VYPR

Vendor CVEs

Geo Chen

All CVEs

65 total · sorted by risk
  • CVE-2025-2341LowMar 16, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in IROAD Dash Cam X5 up to 20250203. It has been rated as problematic. This issue affects some unknown processing of the component SSID. The manipulation leads to use of default credentials. The attack needs to be initiated within the local network. The…

  • CVE-2025-2555LowMar 20, 2025
    risk 0.19cvss 2.9epss 0.00

    A vulnerability classified as problematic has been found in Audi Universal Traffic Recorder App 2.0. Affected is an unknown function of the component FTP Credentials. The manipulation leads to use of hard-coded password. Attacking locally is a requirement. The complexity of an…

  • CVE-2025-1879LowMar 3, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic. This issue affects some unknown processing of the component APK. The manipulation leads to hard-coded credentials. It is possible to launch the attack on the physical device. It was…

  • CVE-2025-2119LowMar 9, 2025
    risk 0.13cvss 2.0epss 0.00

    A vulnerability was found in Thinkware Car Dashcam F800 Pro up to 20250226. It has been declared as problematic. This vulnerability affects unknown code of the component Device Registration Handler. The manipulation leads to use of default credentials. It is possible to launch…

  • CVE-2026-65702HigJul 23, 2026
    risk 0.00cvss 8.6epss 0.01

    Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated remote attackers to write attacker-controlled JSON files to arbitrary filesystem locations and read conversation metadata from…

  • CVE-2026-65701CriJul 23, 2026
    risk 0.00cvss 9.1epss 0.01

    SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote attackers to read and exfiltrate arbitrary files by supplying attacker-controlled filesystem paths through the…

  • CVE-2026-65700CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.02

    h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The…

  • CVE-2026-65699MedJul 23, 2026
    risk 0.00cvss 4.2epss 0.00

    AgentGPT through 1.0.0 contains an authorization bypass through user-controlled key vulnerability that allows authenticated users to attach tasks to another user's agent run by supplying a target run_id in the request body without ownership verification. The…

  • CVE-2026-65697MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attackers to inject a javascript: URI into the Top Pages dashboard by supplying a crafted hostname and pathname to the unauthenticated…

  • CVE-2026-65696MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters.…

  • CVE-2026-65695MedJul 23, 2026
    risk 0.00cvss 6.8epss 0.00

    Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filename argument to read arbitrary .docx files or create and overwrite .docx files outside the intended working directory. Attackers…

  • CVE-2026-65056HigJul 21, 2026
    risk 0.00cvss 8.2epss 0.00

    mcp-webresearch 0.1.7 contains a server-side request forgery vulnerability that allows attackers to access internal network services by supplying loopback, link-local, or cloud metadata addresses to the visit_page tool, which only validates the URL protocol without filtering…

  • CVE-2026-63108HigJul 20, 2026
    risk 0.00cvss 8.8epss 0.02

    Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/denylist enforcement by nesting command substitutions inside parameter expansion defaults. The command parser in parse-command.ts…

  • CVE-2026-63101HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.01

    Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member roster of any group, including email addresses, names, join dates, and roles, by submitting requests to the group followers CSV…

  • CVE-2026-63086HigJul 16, 2026
    risk 0.00cvss 8.6epss 0.00

    text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completions endpoint that allows unauthenticated network attackers to coerce the server into issuing arbitrary HTTP GET requests by…

Page 2 of 2