VYPR

Oss

by Geo Chen

Source repositories

CVEs (26)

  • CVE-2026-65696MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters.…

  • CVE-2026-65695MedJul 23, 2026
    risk 0.00cvss 6.8epss 0.00

    Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers…

  • CVE-2026-65056HigJul 21, 2026
    risk 0.00cvss 8.2epss 0.00

    mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering…

  • CVE-2026-63108HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.02

    Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts…

  • CVE-2026-63101HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.01

    Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV…

  • CVE-2026-63086HigJul 16, 2026
    risk 0.00cvss 8.6epss 0.00

    text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by…

Page 2 of 2