VYPR

cve-search

by cve-search

CVEs (2)

  • CVE-2026-59509CriJul 5, 2026
    risk 0.00cvss epss 0.01

    An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate request parameters controlling the MongoDB collection, projected fields, and regular-expression filters to read arbitrary application…

  • CVE-2021-45470HigDec 23, 2021
    risk 0.00cvss 7.5epss 0.02

    lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.