VYPR
Vendor

Theopaid

Products
20
CVEs
19
Across products
22
Status
Private

Products

20

Recent CVEs

19
  • CVE-2026-70615CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in…

  • CVE-2026-66421CriJul 30, 2026
    risk 0.60cvss 9.3epss 0.01

    OpenClaw Dashboard contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to execute arbitrary JavaScript in the administrator's browser session by injecting HTML markup into agent transcript messages processed through the sessions API.…

  • CVE-2026-66418CriJul 30, 2026
    risk 0.60cvss 9.3epss 0.01

    OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log.…

  • CVE-2026-67182HigJul 28, 2026
    risk 0.49cvss 7.5epss 0.00

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare line feed characters (0x0A) into client-supplied request header values that are copied verbatim to upstream connections without…

  • CVE-2026-70616MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descriptors, goroutines, and memory by sending requests to the GET /loading endpoint with attacker-supplied id query parameter values.…

  • CVE-2026-66754MedJul 28, 2026
    risk 0.38cvss 5.9epss 0.00

    Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated attackers to crash the server by sending a crafted percent-encoded URL. Attackers can send a request whose decoded path matches a…

  • CVE-2026-67181MedJul 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by exploiting improper header forwarding in the proxy implementation. The proxy in src/proxy.rs forwards the client's…

  • CVE-2026-66752MedJul 28, 2026
    risk 0.35cvss 5.4epss 0.00

    tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a Transfer-Encoding header with any value, including non-chunked codings, which causes the library to unconditionally apply…

  • CVE-2026-66746MedJul 28, 2026
    risk 0.35cvss 5.4epss 0.00

    Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by embedding carriage return (0x0D) or line feed (0x0A) bytes into attacker-controlled input. Attackers can exploit percent-decoded…

  • CVE-2026-66753LowJul 28, 2026
    risk 0.24cvss 3.7epss 0.00

    tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return (0x0D) and line feed (0x0A) bytes into HTTP header values on both request and response sides due to insufficient validation in header parsing and…

  • CVE-2026-67185HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequences in the URL path, which are concatenated directly to the configured web root in HttpBuilder::buildResponse() without…

  • CVE-2026-67184HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sending a malformed HTTP request line with an invalid version string. The HttpParser::execute() function fails to allocate the Url…

  • CVE-2026-67183HigJul 28, 2026
    risk 0.00cvss 7.5epss 0.00

    TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well-formed HTTP requests. Each request causes HttpParser::execute() to allocate Url objects, HttpHeaders objects, and HttpHeader…

  • CVE-2026-66751MedJul 28, 2026
    risk 0.00cvss 5.4epss 0.00

    Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms…

  • CVE-2026-66750MedJul 28, 2026
    risk 0.00cvss 4.3epss 0.00

    Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval…

  • CVE-2026-66749MedJul 28, 2026
    risk 0.00cvss 6.5epss 0.00

    Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room parameter that matches no document in the database. Attackers can send a crafted GET /messages…

  • CVE-2026-66731HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a…

  • CVE-2026-66730HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The…

  • CVE-2026-66729HigJul 27, 2026
    risk 0.00cvss 7.5epss 0.01

    facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a…