VYPR

CVEs

378,305 total · page 73 of 7,567

  • CVE-2026-91938HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer document loader nodes that bypass SSRF protection. Attackers can provide arbitrary URLs to fetch cloud metadata, internal services, and private network…

  • CVE-2026-91937HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within the MongoDBMemory node. Unauthenticated attackers can submit MongoDB operator objects through the prediction API to read chat history records belonging to…

  • CVE-2026-91936MedSep 15, 2026
    risk 0.44cvss 6.8epss 0.00

    Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_dispatch inputs are directly interpolated into shell run blocks. Attackers with repository write access can inject shell metacharacters through inputs like…

  • CVE-2026-91935HigSep 15, 2026
    risk 0.54cvss 8.3epss 0.00

    Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect requests to arbitrary hosts. Attackers with chatflows:create or chatflows:update permissions can exfiltrate LLM provider API keys by redirecting requests to…

  • CVE-2026-91934HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite databases, allowing authenticated attackers to write arbitrary files. Attackers can write malicious SQLite databases to system directories or inject files into the…

  • CVE-2026-91933HigSep 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authenticated users to access tools from ChatFlows in other workspaces by supplying an unscoped chatflowid. Attackers can invoke GET and POST requests to retrieve…

  • CVE-2026-91932HigSep 15, 2026
    risk 0.55cvss 8.5epss 0.01

    Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attackers remote code execution through an unvalidated cwd parameter. Attackers can bypass path validation using clean filenames in the args array while controlling…

  • CVE-2026-91931HigSep 15, 2026
    risk 0.55cvss 8.5epss 0.01

    Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attackers to execute arbitrary code by supplying npx package names in the mcpServerConfig parameter. Attackers can invoke npx with attacker-controlled npm…

  • CVE-2026-91930HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowing authenticated users to supply arbitrary organization IDs. Attackers can add themselves as organization owners, create workspaces, and gain administrative…

  • CVE-2026-91929HigSep 15, 2026
    risk 0.46cvss 7.1epss 0.00

    Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resource ownership before operations. Attackers with Enterprise access can delete arbitrary workspaces, invite themselves into other organizations, modify cross-org…

  • CVE-2026-91849MedSep 15, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /index.php?m=member&f=user&v=setAvatar of the component Avatar Upload. The manipulation of the argument File results in unrestricted upload. The attack can be…

  • CVE-2026-91848HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of the file /index.php?m=content&f=article&v=getDataOfJson. The manipulation of the argument title/master_table leads to sql injection. Remote exploitation of…

  • CVE-2026-89307MedSep 15, 2026
    risk 0.33cvss epss 0.00

    The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject arbitrary HTML via the sign parameter, enabling forced redirection of visiting users to an attacker-controlled URL (Stored HTML Injection / Open Redirect).

  • CVE-2026-88621Sep 15, 2026
    risk 0.00cvss epss 0.00

    OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.php. An authenticated administrator can submit a non-HTML upload filename matching an existing file in the application's working directory. The application…

  • CVE-2026-88620Sep 15, 2026
    risk 0.00cvss epss 0.00

    SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/queryAll endpoint. The endpoint does not enforce the required function-level permission or data-scope authorization, allowing an authenticated low-privileged…

  • CVE-2026-88619HigSep 15, 2026
    risk 0.53cvss 8.1epss 0.00

    1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The AdminSmartJobController exposes scheduled-job management endpoints without method-level permission checks, allowing a low-privileged authenticated user to…

  • CVE-2026-87793MedSep 15, 2026
    risk 0.33cvss epss 0.00

    The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.php file, allowing an unauthenticated attacker to execute arbitrary JavaScript in a victim's browser via a crafted URL containing a…

  • CVE-2026-87792HigSep 15, 2026
    risk 0.57cvss epss 0.00

    The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_generator and dsi_csv_generator functions, allowing an unauthenticated attacker to access restricted "Circolare" content and registered users' data. An…

  • CVE-2026-87791HigSep 15, 2026
    risk 0.57cvss epss 0.00

    A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Design Scuole Italia theme. The vulnerability allows an unauthenticated attacker to download arbitrary files accessible by the web server process.

  • CVE-2026-85013HigSep 15, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name,…

  • CVE-2026-77972CriSep 15, 2026
    risk 0.52cvss epss 0.00

    Time-of-check Time-of-use (TOCTOU) Race Condition in Slab safeurl allows an attacker who controls a hostname's DNS responses to reach internal network destinations that validation rejected. Validation returns a verdict and not the address it approved, so the HTTP clients the…

  • CVE-2026-77866CriSep 15, 2026
    risk 0.52cvss epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in Slab safeurl allows an attacker who controls a validated URL to reach internal network destinations the library is configured to block. Only IPv4 addresses are matched against the reserved ranges and the blocklist. Every other…

  • CVE-2026-65831HigSep 15, 2026
    risk 0.43cvss 7.7epss 0.00

    ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator…

  • CVE-2026-59973HigSep 15, 2026
    risk 0.48cvss 8.5epss 0.00

    FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and…

  • CVE-2026-59965HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while…

  • CVE-2026-59157MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsToShellVars in pkg/api/index.go into the…

  • CVE-2026-58196MedSep 15, 2026
    risk 0.24cvss 4.7epss 0.00

    ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer in pkg/auth/discovery/discovery.go, whose…

  • CVE-2026-55887HigSep 15, 2026
    risk 0.50cvss epss 0.00

    MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and…

  • CVE-2026-55864HigSep 15, 2026
    risk 0.44cvss epss 0.01

    GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validation. An anonymous attacker could make the…

  • CVE-2026-55828MedSep 15, 2026
    risk 0.32cvss epss 0.00

    qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain…

  • CVE-2026-55776MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rsa-, ecdsa-, or ed25519. The…

  • CVE-2026-55775LowSep 15, 2026
    risk 0.08cvss epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespace canonicalization. The /sys/namespaces/*…

  • CVE-2026-55774LowSep 15, 2026
    risk 0.07cvss epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing namespace ACL isolation. The…

  • CVE-2026-55770MedSep 15, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP…

  • CVE-2026-55701MedSep 15, 2026
    risk 0.38cvss epss 0.01

    The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go…

  • CVE-2026-55636MedSep 15, 2026
    risk 0.30cvss 5.7epss 0.00

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name namespaces/finalize. A user with…

  • CVE-2026-55630NonSep 15, 2026
    risk 0.00cvss 0.0epss 0.00

    Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS…

  • CVE-2026-55591MedSep 15, 2026
    risk 0.31cvss 5.8epss 0.00

    Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalKConnection, requestAccess, and…

  • CVE-2026-55211CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking…

  • CVE-2026-54724MedSep 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external…

  • CVE-2026-54450LowSep 15, 2026
    risk 0.12cvss epss 0.00

    ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, so NAT64 addresses embedding…

  • CVE-2026-54077HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/…

  • CVE-2026-54076HigSep 15, 2026
    risk 0.46cvss 8.1epss 0.00

    ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and…

  • CVE-2026-50024MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/, allowing a malicious server to make…

  • CVE-2026-47215MedSep 15, 2026
    risk 0.24cvss 4.8epss 0.00

    SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a container in a sibling directory such as…

  • CVE-2026-44282MedSep 15, 2026
    risk 0.24cvss 4.8epss 0.00

    Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_title helper returns the translatable question…

  • CVE-2026-44163MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds.…

  • CVE-2026-37152CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

  • CVE-2026-19407HigSep 15, 2026
    risk 0.50cvss epss 0.01

    Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

  • CVE-2024-58384MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP…