VYPR

CVEs

378,284 total · page 72 of 7,566

  • CVE-2026-91968MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deeply nested filter expressions without recursion depth limits. Authenticated attackers can supply thousands of nested parentheses in the filter query parameter to…

  • CVE-2026-91967MedSep 15, 2026
    risk 0.33cvss 5.0epss 0.00

    AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store attacker-chosen URLs as video…

  • CVE-2026-91966MedSep 15, 2026
    risk 0.38cvss 5.8epss 0.00

    AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe…

  • CVE-2026-91965HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner…

  • CVE-2026-91964HigSep 15, 2026
    risk 0.50cvss 8.8epss 0.01

    FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Server Redirection PDU messages with attacker-controlled LoadBalanceInfo fields. A malicious RDP server can trigger the overflow by sending an arbitrary-length…

  • CVE-2026-91963MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.01

    FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code…

  • CVE-2026-91962MedSep 15, 2026
    risk 0.34cvss 6.3epss 0.00

    FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values from MSG_SNDIN_OPEN messages. Attackers can supply crafted FramesPerPacket values that cause AudioQueueAllocateBuffer size computation to wrap, resulting in…

  • CVE-2026-91961MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to…

  • CVE-2026-91960MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allows remote attackers to cause denial of service. A malicious RD Gateway peer can send a WebSocket Ping frame with a crafted 64-bit extended payload length to…

  • CVE-2026-91959MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway transport parser. Attackers can send a malicious BIND_ACK PDU with a truncated result entry to trigger an out-of-bounds read causing process abort.

  • CVE-2026-91958MedSep 15, 2026
    risk 0.36cvss 6.6epss 0.00

    FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbounded array indexing in xf_detect_monitors. Attackers can craft a malicious RDP file with an out-of-range selectedmonitors value to trigger out-of-bounds heap…

  • CVE-2026-91957LowSep 15, 2026
    risk 0.13cvss 3.1epss 0.00

    FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman…

  • CVE-2026-91956MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with…

  • CVE-2026-91955HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion…

  • CVE-2026-91954MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits commands with NSCodec codec ID. A malicious RDP server can crash a FreeRDP client by sending a crafted Surface Bits command claiming to use NSCodec, even when…

  • CVE-2026-91953MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fails to validate the LB_LOAD_BALANCE_INFO field length before writing to a fixed 512-byte buffer. A malicious RDP server or man-in-the-middle can send a Server…

  • CVE-2026-91952MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the…

  • CVE-2026-91951MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated…

  • CVE-2026-91950MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsigned integer wraparound in buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with computerNameLen set to 0xFFFFFFF0 to bypass…

  • CVE-2026-91949CriSep 15, 2026
    risk 0.53cvss 9.3epss 0.00

    FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures,…

  • CVE-2026-91948HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.01

    FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handling when CHANNEL_OPTION_SHOW_PROTOCOL is enabled. Authenticated clients can queue oversized channel messages that cause buffer underflow and corrupt heap memory…

  • CVE-2026-91947HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger…

  • CVE-2026-91946MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU serializer that fails to initialize padding bytes in the fixed 340-byte wire format. Attackers can receive uninitialized heap memory including live pointers…

  • CVE-2026-91945MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.01

    FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to validate ATR length fields against fixed inline arrays. Authenticated RDP clients can send oversized ATR lengths in PAKID_CORE_DEVICE_IOCOMPLETION responses to…

  • CVE-2026-91944MedSep 15, 2026
    risk 0.33cvss 6.1epss 0.00

    crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the forceHighlightElement() function assigns textContent back to innerHTML, re-parsing JSON responses as HTML. Attackers can inject malicious scripts through crawled…

  • CVE-2026-91943HigSep 15, 2026
    risk 0.43cvss 7.7epss 0.00

    Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_path() re-downloads targets with Python requests without egress validation. Authenticated attackers can supply URLs that redirect to internal addresses or use…

  • CVE-2026-91942MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and…

  • CVE-2026-91941HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that allows untrusted clients to cause denial of service. Attackers can select the PDF scraping strategy in POST requests to download large remote PDFs without size or…

  • CVE-2026-91940HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to…

  • CVE-2026-91938HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network…

  • CVE-2026-91937HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to…

  • CVE-2026-91936MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like…

  • CVE-2026-91935HigSep 15, 2026
    risk 0.54cvss 8.3epss 0.00

    Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to…

  • CVE-2026-91934HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the…

  • CVE-2026-91933HigSep 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve…

  • CVE-2026-91932HigSep 15, 2026
    risk 0.55cvss 8.5epss 0.01

    Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling…

  • CVE-2026-91931HigSep 15, 2026
    risk 0.55cvss 8.5epss 0.01

    Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm…

  • CVE-2026-91930HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative…

  • CVE-2026-91929HigSep 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org…

  • CVE-2026-91849MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be…

  • CVE-2026-91848HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injection. Remote exploitation of…

  • CVE-2026-89307MedSep 15, 2026
    risk 0.33cvss epss 0.00

    The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

  • CVE-2026-88621Sep 15, 2026
    risk 0.00cvss epss 0.00

    OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application…

  • CVE-2026-88620Sep 15, 2026
    risk 0.00cvss epss 0.00

    SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged…

  • CVE-2026-88619HigSep 15, 2026
    risk 0.53cvss 8.1epss 0.00

    1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a low-privileged authenticated user to…

  • CVE-2026-87793MedSep 15, 2026
    risk 0.33cvss epss 0.00

    The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted URL containing a…

  • CVE-2026-87792HigSep 15, 2026
    risk 0.57cvss epss 0.00

    The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An…

  • CVE-2026-87791HigSep 15, 2026
    risk 0.57cvss epss 0.00

    A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.

  • CVE-2026-85013HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name,…

  • CVE-2026-77972CriSep 15, 2026
    risk 0.52cvss epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the address it approved, so the HTTP clients the…