VYPR

CVEs

387,025 total · page 754 of 7,741

  • CVE-2026-46512CriJul 16, 2026
    risk 0.00cvss 9.9epss 0.01

    Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, code, and file, and Tools/DialplanApply.php wrote Dialplan/Templates.php output to extensions_custom.conf…

  • CVE-2026-46404MedJul 16, 2026
    risk 0.37cvss 6.8epss 0.00

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, the presentation URL validation did not properly restrict access to site local and link local addresses. The redirect following logic now pins resolved IPs. This issue is fixed in version 3.0.23.

  • CVE-2026-46378MedJul 16, 2026
    risk 0.33cvss 6.2epss 0.00

    Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go loops while tokenizing an unterminated regex…

  • CVE-2026-46377MedJul 16, 2026
    risk 0.33cvss 6.2epss 0.00

    Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go increments past a trailing backslash in a quoted string such as "\…

  • CVE-2026-46353HigJul 16, 2026
    risk 0.46cvss 8.1epss 0.00

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web checksum validation could be bypassed when a presentationUploadExternalUrl parameter was supplied to API request handling in CreateMeeting.java and ValidationService.java, allowing a user to send valid…

  • CVE-2026-46351HigJul 16, 2026
    risk 0.46cvss 8.1epss 0.00

    BigBlueButton is an open-source virtual classroom. Prior to 3.0.21, bbb-web generated conference sessionToken values with insufficiently secure randomness in bbb-common-web/src/main/java/org/bigbluebutton/api/Util.java and bigbluebutton-web/grails-app/controllers/org/bigbluebutto…

  • CVE-2026-46338MedJul 16, 2026
    risk 0.21cvss 4.3epss 0.00

    PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing…

  • CVE-2026-46687HigJul 16, 2026
    risk 0.00cvss —epss 0.00

    Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter from api_controller.php without validation, and log_controller.php later checks file_exists and calls include…

  • CVE-2026-46686HigJul 16, 2026
    risk 0.00cvss —epss 0.00

    Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php is processed with addslashes but not HTML-escaped before being rendered into the value attribute in admin/views/user.php, allowing…

  • CVE-2026-46341MedJul 16, 2026
    risk 0.33cvss 6.1epss 0.00

    The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to 0.9.21, the fetch-apify-docs tool in src/tools/common/fetch_apify_docs.ts validates allowlisted documentation…

  • CVE-2026-46336HigJul 16, 2026
    risk 0.00cvss 7.1epss 0.01

    Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. From 0.96.0 until 0.140.0, authenticated users can rename uploaded files with path traversal sequences because app/models/model_file.rb uses the…

  • CVE-2026-45336CriJul 16, 2026
    risk 0.58cvss 10.0epss 0.01

    HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier, app.py assigns a hard-coded Flask secret_key used to sign session cookies, allowing unauthenticated attackers who know the public…

  • CVE-2026-44970LowJul 16, 2026
    risk 0.13cvss 3.1epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DefaultUsageTracker.emit_tool_called_event() in src/dbt_mcp/tracking/tracking.py serialized every MCP tool call's complete arguments dictionary and sent it through…

  • CVE-2026-44969LowJul 16, 2026
    risk 0.16cvss 2.5epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, DbtMCP.call_tool() in src/dbt_mcp/mcp/server.py logged the raw arguments dictionary at INFO level before each tool call and at ERROR level on exceptions, and configure_file_logging() wrote…

  • CVE-2026-44968MedJul 16, 2026
    risk 0.41cvss 6.3epss 0.00

    dbt-mcp is a Model Context Protocol server for interacting with dbt. Prior to 1.17.1, _run_dbt_command() in src/dbt_mcp/dbt_cli/tools.py appended unsanitized node_selection and resource_type values to the dbt subprocess argument list, allowing an MCP client to inject dbt global…

  • CVE-2026-15945MedJul 16, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw was found in the group search functionality of the Keycloak server's administrative API. When Fine-Grained Admin Permissions (FGAP) v2 is enabled, a delegated administrator can bypass access restrictions to view parent groups they are not authorized to see. By searching…

  • CVE-2026-15737MedJul 16, 2026
    risk 0.00cvss 5.7epss 0.00

    AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore platform. Unintended logging of sensitive user content in the OpenTelemetry instrumentation in AWS Bedrock AgentCore Python SDK…

  • CVE-2021-27137HigKEVJul 16, 2026
    risk 0.65cvss 8.1epss 0.04

    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable…

  • CVE-2026-9046HigJul 16, 2026
    risk 0.00cvss 7.0epss 0.00

    A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.

  • CVE-2026-6511MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.

  • CVE-2026-63088HigJul 16, 2026
    risk 0.00cvss 8.6epss 0.01

    stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only…

  • CVE-2026-63087CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.01

    Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sending a POST request to the internal plugin install endpoint using hardcoded default stack_id and org_id values present in the…

  • CVE-2026-63086HigJul 16, 2026
    risk 0.00cvss 8.6epss 0.00

    text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by…

  • CVE-2026-63085HigJul 16, 2026
    risk 0.00cvss 8.8epss 0.01

    Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate privileges by exploiting unenforced field restrictions on nested relational save operations. Attackers can modify sensitive User…

  • CVE-2026-57074CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated…

  • CVE-2026-57073CriJul 16, 2026
    risk 0.52cvss 9.1epss 0.01

    HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter strings such as "<![CDATA" or element terminators such as ">" without checking that the offsets are within the buffer. Truncated…

  • CVE-2026-55548MedJul 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, the PacketsApi.exportPackets endpoint in yamcs-core/src/main/java/org/yamcs/http/api/PacketsApi.java failed to enforce object-level ReadPacket privileges when a request omitted specific packet names: with an empty…

  • CVE-2026-55407MedJul 16, 2026
    risk 0.34cvss —epss 0.01

    Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.8.0, the decode_unknown_field function in buffa's protobuf decoder allocated heap memory in proportion to untrusted input (unknown fields in the serialized protobuf)…

  • CVE-2026-55406MedJul 16, 2026
    risk 0.31cvss —epss 0.00

    Buffa is a pure-Rust Protocol Buffers implementation with first-class protobuf editions support. Prior to 0.7.0, a soundness bug in the OwnedView type allowed safe Rust code to trigger a use-after-free: the OwnedView::decode constructor transmuted a borrowed slice to &'static…

  • CVE-2026-50012MedJul 16, 2026
    risk 0.36cvss 5.5epss 0.03

    Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in src/peer_digest.cc), Squid is vulnerable to a heap-based buffer overflow: a cache digest's on-the-wire size may be larger than the…

  • CVE-2026-47751MedJul 16, 2026
    risk 0.28cvss —epss 0.01

    Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to 1.0.74, because the action checked out attacker-controlled pull request head branches, read .mcp.json from the working directory via default setting sources,…

  • CVE-2026-47729MedJul 16, 2026
    risk 0.42cvss 6.5epss 0.02

    Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing…

  • CVE-2026-46621CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated user-controlled algorithm text using Jython through the JSR-223 ScriptEngine API without enforcing a secure sandbox, so an…

  • CVE-2026-46562CriJul 16, 2026
    risk 0.64cvss 9.8epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-core/src/main/java/org/yamcs/algorithms/ScriptAlgorithmExecutorFactory.java was constructed without a ClassFilter, so a user with the…

  • CVE-2026-45795MedJul 16, 2026
    risk 0.27cvss 5.3epss 0.00

    The Janssen Project is an open-source identity and access management (IAM) platform. Prior to 2.0.0, jans-auth-server accepts unsigned JWE request objects because JwtAuthorizationRequest skips inner signature validation when jwe.getSignedJWTPayload() returns null, and…

  • CVE-2026-45612MedJul 16, 2026
    risk 0.29cvss 5.5epss 0.00

    rz-libdemangle is a Rizin library for demangling symbols. Prior to 6bf56d3, the Rust demangler in src/rust/rust_v0.c can perform an out-of-bounds read when the demangler structure is not yet initialized. This issue is fixed in commit 6bf56d3.

  • CVE-2026-45576HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    zrok is software for sharing web services, files, and network resources. From 0.4.23 until 2.0.3, `zrok2 copy` stores attacker-controlled WebDAV or zrok drive paths such as /../outside.txt in the source inventory and passes them to FilesystemTarget.WriteStream, allowing the sync…

  • CVE-2026-45568CriJul 16, 2026
    risk 0.52cvss 9.1epss 0.01

    zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an absolute URL in the request path and passes it to urllib.parse.urljoin, allowing the requested path to replace the configured target…

  • CVE-2026-45367HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations…

  • CVE-2026-45325HigJul 16, 2026
    risk 0.46cvss 8.2epss 0.00

    Gestor de Oferta is a web application for managing mobility service offerings. Prior to 20260509.0340.15, @tmlmobilidade/utils has a prototype pollution vulnerability in setValueAtPath() in packages/utils/src/generic/value-at-path.ts because unsafe path segments are not blocked.…

  • CVE-2026-44632CriJul 16, 2026
    risk 0.59cvss 9.1epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine org.yamcs.algorithms.JavaExprAlgorithmExecutionFactory, which dynamically compiled and evaluated user-controlled algorithm text…

  • CVE-2026-44596MedJul 16, 2026
    risk 0.45cvss 6.5epss 0.02

    Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/java/org/yamcs/http/auth/AuthHandler.java, lacked any rate limiting, account lockout, or failed-attempt throttling, so an…

  • CVE-2026-44595MedJul 16, 2026
    risk 0.31cvss 4.3epss 0.01

    Yamcs is a mission control framework. Prior to 5.12.7, the IAM API endpoints listUsers, getUser, listGroups, and getGroup in yamcs-core did not enforce the required SystemPrivilege.ControlAccess check in yamcs-core/src/main/java/org/yamcs/http/api/IamApi.java, so any…

  • CVE-2026-3031CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.01

    Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated in 2004. Epeg is a fast JPEG thumbnail library that was once part of the Englightenment Project.

  • CVE-2026-14371HigJul 16, 2026
    risk 0.00cvss —epss 0.01

    The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.

  • CVE-2026-13401HigJul 16, 2026
    risk 0.49cvss 7.5epss 0.00

    XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as "" or…

  • CVE-2026-13397HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes. The parserc_parse function never advances the attribute-parse state cursor on certain malformed attribute forms, looping forever. Nameless attributes such as ""…

  • CVE-2026-13104HigJul 16, 2026
    risk 0.00cvss 7.3epss 0.00

    A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.

  • CVE-2026-13103HigJul 16, 2026
    risk 0.00cvss 7.3epss 0.00

    A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.

  • CVE-2026-10590MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.