VYPR

CVEs

37,964 total · page 108 of 760

  • CVE-2026-35293CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-35292CriJun 17, 2026
    risk 0.65cvss 10.0epss 0.01

    Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-35286CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-35285CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-35284CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-35283CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-35282CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-35281CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-35280CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via…

  • CVE-2026-35278CriJun 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…

  • CVE-2026-35270CriJun 17, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to…

  • CVE-2026-35268CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise…

  • CVE-2026-35263CriJun 17, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic…

  • CVE-2026-48777CriJun 16, 2026
    risk 0.53cvss —epss 0.01

    FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields…

  • CVE-2026-22313CriJun 16, 2026
    risk 0.59cvss 9.1epss 0.01

    The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by…

  • CVE-2026-0126CriJun 16, 2026
    risk 0.64cvss 9.8epss 0.00

    In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2026-53776CriJun 16, 2026
    risk 0.52cvss 9.1epss 0.01

    Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a…

  • CVE-2025-13036CriJun 16, 2026
    risk 0.60cvss —epss 0.00

    An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.

  • CVE-2026-12316CriJun 16, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

  • CVE-2026-12315CriJun 16, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12304CriJun 16, 2026
    risk 0.59cvss 9.1epss 0.00

    Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12297CriJun 16, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12296CriJun 16, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12295CriJun 16, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12294CriJun 16, 2026
    risk 0.62cvss 9.6epss 0.00

    Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

  • CVE-2026-12293CriJun 16, 2026
    risk 0.64cvss 9.8epss 0.00

    Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.

  • CVE-2026-40750CriJun 16, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This issue affects Kids Online Store: from n/a through 0.8.9.

  • CVE-2026-52715CriJun 16, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions.

  • CVE-2026-49774CriJun 16, 2026
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.

  • CVE-2026-49772CriJun 16, 2026
    risk 0.53cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allows Blind SQL Injection. This issue affects The Events Calendar: from 6.15.12 through 6.16.2.

  • CVE-2026-39574CriJun 16, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions.

  • CVE-2026-48853CriJun 15, 2026
    risk 0.53cvss —epss 0.01

    Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via atom table exhaustion and, when a decoded term flows into a call site that invokes it,…

  • CVE-2026-12205CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later…

  • CVE-2026-48714CriJun 15, 2026
    risk 0.52cvss 9.1epss 0.01

    i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see…

  • CVE-2026-48713CriJun 15, 2026
    risk 0.52cvss 9.1epss 0.01

    Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key…

  • CVE-2026-12087CriJun 15, 2026
    risk 0.52cvss 9.1epss 0.00

    Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both…

  • CVE-2026-11832CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which is predictable.

  • CVE-2026-9691CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.

  • CVE-2026-52703CriJun 15, 2026
    risk 0.62cvss 9.6epss 0.01

    Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.

  • CVE-2026-52693CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions.

  • CVE-2026-49781CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions.

  • CVE-2026-49776CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions.

  • CVE-2026-49770CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions.

  • CVE-2026-49769CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions.

  • CVE-2026-49768CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions.

  • CVE-2026-49766CriJun 15, 2026
    risk 0.64cvss 9.9epss 0.01

    Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions.

  • CVE-2026-49765CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions.

  • CVE-2026-49764CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions.

  • CVE-2026-49763CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions.

  • CVE-2026-49109CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions.