VYPR
Vendor

Gchq

Products
2
CVEs
7
Across products
7
Status
Private

Products

2

Recent CVEs

7
  • CVE-2018-1000651CriAug 20, 2018
    risk 0.65cvss 10.0epss 0.02

    Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of service, server side request forgery, port scanning. This attack appear to be exploitable via Specially crafted XML file.

  • CVE-2025-25182CriFeb 12, 2025
    risk 0.54cvss 9.4epss 0.01

    Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and prior to versions 7.2.24, 7.3-beta.22, 7.4.4, and 7.5-beta.2 that allows authentication bypass to a Stroom system when configured with ALB and installed in a…

  • CVE-2026-42615HigApr 29, 2026
    risk 0.40cvss 7.2epss 0.00

    GCHQ CyberChef before 11.0.0 allows XSS via Show Base64 offsets, as demonstrated by the /#recipe=Show_Base64_offsets('%3Cscript substring.

  • CVE-2019-10779MedJan 28, 2020
    risk 0.40cvss 6.1epss 0.01

    All versions of stroom:stroom-app before 5.5.12 and all versions of the 6.0.0 branch before 6.0.25 are affected by Cross-site Scripting. An attacker website is able to load the Stroom UI into a hidden iframe. Using that iframe, the attacker site can issue commands to the Stroom…

  • CVE-2019-15532MedAug 26, 2019
    risk 0.33cvss 6.1epss 0.01

    CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.

  • CVE-2026-72912MedAug 10, 2026
    risk 0.21cvss 4.3epss 0.00

    CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CPU when a malformed #recipe= URL fragment containing a large number of unmatched quote characters…

  • CVE-2026-57439MedJul 8, 2026
    risk 0.00cvss 5.0epss 0.00

    CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart operation accepts __proto__ as a key while parsing user-supplied CSV, allowing prototype pollution that can be chained with operations such as Parse UDP to inject…