VYPR

CVEs

378,357 total · page 88 of 7,568

  • CVE-2026-86830HigSep 14, 2026
    risk 0.47cvss 7.2epss 0.00

    Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby…

  • CVE-2026-82519MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allows authenticated low-privileged attackers to bypass enforced two-factor authentication indefinitely by exploiting an unguarded code path in the profile-page…

  • CVE-2026-82049HigSep 14, 2026
    risk 0.48cvss epss 0.00

    In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives containing a hard link to a symbolic link. Such archives may cause extraction to modify the permissions or modification time of a file outside the destination…

  • CVE-2026-82035HigSep 14, 2026
    risk 0.39cvss 7.1epss 0.00

    PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output…

  • CVE-2026-77884HigSep 14, 2026
    risk 0.46cvss epss 0.00

    Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The server listens on TCP port 8080 and serves files and directory listings from Android external storage.

  • CVE-2026-59178CriSep 14, 2026
    risk 0.57cvss 9.8epss 0.00

    ESPHome Device Builder Dashboard is a dashboard for the ESPHome home management software. Prior to version 1.0.12, the dashboard reads its authentication credentials from `$ESPHOME_USERNAME` and `$ESPHOME_PASSWORD`. Earlier versions, and the legacy `esphome` dashboard, read the…

  • CVE-2026-19543MedSep 14, 2026
    risk 0.40cvss 6.2epss 0.00

    IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input validation exclusively on the client side and fails to enforce the same restrictions on the server side. An attacker can modify requests to bypass validation…

  • CVE-2026-18515MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Navigator for i when they should be blocked by Navigator configuration. This could allow attackers to upload files onto the system to places the Navigator support…

  • CVE-2026-18151MedSep 14, 2026
    risk 0.27cvss 4.2epss 0.00

    IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition during the WebSocket handshake process.

  • CVE-2026-15893MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_reachable = 3*base/2 using integer…

  • CVE-2013-1446Sep 14, 2026
    risk 0.00cvss epss

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Was assigned for an old issue in the brltty daemon and never published completely.

  • CVE-2026-91081MedSep 14, 2026
    risk 0.31cvss 5.8epss 0.00

    Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous attackers to make outbound requests by providing a public document UUID. Attackers can exploit DNS time-of-check-time-of-use race conditions and shared…

  • CVE-2026-91080HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.01

    webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticated attackers to exhaust memory by sending oversized bodies. Attackers can send multi-gigabyte request bodies with invalid signatures to trigger out-of-memory…

  • CVE-2026-91079HigSep 14, 2026
    risk 0.55cvss 8.5epss 0.00

    Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing hostname allowlist validation. Authenticated workspace members can supply arbitrary URLs to the print endpoint, which Puppeteer renders and returns as…

  • CVE-2026-91021MedSep 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges…

  • CVE-2026-90946HigSep 14, 2026
    risk 0.49cvss 7.5epss 0.01

    DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported…

  • CVE-2026-90945CriSep 14, 2026
    risk 0.64cvss 9.8epss 0.01

    Crawlab through 0.6.3 uses a hard-coded HMAC-SHA256 secret for JWT token signing that cannot be overridden via configuration or environment variables. Unauthenticated attackers can forge valid administrator tokens to access administrative APIs and execute code on worker nodes.

  • CVE-2026-90944HigSep 14, 2026
    risk 0.53cvss 8.2epss 0.01

    Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to…

  • CVE-2026-90942CriSep 14, 2026
    risk 0.62cvss 9.6epss 0.00

    Casdoor through 4.4.0 fails to properly mask the instance-wide built-in certificate private key in /api/get-certs and /api/get-cert endpoints, allowing organization administrators to retrieve it. Attackers can use the exposed private key to forge JWT tokens for any user in any…

  • CVE-2026-90807MedSep 14, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the file src/modules/agent-to-agent/agent-route.ts of the component Attachment Handler. The manipulation results in link following. The attack may be performed…

  • CVE-2026-90806MedSep 14, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCasesView of the file backend/cases/bulk_views.py of the component Bulk Case Update. The manipulation leads to missing authorization. The attack is possible to be…

  • CVE-2026-90805HigSep 14, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be…

  • CVE-2026-86836HigSep 14, 2026
    risk 0.48cvss epss 0.00

    In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path…

  • CVE-2026-85921HigSep 14, 2026
    risk 0.53cvss 8.2epss 0.00

    Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

  • CVE-2026-85892HigSep 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

  • CVE-2026-73494HigSep 14, 2026
    risk 0.41cvss 7.4epss 0.00

    blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze…

  • CVE-2026-70658HigSep 14, 2026
    risk 0.41cvss 7.4epss 0.01

    Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid_signature? in app/controllers/pay/webhooks/paddle_billing_controller.rb compares the computed 64-character SHA-256 HMAC with the attacker-controlled h1 token…

  • CVE-2026-57583LowSep 14, 2026
    risk 0.14cvss 3.3epss 0.00

    OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts. Prior to @openzeppelin/wizard 0.10.11, @openzeppelin/wizard-cairo 3.0.1, @openzeppelin/wizard-stellar 0.6.2, and @openzeppelin/wizard-stylus 0.3.1,…

  • CVE-2026-57581MedSep 14, 2026
    risk 0.27cvss 5.3epss 0.00

    DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applications with configured file upload storage allow unauthenticated users to submit files directly to DotvvmFileUploadMiddleware without an X-DotVVM-UploadToken…

  • CVE-2026-57578CriSep 14, 2026
    risk 0.53cvss epss 0.00

    DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, AuthorizeActionFilter performs no authorization because its explicit ICommandActionFilter.OnCommandExecutingAsync, IViewModelActionFilter.OnViewModelCreatedAsync,…

  • CVE-2026-57577HigSep 14, 2026
    risk 0.46cvss epss 0.00

    DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtracking in DotvvmRoute.IsMatch when a remote…

  • CVE-2026-57570MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.15 and 7.0.47, HasMany and MorphMany handling through attachManyRelation during CRUD…

  • CVE-2026-55866LowSep 14, 2026
    risk 0.17cvss 3.7epss 0.00

    SpiceDB is an open source database system for creating and managing security-critical application permissions. From 1.34.0 until 1.54.0, SpiceDB can return PERMISSIONSHIP_HAS_PERMISSION instead of PERMISSIONSHIP_CONDITIONAL_PERMISSION or PERMISSIONSHIP_NO_PERMISSION because…

  • CVE-2026-55847MedSep 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js helper at allure-generator/src/main/javascript/helpers/ansi.js passes attacker-influenced statusMessage and statusTrace values through AnsiToHtml without HTML…

  • CVE-2026-55846MedSep 14, 2026
    risk 0.33cvss 6.2epss 0.00

    Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP server started by allure serve and allure open uses URI.getPath() in Commands.setUpServer() in allure-commandline/src/main/java/io/qameta/allure/Commands.java and…

  • CVE-2026-55832MedSep 14, 2026
    risk 0.33cvss 6.1epss 0.00

    Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tensor.rs get_external_resources and joins the…

  • CVE-2026-55253HigSep 14, 2026
    risk 0.43cvss 7.7epss 0.00

    LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-mongodb 0.3.0 and langgraph-store-mongodb 0.4.0, MongoDBSaver.list(), MongoDBSaver.alist(), and MongoDBStore.search() incorporate filter dictionaries into…

  • CVE-2026-55091HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.00

    flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.prototype.convert in index.js uses attacker-influenced id and parent record fields directly as keys in the plain temp and pendingChildOf objects. When parent…

  • CVE-2026-54723MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a server configured with the primary or deprecated master role allows an unauthenticated, modified GET request to the +changelog route because verify_primary…

  • CVE-2026-54567HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before…

  • CVE-2026-54182HigSep 14, 2026
    risk 0.46cvss 8.1epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached…

  • CVE-2026-54181MedSep 14, 2026
    risk 0.28cvss 5.4epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, src/resources/views/crud/columns/color.blade.php inverts the escaped and…

  • CVE-2026-54180HigSep 14, 2026
    risk 0.42cvss 7.6epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder operations resolve records from the…

  • CVE-2026-54178HigSep 14, 2026
    risk 0.46cvss 8.1epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in…

  • CVE-2026-54177MedSep 14, 2026
    risk 0.36cvss 6.6epss 0.01

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, HasUploadFields methods uploadFileToDisk and uploadMultipleFilesToDisk,…

  • CVE-2026-54176MedSep 14, 2026
    risk 0.35cvss 6.5epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, MyAccountController::postAccountInfoForm at POST /admin/edit-account-info…

  • CVE-2026-54175HigSep 14, 2026
    risk 0.42cvss 7.6epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm in src/app/Http/Controllers/MyAccountContr…

  • CVE-2026-54150MedSep 14, 2026
    risk 0.38cvss epss 0.00

    next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/utils.ts isRemote() treats any value…

  • CVE-2026-54087HigSep 14, 2026
    risk 0.42cvss 7.6epss 0.00

    EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline same-origin rendering without a download…

  • CVE-2026-53752HigSep 14, 2026
    risk 0.42cvss 7.5epss 0.00

    docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX files. Prior to 11.5.14, PropertyResolver and adjacent helpers recursively follow the WordprocessingML w:basedOn style inheritance chain without cycle…