user/autocomplete), which backs the "Preview as User" panel and other user-selector components. The endpoint validates only a CSRF-style access…

  • CVE-2024-58385CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Yonyou U8 CRM contains an unauthenticated SQL injection vulnerability in the fillbacksettingedit.php configuration endpoint where the DontCheckLogin=1 parameter bypasses authentication and the id parameter is incorporated into SQL queries without sanitization. Attackers can…

  • CVE-2023-54398CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Yonyou U8 Cloud contains an unauthenticated Java deserialization vulnerability in the nc.impl.pub.filesystem.FileManageServlet component that allows remote unauthenticated attackers to execute arbitrary OS commands by sending a serialized payload via POST request. Attackers can…

  • CVE-2026-91992MedSep 15, 2026
    risk 0.31cvss 5.9epss 0.00

    Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused across requests without proper state clearing. Attackers can obtain sensitive credentials by issuing requests through the same client instance, allowing TLS…

  • CVE-2026-91991MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary cookie attributes by passing capitalized or legacy keyword arguments to set_cookie. Attackers can embed semicolon-delimited data in capitalized parameters…

  • CVE-2026-91990HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart data before validating the max_parts limit. Attackers can send crafted multipart requests with many parts to create large transient lists, exhausting server…

  • CVE-2026-91989HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.01

    atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote attackers to read arbitrary files by supplying directory traversal sequences in request paths. Attackers can bypass path containment checks by including '../'…

  • CVE-2026-91988HigSep 15, 2026
    risk 0.53cvss 8.1epss 0.00

    atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowing network man-in-the-middle attackers to rewrite catalog responses. Attackers can inject arbitrary command and argument values that are spawned as local…

  • CVE-2026-91987MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero cost for unknown models not in the pricing table. Attackers can configure deployments with unknown model identifiers to bypass daily cost caps and exceed…

  • CVE-2026-91986MedSep 15, 2026
    risk 0.35cvss 5.4epss 0.00

    gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attackers to inject NUL/CR/LF bytes via crafted git URLs. Attackers can inject extra NUL-delimited protocol fields to spoof virtual hosts or inject newlines into…

  • CVE-2026-91985HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allowing read-only members to obtain the share's secret credential. Attackers can exchange the disclosed hash for a link-share JWT at the share's permission level…

  • CVE-2026-91984MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task's project. Authenticated attackers can insert task position rows into arbitrary other tenant project views via POST or PUT task-position endpoints.

  • CVE-2026-91983MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails to inspect query string parameters. Attackers with limited token scopes can use the expand parameter to access restricted data like comments, reactions, and…

  • CVE-2026-91982MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settings/totp and /api/v1/user/settings/totp/qrcode endpoints without re-authentication. Attackers with a valid access token can read the secret, import it into…

  • CVE-2026-91981MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers with a read-only share link can enumerate project users via the projects endpoint and confirm arbitrary usernames exist via the global search endpoint.

  • CVE-2026-91980MedSep 15, 2026
    risk 0.21cvss 4.3epss 0.00

    vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enumerate all teams and members. Attackers can attach arbitrary team IDs via the project teams endpoint to retrieve complete team rosters including member names…

  • CVE-2026-91979MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial of service. Attackers can upload highly compressed files that expand to tens of gigabytes in memory and disk, exhausting server resources and crashing the…

  • CVE-2026-91973HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.01

    Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiting protection. Remote unauthenticated attackers can issue unbounded credential-guessing requests against /dav, /.well-known, and /feeds routes to bypass the…

  • CVE-2026-91972HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.01

    Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, register, password-reset, and OAuth token routes. Remote unauthenticated attackers can perform unbounded credential guessing, account enumeration, and…

  • CVE-2026-91971MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing authenticated users to upload crafted images that decode to excessive pixel counts. Attackers can upload small images with extreme aspect ratios that consume…

  • CVE-2026-91970MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce aggregate memory budgets during migration jobs. Authenticated attackers can submit migration requests pointing to attacker-controlled servers advertising…

  • CVE-2026-91969MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endpoint that fails to limit parsed row cardinality. Authenticated attackers can upload multipart CSV files with millions of tiny records to exhaust process memory…

  • CVE-2026-91968MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to…