VYPR

CVEs

373,797 total · page 15 of 7,476

  • CVE-2026-62102HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.

  • CVE-2026-62089HigSep 11, 2026
    risk 0.46cvss 7.1epss 0.00

    Missing Authorization vulnerability in Pixar Labs Master Addons for Elementor allows Privilege Abuse. This issue affects Master Addons for Elementor: from n/a through 3.2.2.

  • CVE-2026-62088MedSep 11, 2026
    risk 0.27cvss 5.3epss 0.00

    Insertion of Sensitive Information Into Sent Data vulnerability in 10up ElasticPress allows Retrieve Embedded Sensitive Data. This issue affects ElasticPress: from n/a through 5.3.4.

  • CVE-2026-54072CriSep 11, 2026
    risk 0.53cvss 9.3epss 0.00

    Authorizer is an open-source, self-hostable authentication and authorization server. Prior to version 2.2.1, the `/authorize` endpoint accepts any `redirect_uri` without validating it against `AllowedOrigins`. When `response_type=token` or `response_type=id_token`, the server…

  • CVE-2026-27378MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.

  • CVE-2025-69904Sep 11, 2026
    risk 0.00cvss epss 0.00

    Linkstack v4.8.4 and earlier is vulnerable to Path Traversal, which allows an administrator to read arbitrary files on the server by manipulating file path input. Successful exploitation may lead to unauthorized access to sensitive system or application files.

  • CVE-2026-9160MedSep 11, 2026
    risk 0.28cvss 4.3epss 0.00

    Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website Template allows Code Injection. This issue affects Website Template: through 11092026. NOTE: The vendor was contacted early about this disclosure but did not…

  • CVE-2026-89099HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A race condition in the document value layer of MongoDB Server can allow concurrent server threads to operate on the same internal memory without synchronization, leading to memory corruption. An authenticated user holding ordinary read-write privileges on a database may be able…

  • CVE-2026-89090MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type…

  • CVE-2026-87910MedSep 11, 2026
    risk 0.30cvss epss 0.00

    When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archive. In this case, the filter function is run twice: once for the extracted member, and once with name set to the location of the link. For one of the calls,…

  • CVE-2026-82617CriSep 11, 2026
    risk 0.65cvss epss 0.00

    The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and DEFAULT_REGEX_NAME_FINDER.URL - contain ambiguous nested quantifiers. An application that obtains these finders through…

  • CVE-2026-82535MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious script payloads into survey answers by computing deterministic invitation codes and bypassing authorization checks in the survey…

  • CVE-2026-81909MedSep 11, 2026
    risk 0.31cvss epss 0.00

    Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concrete/controllers/backend/block/process.php).It does not verify that the referenced block is genuinely orphaned on the target page, nor that the caller holds any…

  • CVE-2026-81908MedSep 11, 2026
    risk 0.39cvss epss 0.00

    Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The listGroups() method in concrete/src/Api/Controller/Groups.php registers a permissions checker callback that unconditionally returns true, so no per-object (tree…

  • CVE-2026-7298MedSep 11, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software Industry and Trade Inc. Smart E-Commerce allows Reflected XSS. This issue affects Smart E-Commerce: through 11092026. NOTE: The vendor was contacted early…

  • CVE-2026-78807HigSep 11, 2026
    risk 0.46cvss 7.1epss 0.00

    An issue in wpa_supplicant all versions before v.2.12 allows a local attacker to bypass proper network context and AKMP matching for PMKSA caching via missing validation in the driver based PMKSA selection path in wpa.c

  • CVE-2026-68528MedSep 11, 2026
    risk 0.32cvss epss 0.00

    Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting in stored cross-site scripting. An attacker able to control a title in a syndicated feed could execute script in the site origin for any visitor to the…

  • CVE-2026-67211Sep 11, 2026
    risk 0.00cvss epss 0.00

    OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP SymSpellModelSerializer Versions Affected: - 3.0.0-M4 - 3.0.0-M5 (The opennlp-spellcheck extension was introduced in 3.0.0-M4. Releases 1.x and 2.x do not contain the affected code.) Description: The…

  • CVE-2026-18495MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be…

  • CVE-2026-18122MedSep 11, 2026
    risk 0.32cvss epss 0.00

    Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization; the Concrete CMS REST API's Express entry collection endpoint disabled the per-entry view permission check. An OAuth token with read scope for an Express…

  • CVE-2026-72710CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    SPIP before 4.4.18 contains a remote code execution vulnerability in the editer_objet action where the arg parameter resolves SQL table names without enforcing an editable columns allowlist, allowing attackers with a valid nonce to inject attacker-controlled rows into the…

  • CVE-2026-72709CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    SPIP before 4.4.18 contains a missing authorization vulnerability in the administrative action endpoints under ecrire/action/ that allows unauthenticated attackers to perform privileged actions by supplying a valid HMAC-SHA256 nonce without any server-side permission check via…

  • CVE-2026-72708HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    SPIP before 4.4.18 contains an unauthenticated blind SQL injection vulnerability in the public sitemap endpoint where the MySQL escaper spip_mysql_cite() in ecrire/req/mysql.php returns values unescaped when the target column is a date type and the supplied value matches the…

  • CVE-2026-54047CriSep 11, 2026
    risk 0.53cvss epss 0.00

    Laci Synchroni is a decentralized mod and appearance sync server and plugin for Dalamud. Versions of the backend prior to 1.2.3 have an improper authentication vulnerability in the application's OAuth2 login flow. The application relies on client-side state by trusting the `UID`…

  • CVE-2026-18061MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached…

  • CVE-2026-8304MedSep 11, 2026
    risk 0.36cvss 5.5epss 0.00

    Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pardus About: from 1.2.1 before 1.2.5.

  • CVE-2026-89265MedSep 11, 2026
    risk 0.28cvss 4.3epss 0.00

    MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoint, which omits the @AuthorityVerify annotation required to enforce role-based permissions. Authenticated back-office users without image-category permissions…

  • CVE-2026-89264MedSep 11, 2026
    risk 0.28cvss 4.3epss 0.00

    MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authenticated users to post comments attributed to any other user. Attackers can supply arbitrary userUid values in the request body to impersonate other accounts…

  • CVE-2026-89263MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauthenticated attackers to disable email notifications for arbitrary users. Remote callers can modify the startEmailNotification flag in Redis cache for any user…

  • CVE-2026-89262HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment…

  • CVE-2026-89261MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication, allowing remote attackers to delete, recreate, or alter the blog search index. Attackers can invoke POST endpoints to wipe the entire search index, delete…

  • CVE-2026-89260HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or…

  • CVE-2026-89066HigSep 11, 2026
    risk 0.44cvss 7.8epss 0.00

    Improper neutralization of special elements used in an OS command in the task synthesis component in projen before 0.103.0 might allow context-dependent attackers to execute arbitrary commands on a developer workstation or continuous integration runner via shell metacharacters…

  • CVE-2026-89065HigSep 11, 2026
    risk 0.39cvss 7.1epss 0.00

    Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow context-dependent attackers to recursively delete files and directories outside the project directory that are writable by the environment running projen, via crafted…

  • CVE-2026-89013HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip…

  • CVE-2026-89012MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can…

  • CVE-2026-87122Sep 11, 2026
    risk 0.00cvss epss

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-85984. Reason: This candidate is a reservation duplicate of CVE-2026-85984. Notes: All CVE users should reference CVE-2026-85984 instead of this candidate. All references and descriptions in…

  • CVE-2026-81861MedSep 11, 2026
    risk 0.38cvss epss 0.00

    CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized access to RTU functionality.

  • CVE-2026-7863HigSep 11, 2026
    risk 0.55cvss 8.4epss 0.01

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Software allows OS Command Injection. This issue affects Pardus Software: before 1.0.5.

  • CVE-2026-70341HigSep 11, 2026
    risk 0.55cvss 8.5epss 0.01

    Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

  • CVE-2026-68497HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.01

    jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These…

  • CVE-2026-3869CriSep 11, 2026
    risk 0.60cvss epss 0.01

    CWE-303 : Incorrect Implementation of Authentication Algorithm vulnerability exists that could cause loss of confidentiality, integrity and availability of the PLC provided an application project with a lower application level is running on the PLC.

  • CVE-2026-15439MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of the wpForo integration AJAX selector (action gamipress_wpforo_get_posts) in versions up to, and including, 7.9.7. The value is passed only through…

  • CVE-2026-8303HigSep 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.

  • CVE-2026-8301HigSep 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair allows OS Command Injection. This issue affects Pardus Boot Repair: before 1.0.8.

  • CVE-2026-89010CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.03

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to the sync_server daemon on TCP port 13136.…

  • CVE-2026-89009CriSep 11, 2026
    risk 0.59cvss 9.1epss 0.01

    WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated arbitrary file write vulnerability that allows remote attackers to overwrite any file on the device by sending a crafted payload to the sync_server daemon on TCP port 13136.…

  • CVE-2026-87988CriSep 11, 2026
    risk 0.65cvss epss 0.00

    An arbitrary file access vulnerability in Mistral Vibe allows an attacker to bypass workspace restrictions through commands classified as unconditionally allowed. Missing path validation for these commands enables access to files outside the active workspace without user…

  • CVE-2026-87987CriSep 11, 2026
    risk 0.65cvss epss 0.00

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using environment variable assignments preceding allowlisted commands. These assignments are excluded from inspection, enabling attacker-controlled environment…

  • CVE-2026-87986CriSep 11, 2026
    risk 0.65cvss epss 0.00

    An arbitrary code execution vulnerability in Mistral Vibe allows an attacker to bypass command permission checks using shell constructs it's parser cannot interpret. Unparsed portions are omitted from inspection, enabling embedded commands to execute on the user's system without…