VYPR

CVEs

378,333 total · page 74 of 7,567

  • CVE-2026-65831HigSep 15, 2026
    risk 0.43cvss 7.7epss 0.00

    ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with language: js because PolyglotQueryEngine.command, PolyglotQueryEngine.analyze, and PolyglotQueryEngine.registerFunctions do not enforce database-administrator…

  • CVE-2026-59973HigSep 15, 2026
    risk 0.48cvss 8.5epss 0.00

    FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 and from frontmcp and @frontmcp/adapters 1.2.1 until 1.5.0, libs/adapters/src/openapi/openapi.adapter.ts loadOpenAPISpec() forwards untrusted OpenAPI url and…

  • CVE-2026-59965HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plugin exposes POST /api/alt-text-plugin/generate and POST /api/alt-text-plugin/bulk with a default guard that accepts any authenticated user, while…

  • CVE-2026-59157MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior to 1.22.0, webhookd deployments without htpasswd authentication forwarded all incoming HTTP headers through HTTPParamsToShellVars in pkg/api/index.go into the…

  • CVE-2026-58196MedSep 15, 2026
    risk 0.24cvss 4.7epss 0.00

    ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.31.0, remote.Handler.Authenticate in pkg/auth/remote/handler.go invokes discovery.DetectAuthenticationFromServer in pkg/auth/discovery/discovery.go, whose…

  • CVE-2026-55887HigSep 15, 2026
    risk 0.50cvss epss 0.00

    MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway YAML-unmarshalled the attacker-controlled io.docker.server.metadata OCI image label into the broad catalog.Server structure for direct docker:// references and…

  • CVE-2026-55864HigSep 15, 2026
    risk 0.44cvss epss 0.01

    GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tools/ogc/sld accepted a caller-supplied WMS server URL and performed a server-side HTTP GET without destination validation. An anonymous attacker could make the…

  • CVE-2026-55828MedSep 15, 2026
    risk 0.32cvss epss 0.00

    qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses strictly lexical path validation that does not account for on-disk symlinks created earlier in the extraction process. A crafted tar archive can use a symlink chain…

  • CVE-2026-55776MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter selected rsa-, ecdsa-, or ed25519. The…

  • CVE-2026-55775LowSep 15, 2026
    risk 0.08cvss epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on /sys/namespaces/root within a non-root namespace could exploit special handling of the literal root path in namespace canonicalization. The /sys/namespaces/*…

  • CVE-2026-55774LowSep 15, 2026
    risk 0.07cvss epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/leases/revoke/:lease_id in one namespace could revoke a lease in another namespace when the foreign lease_id was known, bypassing namespace ACL isolation. The…

  • CVE-2026-55770MedSep 15, 2026
    risk 0.37cvss 6.8epss 0.00

    OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC 4514 distinguished-name escaping function, where RFC 4515 LDAP search-filter escaping was required in sdk/helper/ldaputil/client.go GetUserDN. With the LDAP…

  • CVE-2026-55701MedSep 15, 2026
    risk 0.38cvss epss 0.01

    The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, the githubreceiver validates the receiver/githubreceiver/config.go RequiredHeaders configuration at startup, but receiver/githubreceiver/trace_receiver.go…

  • CVE-2026-55636MedSep 15, 2026
    risk 0.30cvss 5.7epss 0.00

    Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name namespaces/finalize. A user with…

  • CVE-2026-55630NonSep 15, 2026
    risk 0.00cvss 0.0epss 0.00

    Kiwi TCMS is an open source test management system. Prior to 16.1, TestCase.extra_link and TestPlan.extra_link accepted unsanitized user input and rendered stored values verbatim, creating an opportunity for cross-site scripting. Official Docker images and unmodified Kiwi TCMS…

  • CVE-2026-55591MedSep 15, 2026
    risk 0.31cvss 5.8epss 0.00

    Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in src/serverroutes.ts accepted attacker-controlled host, port, useTLS, and selfsignedcert parameters from the testSignalKConnection, requestAccess, and…

  • CVE-2026-55211CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Surfio is a library for reading and writing surface files. Prior to 0.0.19, surfio does not correctly validate size fields in IRAP files, leading to a buffer overflow when untrusted files are parsed. The severity assumes surfio is used to parse untrusted files in a networking…

  • CVE-2026-54724MedSep 15, 2026
    risk 0.33cvss 6.1epss 0.00

    Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalidated next parameter, allowing an unauthenticated attacker to create a URL on a trusted Kiwi TCMS hostname that redirects a victim to an arbitrary external…

  • CVE-2026-54450LowSep 15, 2026
    risk 0.12cvss epss 0.00

    ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior to 0.29.1, networking.IsPrivateIP in pkg/networking/utilities.go omits the IPv6 NAT64 prefixes 64:ff9b::/96 and 64:ff9b:1::/48, so NAT64 addresses embedding…

  • CVE-2026-54077HigSep 15, 2026
    risk 0.39cvss 7.1epss 0.00

    ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/query/sql/parser/ImportDatabaseStatement.java did not require administrative privileges and passed its source to integration/src/main/java/com/arcadedb/integration/…

  • CVE-2026-54076HigSep 15, 2026
    risk 0.46cvss 8.1epss 0.00

    ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check only to LocalDocumentType.createProperty, while the remaining public schema mutators in engine/src/main/java/com/arcadedb/schema/LocalDocumentType.java and…

  • CVE-2026-50024MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_tasks parses an attacker-controlled ref path from .git/HEAD and joins unvalidated path segments onto temp_dst/.git/logs/, allowing a malicious server to make…

  • CVE-2026-47215MedSep 15, 2026
    risk 0.24cvss 4.8epss 0.00

    SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.3.9 and 4.1.14, incorrect path-string matching in the singularity.conf limit container paths directive allows a container in a sibling directory such as…

  • CVE-2026-44282MedSep 15, 2026
    risk 0.24cvss 4.8epss 0.00

    Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or election editor with question-management rights can store HTML or script-bearing content in question.body. The question_title helper returns the translatable question…

  • CVE-2026-44163MedSep 15, 2026
    risk 0.27cvss 5.3epss 0.00

    fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.5.3, the in_opentelemetry HTTP input read the entire incoming request body and decompressed payloads into memory without enforcing maximum size thresholds.…

  • CVE-2026-37152CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.

  • CVE-2026-19407HigSep 15, 2026
    risk 0.50cvss epss 0.01

    Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an attacker to achieve Remote Code Execution (RCE) and tenant-project token theft.

  • CVE-2024-58384MedSep 15, 2026
    risk 0.28cvss 5.4epss 0.00

    Tornado before 6.4.1 contains a CRLF injection vulnerability in CurlAsyncHTTPClient that fails to reject carriage return and line feed characters in request headers. Attackers can inject CRLF sequences into header values to inject arbitrary headers or construct entirely new HTTP…

  • CVE-2024-14029HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request…

  • CVE-2023-54397HigSep 15, 2026
    risk 0.42cvss 7.5epss 0.00

    Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed…

  • CVE-2026-92082MedSep 15, 2026
    risk 0.41cvss epss 0.00

    By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute force login attacks. To mitigate this, Payara Server includes built-in automatic attack protection. For configuration details, see …

  • CVE-2026-91842MedSep 15, 2026
    risk 0.27cvss 4.1epss 0.00

    A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be…

  • CVE-2026-91836LowSep 15, 2026
    risk 0.11cvss 2.8epss 0.00

    A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/static_scanner.go of the component Static Scanner. This manipulation causes incomplete comparison with missing factors. It is possible to launch the attack on the…

  • CVE-2026-91835LowSep 15, 2026
    risk 0.11cvss 2.8epss 0.00

    A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the file internal/runner/static_scanner.go of the component File Classifier. The manipulation results in interpretation conflict. Attacking locally is a…

  • CVE-2026-90650HigSep 15, 2026
    risk 0.40cvss 7.2epss 0.00

    The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-90439MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions <= OpenSSL 3.5.0 under certain configurations, a limited heap buffer overflow could happen while processing a TLS handshake. This can happen in a…

  • CVE-2026-89025HigSep 15, 2026
    risk 0.49cvss 7.5epss 0.00

    Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed…

  • CVE-2026-88618MedSep 15, 2026
    risk 0.42cvss 6.5epss 0.00

    1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-88617CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.00

    SmartAdmin v3.30.0 contains an authorization flaw in the configuration query endpoint. This allows a remote attacker to escalate privileges.

  • CVE-2026-88616HigSep 15, 2026
    risk 0.57cvss 8.8epss 0.01

    An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components

  • CVE-2026-79551Sep 15, 2026
    risk 0.00cvss epss 0.00

    Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key.

  • CVE-2026-79425HigSep 15, 2026
    risk 0.53cvss 8.1epss 0.00

    An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.

  • CVE-2026-79303Sep 15, 2026
    risk 0.00cvss epss 0.00

    kaiten from 57.192.20 to before 57.214.26 is vulnerable to SQL Injection. Dynamic SQL statements are generated without the required data validation and without using parameterized statements or stored procedures.

  • CVE-2026-63696CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Download of Code Without Integrity Check vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.

  • CVE-2026-63695CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Dell SmartFabric OS10 Software, versions prior to 10.6.1.3, contains a Session Fixation vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Session theft.

  • CVE-2026-61549CriSep 15, 2026
    risk 0.52cvss epss 0.00

    Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_options.kubernetes.serviceAccountName, and the Kubernetes backend in pipeline/backend/kubernetes/pod.go copies that pipeline-step value directly into the pod…

  • CVE-2026-59971CriSep 15, 2026
    risk 0.58cvss 10.0epss 0.00

    MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_settings or enable_dns_rebinding_protection,…

  • CVE-2026-57586HigSep 15, 2026
    risk 0.49cvss 8.6epss 0.00

    CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or…

  • CVE-2026-55650MedSep 15, 2026
    risk 0.22cvss 4.4epss 0.00

    Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2 and earlier, TextComponent in src/components/chart/index.tsx renders unsanitized Text Widget content through dangerouslySetInnerHTML, allowing injected markup…

  • CVE-2026-55617MedSep 15, 2026
    risk 0.38cvss epss 0.00

    Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous token from the server-side session token…