VYPR

CVEs

387,004 total · page 744 of 7,741

  • CVE-2026-16216MedJul 19, 2026
    risk 0.00cvss 4.3epss 0.00

    A weakness has been identified in geex-arts django-jet up to 1.0.8. Affected is an unknown function of the component OAuth Handler. Executing a manipulation can lead to cross-site request forgery. The attack may be performed from remote. The exploit has been made available to…

  • CVE-2026-16215MedJul 19, 2026
    risk 0.00cvss 6.5epss 0.01

    A security flaw has been discovered in geex-arts django-jet up to 1.0.8. This impacts an unknown function of the component OAuth Credential Revoke Handler. Performing a manipulation results in missing authorization. The attack is possible to be carried out remotely. The exploit…

  • CVE-2026-16214MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in geex-arts django-jet up to 1.0.8. This affects an unknown function of the file jet/dashboard/views.py of the component Dashboard Module. Such manipulation leads to authorization bypass. The attack can be executed remotely. The exploit is…

  • CVE-2026-16213LowJul 19, 2026
    risk 0.00cvss 3.3epss 0.00

    A security flaw has been discovered in Fantomas42 django-blog-zinnia up to 0.20. Affected by this vulnerability is an unknown functionality of the file zinnia/views/mixins/entry_protection.py of the component Protected Entry Password Handler. The manipulation results in…

  • CVE-2026-16212MedJul 19, 2026
    risk 0.00cvss 4.2epss 0.00

    A vulnerability was identified in awesto django-shop up to 1.2.4. Affected is an unknown function of the file shop/models/inventory.py of the component Purchase Stock Handler. The manipulation leads to race condition. The attack is possible to be carried out remotely. The attack…

  • CVE-2026-16211LowJul 19, 2026
    risk 0.00cvss 2.6epss 0.00

    A vulnerability was determined in allegro up to bcf65b994ef29fb3fc2e10b660e6288723d5209e. This impacts the function AssetLastHostname.increment_hostname of the file src/ralph/assets/models/assets.py of the component Hostname Allocation Handler. Executing a manipulation of the…

  • CVE-2026-16210HigJul 19, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in newpanjing simpleui 2026.01.13. This affects the function self.get_action of the file simpleui/admin.py of the component AjaxAdmin AJAX Endpoint. Performing a manipulation results in missing authentication. Remote exploitation of the attack is…

  • CVE-2026-16209HigJul 19, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability has been found in Gerapy up to 0.9.13. The impacted element is an unknown function of the file gerapy/server/core/views.py of the component Project Upload Endpoint. Such manipulation leads to missing authentication. The attack may be launched remotely. The…

  • CVE-2026-16208MedJul 19, 2026
    risk 0.00cvss 5.0epss 0.00

    A flaw has been found in django-tastypie up to 0.15.1. The affected element is the function CacheThrottle/CacheDBThrottle of the file tastypie/throttle.py. This manipulation causes race condition. The attack may be initiated remotely. The complexity of an attack is rather high.…

  • CVE-2026-16207LowJul 19, 2026
    risk 0.00cvss 3.7epss 0.01

    A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file tastypie/authentication.py. The manipulation results in use of get request method with sensitive query strings. The attack can be launched remotely. This…

  • CVE-2026-16206MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The attack can be initiated remotely. The project…

  • CVE-2026-16205LowJul 19, 2026
    risk 0.00cvss 2.4epss 0.00

    A weakness has been identified in Pluck CMS up to 4.7.21. This vulnerability affects the function htmlspecialchars_decode of the file data/modules/albums/albums.admin.php of the component Albums Module. Executing a manipulation of the argument Info can lead to cross site…

  • CVE-2026-16204MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.01

    A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation results in code injection. It is possible…

  • CVE-2026-16203LowJul 19, 2026
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /forCYS.php. Such manipulation of the argument course leads to cross site scripting. The attack may be performed from remote.…

  • CVE-2026-16202LowJul 19, 2026
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out…

  • CVE-2026-16201MedJul 19, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was found in zevorn rt-claw up to 0.2.0. Affected is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation results in information disclosure. The attack can be executed remotely. The exploit…

  • CVE-2026-16200HigJul 19, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability has been found in zevorn rt-claw up to 0.2.0. This impacts the function claw_tool_invoke of the file claw/services/swarm/swarm.c of the component RPC Handler. The manipulation leads to incorrect authorization. Remote exploitation of the attack is possible. The…

  • CVE-2026-16199MedJul 19, 2026
    risk 0.00cvss 6.3epss 0.00

    A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/credentialed_exec.go. Executing a manipulation can lead to improper authorization. The attack may be launched remotely. The exploit…

  • CVE-2026-16198MedJul 19, 2026
    risk 0.00cvss 5.6epss 0.01

    A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. The impacted element is an unknown function of the file web/backend/middleware/access_control.go of the component First Run Setup. Performing a manipulation of the argument allowed_cidrs results in authentication…

  • CVE-2026-16197MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. The affected element is the function handleMessageReceive of the file pkg/channels/feishu/feishu_64.go of the component Group Message Handler. Such manipulation leads to missing authorization. The attack…

  • CVE-2026-16196MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Impacted is the function isPrivateOrRestrictedIP of the file pkg/tools/integration/web.go of the component web_fetch. This manipulation causes server-side request forgery. The attack can be initiated remotely. The…

  • CVE-2026-16195MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This issue affects the function dispatchIncoming of the file pkg/channels/wecom/wecom.go of the component Group Message Handler. The manipulation results in incorrect authorization. It is possible to launch the…

  • CVE-2026-10130HigJul 18, 2026
    risk 0.46cvss 8.2epss 0.01

    QueryWeaver contains an authentication bypass vulnerability that allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token…

  • CVE-2026-16194MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in zhayujie CowAgent up to 2.1.1. This affects the function WebFetch.execute of the file agent/tools/web_fetch/web_fetch.py. Executing a manipulation of the argument url can lead to server-side request forgery. The attack may be performed from…

  • CVE-2026-16156LowJul 18, 2026
    risk 0.00cvss 3.5epss 0.00

    A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /forexam.php. The manipulation of the argument day results in cross site scripting. It is possible to launch the attack remotely. The exploit has…

  • CVE-2026-57857MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross-site scripting on the WooCommerce checkout page. When the plugin handles an order cancellation, the error_message GET parameter is passed directly to wc_add_notice() in…

  • CVE-2026-16155LowJul 18, 2026
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /schoolyr.php. The manipulation of the argument sy leads to cross site scripting. It is possible to initiate the attack…

  • CVE-2026-16154HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be…

  • CVE-2026-16152HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible to be carried out remotely. The exploit…

  • CVE-2026-12228MedJul 18, 2026
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into `DBDirectMessage.content` without server-side sanitization. When a victim opens…

  • CVE-2026-57848MedJul 18, 2026
    risk 0.00cvss 5.5epss 0.00

    Stoat for Android exports the chat.stoat.activities.ShareTargetActivity component (reachable to any process on the device via the android.intent.action.SEND intent) and accepts the file to share as a URI supplied through the android.intent.extra.STREAM extra. The activity does…

  • CVE-2026-53994HigJul 18, 2026
    risk 0.42cvss 7.5epss 0.00

    ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an authenticated SFTP user. The fxp_packet_read() function accepts the attacker-supplied 32-bit big-endian SFTP packet length without a minimum sanity check. A value of 0 causes an unsigned subtraction elsewhere…

  • CVE-2026-16151MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads to improperly controlled modification of object prototype attributes. The attack can be executed…

  • CVE-2026-16150MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in RobinHerbots Inputmask up to 5.0.9. Affected by this issue is the function extendDefaults/extendDefinitions/extendAliases in the library lib/dependencyLibs/extend.js of the component Internal Deep Merge Helper. The manipulation results in improperly…

  • CVE-2026-16133MedJul 18, 2026
    risk 0.00cvss 5.0epss 0.01

    A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. The attack requires a high level of…

  • CVE-2026-16131MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-16130MedJul 18, 2026
    risk 0.00cvss 4.4epss 0.00

    A vulnerability was identified in nearai ironclaw up to 0.29.1. The affected element is the function validate_path of the file src/tools/builtin/path_utils.rs of the component write_file. The manipulation leads to link following. Local access is required to approach this attack.…

  • CVE-2026-16129MedJul 18, 2026
    risk 0.00cvss 5.3epss 0.00

    A vulnerability has been found in princezuda SafestClaw up to 4.2.4. This vulnerability affects the function ShellAction._validate_command of the file src/safestclaw/actions/shell.py of the component Built-in Web Interface. Such manipulation leads to incomplete blacklist. An…

  • CVE-2026-16128HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.01

    A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This impacts the function receiver_thread of the file claw/services/swarm/swarm.c of the component http_request. Performing a manipulation results in server-side request forgery. It is possible to initiate the…

  • CVE-2026-16127HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was identified in zevorn rt-claw up to 0.2.0. This affects the function claw_net_get/claw_net_post of the file claw/tools/tool_net.c of the component http_request. Such manipulation of the argument url leads to server-side request forgery. The attack may be…

  • CVE-2026-16126HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was determined in zevorn rt-claw up to 0.2.0. The impacted element is the function handle_rpc_request of the file claw/services/swarm/swarm.c of the component Swarm RPC Receiver. This manipulation causes incorrect authorization. The attack is possible to be…

  • CVE-2026-16125HigJul 18, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in zevorn rt-claw up to 0.2.0. The affected element is the function claw_net_get/claw_net_post of the file claw/services/tools/net.c of the component http_request. The manipulation of the argument url results in server-side request forgery. The attack…

  • CVE-2026-16124MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.15.0-beta.32. This affects the function CheckSSRF/isPrivateIP of the file internal/tools/web_shared.go of the component web_fetch. Such manipulation leads to server-side request forgery. The attack can…

  • CVE-2026-16123MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A weakness has been identified in nextlevelbuilder GoClaw up to 3.13.2. Affected by this issue is the function ToolsInvokeHandler.ServeHTTP of the file internal/http/tools_invoke.go of the component Invoke Endpoint. This manipulation causes missing authorization. The attack can…

  • CVE-2026-16122MedJul 18, 2026
    risk 0.00cvss 4.3epss 0.00

    A security flaw has been discovered in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function extractBin/RequestApproval/matchesAllowlist of the file internal/tools/exec_approval.go. The manipulation results in incorrect authorization. The exploit…

  • CVE-2026-16121MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.go. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly…

  • CVE-2026-9323HigJul 18, 2026
    risk 0.46cvss 8.1epss 0.01

    The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. Each call consumes approximately…

  • CVE-2026-16120MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was determined in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This impacts the function matchesAllowlist/extractBin of the file internal/tools/exec_approval.go. Executing a manipulation can lead to incorrectly-resolved name. The attack may be performed from…

  • CVE-2026-16119MedJul 18, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was found in nextlevelbuilder GoClaw up to 3.13.2. This affects the function RequestApproval of the file internal/tools/exec_approval.go of the component WebSocket Approval Endpoint. Performing a manipulation results in incorrect authorization. The attack is…

  • CVE-2026-16117CriJul 18, 2026
    risk 0.00cvss 10.0epss 0.00

    Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for route matching, but request.url retains the original encoded form, and the prefix-rewrite step uses a…