VYPR

CVEs

373,801 total · page 17 of 7,477

  • CVE-2024-12145MedSep 11, 2026
    risk 0.21cvss 4.3epss 0.00

    The BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 14.3.3 via the bp_notifications_action_bulk_manage due to missing validation on a user controlled key. This makes it possible for authenticated attackers,…

  • CVE-2026-89147HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read without timeout on newly accepted connections. An unauthenticated remote client can connect to the SMUX listener and send no data,…

  • CVE-2026-89146HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    libp2p-rendezvous through 0.17.1 fails to validate registration TTL values in discovery responses, allowing attackers to trigger timer arithmetic overflow. A malicious rendezvous server can send a discovery response with an unbounded TTL value that causes the client node process…

  • CVE-2026-86813MedSep 11, 2026
    risk 0.31cvss 4.8epss 0.00

    The MetForm WordPress plugin before 4.1.9 does not properly neutralize newline characters in user-submitted values that are placed into notification email headers, allowing unauthenticated attackers to inject additional email headers, such as Bcc, into the emails the site sends…

  • CVE-2026-86809MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The Persian Elementor WordPress plugin from 2.7.10 before 2.8.2 does not verify that the payment authority returned to its ZarinPal payment callback belongs to the transaction being completed, allowing unauthenticated attackers to complete a pending order using a valid payment…

  • CVE-2026-85116MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The Simple CAPTCHA with Cloudflare Turnstile WordPress plugin from 1.2.2 before 1.42.3 runs the shortcode parser over the whole rendered Contact Form 7 form, including the values a visitor submitted, allowing unauthenticated users to execute arbitrary shortcodes registered on…

  • CVE-2026-82215MedSep 11, 2026
    risk 0.38cvss 5.9epss 0.00

    The Payment Gateway PayPay for WooCommerce WordPress plugin from 0.5 to 0.9.3 does not verify the authenticity of the payment notifications it receives before acting on them, allowing unauthenticated attackers who know the store's merchant identifier to mark arbitrary orders as…

  • CVE-2026-82213MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The Nexi XPay Build WordPress plugin from 7.6.1 to 7.6.2 does not verify that the saved payment token being requested belongs to the current user, allowing unauthenticated attackers to retrieve other customers' stored card token references together with a valid authorisation…

  • CVE-2026-77159MedSep 11, 2026
    risk 0.36cvss 5.5epss 0.00

    A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink,…

  • CVE-2026-87859MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan emits. An unauthenticated remote attacker…

  • CVE-2026-87123MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    hbs is an Express view engine wrapper for Handlebars. Version 4.3.0 can crash the Node.js process during output escaping when an async helper, registered with registerAsyncHelper, resolves to an object whose toHTML property is truthy but not callable. Handlebars escapeExpression…

  • CVE-2026-47839CriSep 11, 2026
    risk 0.60cvss epss 0.00

    A vulnerability allows users authenticating through a federated OIDC provider to obtain the uaa.admin scope despite operators restricting that provider through externalGroupsWhitelist configuration. The issue occurs specifically when an OIDC identity provider uses…

  • CVE-2026-17037HigSep 11, 2026
    risk 0.40cvss 7.2epss 0.00

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘comment’ parameter in all versions up to, and including, 6.2.0 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-87727MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerability, which allows an unauthenticated attacker to read or delete arbitrary files on the affected product.

  • CVE-2026-80469HigSep 11, 2026
    risk 0.54cvss 8.3epss 0.00

    An attacker may achieve arbitrary code execution on a target system by uploading a malicious device driver package, bypassing driver verification mechanisms, and triggering the execution of attacker-controlled code. User interaction is required.

  • CVE-2026-19486HigSep 11, 2026
    risk 0.57cvss epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability in Google Cloud Gemini Enterprise Agent Platform App Builder versions prior to 2026-06-01 on Google Cloud Platform allows an unauthenticated attacker to leak the Compute Engine default service account access token. This…

  • CVE-2025-15679HigSep 11, 2026
    risk 0.47cvss epss 0.00

    Under certain circumstances such as reset to factory default operation, the BMC root account is made active without a password on BullSequana XH3406 and XH3515.

  • CVE-2026-89179MedSep 11, 2026
    risk 0.28cvss 4.3epss 0.00

    WeenyGenius, a computer lab management system by Howyar Technologies, has a Missing Support for Integrity Check vulnerability. Unauthenticated attackers on the same network can intercept a student's connection packet and replay it, thereby forging the appearance that the student…

  • CVE-2026-89178HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    WeenyGenius, a computer lab management system by Howyar Technologies, has an Origin Validation Error vulnerability. Unauthenticated attackers on the same network can spoof the teacher workstation and send broadcast packets, causing student computers to attempt to establish a…

  • CVE-2026-89177HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    WeenyGenius, a computer lab management system by Howyar Technologies, has a Use of Insecure Protocol vulnerability. Due to the reliance on ZMTP Null mode, unauthenticated attackers on the same network can capture packets to leak transmitted data, or perform replay attacks with…

  • CVE-2026-89176HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same network can easily spoof student or teacher endpoints. Impersonating a student can disrupt normal classroom…

  • CVE-2026-89175MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values.

  • CVE-2026-89174HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts.

  • CVE-2026-89173MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.

  • CVE-2026-6642MedSep 11, 2026
    risk 0.35cvss 6.4epss 0.00

    The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bulk edit preset export/import mechanism in versions up to and including 3.35. This is due to insufficient output escaping on preset field values when they are rendered in HTML…

  • CVE-2026-6641MedSep 11, 2026
    risk 0.35cvss 6.4epss 0.00

    The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to and including 3.35. This is due to insufficient input sanitization and output escaping on the mla_link_href parameter when mla_output…

  • CVE-2026-6640MedSep 11, 2026
    risk 0.35cvss 6.4epss 0.00

    The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_link_attributes' parameter in all versions up to, and including, 3.35 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-87908HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can…

  • CVE-2026-86815MedSep 11, 2026
    risk 0.36cvss 5.5epss 0.00

    The BackWPup WordPress plugin before 5.7.5 does not properly restrict access to several of its REST API routes for job, backup-destination, and backup-execution management, allowing users holding a BackWPup WordPress plugin before 5.7.5-defined, administrator-assigned limited…

  • CVE-2026-86812MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The WPCafe WordPress plugin before 3.0.18 does not correctly restrict access to a set of order-management REST endpoints because their permission callbacks return an incorrect type on failure, allowing unauthenticated users to disclose guest order information and to change the…

  • CVE-2026-86782MedSep 11, 2026
    risk 0.36cvss 5.5epss 0.00

    The Visualizer WordPress plugin before 4.0.6 does not properly authorise access to its chart-building actions, allowing users with the Contributor role and above to publish, rename, and overwrite the content of posts and pages they do not own, including other users' private…

  • CVE-2026-86781MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The SSL Zen — SSL Certificate Installer & HTTPS Redirects WordPress plugin before 4.7.40 does not perform capability or nonce checks on a certificate-file download routine that runs early in the WordPress admin request lifecycle, allowing any authenticated user, including…

  • CVE-2026-86780MedSep 11, 2026
    risk 0.44cvss 6.8epss 0.00

    The Featured Image with URL WordPress plugin before 1.0.6 does not sanitise and escape a stored image attribute value before outputting it, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks that execute in the browser of any…

  • CVE-2026-86779LowSep 11, 2026
    risk 0.18cvss 2.7epss 0.00

    The Visualizer WordPress plugin before 4.0.6 does not properly authorise chart-deletion requests, performing only a site-wide capability check with no per-object ownership verification, allowing users with the Contributor role and above to permanently delete any chart on the…

  • CVE-2026-85678MedSep 11, 2026
    risk 0.44cvss 6.8epss 0.00

    The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of…

  • CVE-2026-85677HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    The Gutenverse News WordPress plugin before 3.3.3 does not restrict the extra HTML it adds to WordPress's allowed elements to the context it is meant for, applying the same relaxed list to every sanitisation context including untrusted comments, allowing unauthenticated users…

  • CVE-2026-83546MedSep 11, 2026
    risk 0.44cvss 6.8epss 0.00

    The CoolClock WordPress plugin before 4.3.8 does not properly escape a skin setting before outputting it within an HTML attribute, allowing users with contributor-level access and above to inject arbitrary web scripts that execute when the content is viewed.

  • CVE-2026-83545MedSep 11, 2026
    risk 0.44cvss 6.8epss 0.00

    The CoolClock WordPress plugin before 4.3.8 does not properly escape a custom skin setting before outputting it inside an inline script, allowing users with contributor-level access and above to inject arbitrary JavaScript that executes when the content is viewed.

  • CVE-2026-82305MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The YITH WooCommerce Wishlist WordPress plugin before 4.18.1 does not verify that a user is authorised to rename a given wishlist, allowing unauthenticated users to rename any wishlist on the site.

  • CVE-2026-74925HigSep 11, 2026
    risk 0.47cvss 7.2epss 0.00

    The MultiVendorX WordPress plugin before 5.0.16 does not restrict who can update its role and capability settings, allowing users holding its vendor role to grant that role administrator-level capabilities and take over the site.

  • CVE-2026-73785HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).

  • CVE-2026-73784HigSep 11, 2026
    risk 0.57cvss 8.8epss 0.00

    A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.

  • CVE-2026-14566MedSep 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata…

  • CVE-2026-14565MedSep 11, 2026
    risk 0.35cvss 5.4epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store…

  • CVE-2026-14563CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including…

  • CVE-2026-14562MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order…

  • CVE-2026-14560CriSep 11, 2026
    risk 0.65cvss 10.0epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the…

  • CVE-2026-14559CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.

  • CVE-2026-13326MedSep 11, 2026
    risk 0.45cvss epss 0.00

    An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

  • CVE-2025-15695LowSep 11, 2026
    risk 0.23cvss 3.5epss 0.00

    The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor…