VYPR

CVEs

37,964 total · page 109 of 760

  • CVE-2026-49106CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions.

  • CVE-2026-49105CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in WP Zendesk for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

  • CVE-2026-49104CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.2.1 versions.

  • CVE-2026-49085CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in WP Insightly for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms <= 1.1.4 versions.

  • CVE-2026-49067CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Advanced 301 and 302 Redirect <= 1.6.9 versions.

  • CVE-2026-48886CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in JS Help Desk <= 3.0.9 versions.

  • CVE-2026-48881CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Broken Access Control in TrueBooker <= 1.1.9 versions.

  • CVE-2026-48836CriJun 15, 2026
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.

  • CVE-2026-45439CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.

  • CVE-2026-42665CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Data Access <= 5.5.70 versions.

  • CVE-2026-42639CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GD Rating System <= 3.6.2 versions.

  • CVE-2026-42386CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Order Delivery Date for WooCommerce <= 4.5.1 versions.

  • CVE-2026-42381CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Funnel Builder by FunnelKit <= 3.15.0.1 versions.

  • CVE-2026-40798CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in wpForo Forum <= 3.0.4 versions.

  • CVE-2026-40772CriJun 15, 2026
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated Arbitrary File Upload in GeekyBot <= 1.2.2 versions.

  • CVE-2026-40771CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Contest Gallery <= 28.1.6 versions.

  • CVE-2026-39591CriJun 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Subscriber Arbitrary File Upload in WP-BusinessDirectory <= 4.0.0 versions.

  • CVE-2026-39583CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Privilege Escalation in Datalogics Ecommerce Delivery <= 2.6.62 versions.

  • CVE-2026-39530CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in SpeakOut! Email Petitions <= 4.6.5 versions.

  • CVE-2026-39519CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GeekyBot <= 1.2.0 versions.

  • CVE-2026-39512CriJun 15, 2026
    risk 0.53cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GeoDirectory <= 2.8.152 versions.

  • CVE-2026-39511CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Photo Album Plus <= 9.1.08.001 versions.

  • CVE-2026-39502CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Form Maker by 10Web <= 1.15.38 versions.

  • CVE-2026-39493CriJun 15, 2026
    risk 0.53cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.9.27 versions.

  • CVE-2026-39492CriJun 15, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Maps <= 4.9.1 versions.

  • CVE-2026-39465CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.01

    Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.

  • CVE-2026-39441CriJun 15, 2026
    risk 0.53cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Feed KuantoKusta for WooCommerce – Free <= 5.3 versions.

  • CVE-2026-34901CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

  • CVE-2026-27053CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

  • CVE-2026-50890CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.

  • CVE-2026-50887CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.

  • CVE-2026-50886CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.

  • CVE-2026-50883CriJun 15, 2026
    risk 0.62cvss 9.6epss 0.01

    An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.

  • CVE-2026-50880CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.

  • CVE-2026-50873CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.

  • CVE-2026-50872CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request.

  • CVE-2026-50871CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.03

    An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

  • CVE-2026-50869CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

  • CVE-2026-49952CriJun 15, 2026
    risk 0.52cvss 9.1epss 0.04

    Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter…

  • CVE-2026-48114CriJun 15, 2026
    risk 0.57cvss 9.8epss 0.00

    Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegistration.dbInsert() builds an INSERT against…

  • CVE-2026-45390CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.01

    In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file…

  • CVE-2026-45389CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and…

  • CVE-2026-45388CriJun 15, 2026
    risk 0.59cvss 9.1epss 0.00

    In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server authentication (because of KeyUsage and ExtendedKeyUsage).

  • CVE-2026-39196CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to access sensitive database information via crafted SQL statements.

  • CVE-2026-39006CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

  • CVE-2026-38812CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.00

    RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.

  • CVE-2026-38329CriJun 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a…

  • CVE-2026-38065CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.02

    Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

  • CVE-2026-38064CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.02

    Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.

  • CVE-2026-38063CriJun 15, 2026
    risk 0.64cvss 9.8epss 0.02

    Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.