VYPR
Vendor

Stanford

Products
5
CVEs
11
Across products
11
Status
Private

Products

5

Recent CVEs

11
  • CVE-2023-39020CriJul 28, 2023
    risk 0.57cvss 9.8epss 0.01

    stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2021-44550CriFeb 24, 2022
    risk 0.57cvss 9.8epss 0.01

    An Incorrect Access Control vulnerability exists in CoreNLP 4.3.2 via the classifier in NERServlet.java (lines 158 and 159).

  • CVE-2022-0239CriJan 17, 2022
    risk 0.57cvss 9.8epss 0.01

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2021-3878CriOct 15, 2021
    risk 0.57cvss 9.8epss 0.02

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2026-72742HigAug 11, 2026
    risk 0.49cvss 8.6epss 0.00

    DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attackers with influence over language model outputs to read arbitrary local files by injecting a filesystem path into the url field of a parsed Image or Audio typed…

  • CVE-2013-2106HigDec 3, 2019
    risk 0.49cvss 7.5epss 0.02

    webauth before 4.6.1 has authentication credential disclosure

  • CVE-2026-54499HigJul 8, 2026
    risk 0.42cvss 7.5epss 0.00

    Stanza is a Stanford NLP Python library for tokenization, sentence segmentation, NER, and parsing of many human languages. Prior to 1.12.2, Stanza model loaders such as stanza.models.common.pretrain.Pretrain.load() attempt torch.load(..., weights_only=True) but fall back to…

  • CVE-2021-3869HigOct 19, 2021
    risk 0.42cvss 7.5epss 0.01

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2022-0198HigJan 13, 2022
    risk 0.39cvss 7.1epss 0.01

    corenlp is vulnerable to Improper Restriction of XML External Entity Reference

  • CVE-2025-12695MedNov 4, 2025
    risk 0.38cvss 5.9epss 0.00

    The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.

  • CVE-2009-2945Sep 15, 2009
    risk 0.00cvss epss 0.01

    weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by…