VYPR
Vendor

Pawelmalak

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2023-23277MedApr 11, 2023
    risk 0.40cvss 6.1epss 0.01

    Snippet-box 1.0.0 is vulnerable to Cross Site Scripting (XSS). Remote attackers can render arbitrary web script or HTML from the "Snippet code" form field.

  • CVE-2026-100501MedSep 25, 2026
    risk 0.35cvss 6.5epss 0.00

    Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api/auth login endpoint that allows unauthenticated attackers to brute-force the admin password. Attackers can submit unlimited password guesses without rate…

  • CVE-2026-100418MedSep 25, 2026
    risk 0.27cvss 5.3epss 0.00

    Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that returns the entire configuration object without field redaction. Attackers can retrieve the stored weather API key and internal operational settings by sending…

  • CVE-2026-100502MedSep 25, 2026
    risk 0.26cvss 5.0epss 0.00

    Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attackers with former admin access to obtain tokens with arbitrary lifespans by supplying unvalidated duration parameters. Attackers can mint near-permanent…