VYPR

CVEs

373,809 total · page 18 of 7,477

  • CVE-2026-14566MedSep 11, 2026
    risk 0.28cvss 4.3epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before updating WooCommerce order item metadata for a supplied order, allowing any authenticated user such as a subscriber to tamper with the custom metadata…

  • CVE-2026-14565MedSep 11, 2026
    risk 0.35cvss 5.4epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not perform any capability, ownership, or nonce check before saving popup configuration to a product, nor escape the stored values on output, allowing any authenticated user such as a subscriber to store…

  • CVE-2026-14563CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The advanced-customized-prompts WordPress plugin through 1.0.1 does not verify the password before issuing an authenticated session for a supplied email address in an unauthenticated action, allowing unauthenticated attackers to log in as any registered user, including…

  • CVE-2026-14562MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not perform any authorization or ownership checks before returning WooCommerce order metadata and the URLs of customer-uploaded attachments, allowing unauthenticated attackers to disclose other customers' order…

  • CVE-2026-14560CriSep 11, 2026
    risk 0.65cvss 10.0epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied content type and preserving the original filename, allowing unauthenticated attackers to upload arbitrary PHP files and execute code on the…

  • CVE-2026-14559CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.00

    The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not verify a user's password before authenticating them, allowing unauthenticated attackers to log in as any registered user, including administrators, by supplying only that user's email address.

  • CVE-2026-13326MedSep 11, 2026
    risk 0.45cvss epss 0.00

    An out-of-bounds read in Qt NFC's language code length parsing allows a physically proximate attacker to cause a denial of service or limited memory disclosure via a crafted NFC tag.

  • CVE-2025-15695LowSep 11, 2026
    risk 0.23cvss 3.5epss 0.00

    The Translate WordPress with GTranslate WordPress plugin before 3.0.10 does not validate one of its settings before the bundled front-end scripts build markup from it, allowing users with a role as high as administrator to store JavaScript that runs in the session of any visitor…

  • CVE-2026-89169MedSep 11, 2026
    risk 0.27cvss epss 0.00

    live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.

  • CVE-2026-89162LowSep 11, 2026
    risk 0.12cvss 2.9epss 0.00

    In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available to the adversary is already unsafe.

  • CVE-2026-89060HigSep 11, 2026
    risk 0.43cvss 7.7epss 0.00

    A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed cluster’s ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those…

  • CVE-2026-8778CriSep 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The MIPL Grouped Checkout Fields for WooCommerce – Customize & Organize Checkout Fields. plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the `mipl_wc_upload_file` function in all versions up to, and including, 1.2.1. This…

  • CVE-2026-89161HigSep 11, 2026
    risk 0.41cvss 7.4epss 0.00

    In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied subject being passed in as a context. An incorrect free operation can occur.

  • CVE-2026-89160LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCRE2_MATCH_INVALID_UTF matching of an invalid UTF subject.

  • CVE-2026-89158MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 integer overflow and resultant out-of-bounds write.

  • CVE-2026-89157MedSep 11, 2026
    risk 0.30cvss 5.7epss 0.00

    PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert out-of-bounds write when an attacker can provide a large pattern.

  • CVE-2026-89156LowSep 11, 2026
    risk 0.12cvss 2.9epss 0.00

    PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fallback when an attacker can provide invalid UTF data.

  • CVE-2026-84960MedSep 11, 2026
    risk 0.40cvss 6.1epss 0.00

    The WP-Members Membership Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Query String in all versions up to, and including, 3.5.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers…

  • CVE-2026-81825HigSep 11, 2026
    risk 0.47cvss 7.2epss 0.00

    The Simple Ajax Chat – Add a Fast, Secure Chat Box plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Chat Message in all versions up to, and including, <= 20260811 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-81754HigSep 11, 2026
    risk 0.47cvss 7.2epss 0.00

    The Vigilant – 100% Free Security Suite: Firewall, 2FA, Login, Headers, Scanner… plugin for WordPress is vulnerable to Stored Cross-Site Scripting via User-Agent Header in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping.…

  • CVE-2026-7438MedSep 11, 2026
    risk 0.42cvss 6.4epss 0.00

    The Bold Timeline Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `supertitle` and `subtitle` attributes of the `bold_timeline_item` shortcode in all versions up to, and including, 1.2.8 due to insufficient input sanitization and output escaping on…

  • CVE-2026-78172MedSep 11, 2026
    risk 0.40cvss 6.1epss 0.00

    The Themify – WooCommerce Product Filter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via Query Parameter Name in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-77150MedSep 11, 2026
    risk 0.33cvss 6.1epss 0.00

    The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'data[name]' Parameter in all versions up to, and including, 2.0.16 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-19991HigSep 11, 2026
    risk 0.46cvss 8.1epss 0.00

    The UsersWP plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 1.2.70 via the upload_file_remove() AJAX handler. The plugin stores the value of an account 'file' form field taken directly from $_POST when no real $_FILES upload is…

  • CVE-2026-19985MedSep 11, 2026
    risk 0.40cvss 6.1epss 0.00

    The Relevanssi – A Better Search plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 4.28.1 via the 's', 'post_types', and 'orderby' request parameters. This is due to insufficient input sanitization and output escaping in the…

  • CVE-2026-18964MedSep 11, 2026
    risk 0.40cvss 6.1epss 0.00

    The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 3.5.9 due to insufficient input…

  • CVE-2026-18579HigSep 11, 2026
    risk 0.47cvss 7.2epss 0.00

    The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'HTTP_X_FORWARDED_FOR' parameter in all versions up to, and including, 9.2.08.003 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-18562MedSep 11, 2026
    risk 0.40cvss 6.1epss 0.00

    The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via SEO-friendly permalink filter URL segments in versions up to, and including, 1.4.3. This is due to insufficient input sanitization and output…

  • CVE-2026-18561HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    The Unlimited Elements For Elementor plugin for WordPress is vulnerable to SQL Injection via the 'addontype' parameter in versions up to, and including, 2.0.16. This is due to insufficient escaping on the user-supplied parameter and the lack of sufficient preparation on the…

  • CVE-2026-15462HigSep 11, 2026
    risk 0.49cvss 7.5epss 0.00

    The Sticky Chat Widget plugin for WordPress is vulnerable to SQL Injection via the 'scw_form_fields' parameter array keys of the 'scw_save_form_data' AJAX action in versions up to, and including, 1.4.2. This is due to the save_form_data() function passing attacker-controlled…

  • CVE-2026-12215MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Authentication Bypass via OTP Brute Force in all versions up to, and including, 2.7.2. The vulnerability exists because the OTP rate-limit attempt counter in `process_otp_form` is keyed exclusively on the…

  • CVE-2026-11496MedSep 11, 2026
    risk 0.42cvss 6.5epss 0.00

    The Woo PDF Invoice Builder plugin (also distributed as "PDF Builder for WooCommerce") for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.0.8. This is due to the InspectOrder() AJAX handler…

  • CVE-2026-11446MedSep 11, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booktics – Booking Calendar for Appointments and Service Businesses plugin for WordPress is vulnerable to unauthorized modification of data in all versions up to, and including, 1.0.23. This is due to the create_order_permission() permission callback on the POST…

  • CVE-2026-89151LowSep 11, 2026
    risk 0.23cvss 3.5epss 0.00

    Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

  • CVE-2026-88260HigSep 11, 2026
    risk 0.57cvss epss 0.00

    Authentication bypass using an alternate path or channel and Improper validation of syntactic correctness of input vulnerability in Brainzcompany Zenius EMS 8.0 allows Remote Code Inclusion. This issue affects Zenius EMS 8.0: through OAM (Build 109).

  • CVE-2026-78135MedSep 11, 2026
    risk 0.29cvss 5.6epss 0.00

    libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

  • CVE-2026-89145MedSep 11, 2026
    risk 0.20cvss 4.2epss 0.00

    Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can create a plugin with HTML characters in its name to…

  • CVE-2026-89092MedSep 11, 2026
    risk 0.27cvss 4.2epss 0.00

    The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled…

  • CVE-2026-88914MedSep 11, 2026
    risk 0.29cvss 4.4epss 0.00

    A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an…

  • CVE-2026-78134HigSep 11, 2026
    risk 0.39cvss 7.1epss 0.00

    strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

  • CVE-2026-78133HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

  • CVE-2026-78132HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

  • CVE-2026-78131LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

  • CVE-2026-78130HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

  • CVE-2026-78129MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

  • CVE-2026-78127LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

  • CVE-2026-78126MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

  • CVE-2026-78124LowSep 11, 2026
    risk 0.17cvss 3.7epss 0.00

    strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

  • CVE-2026-78123MedSep 11, 2026
    risk 0.31cvss 5.9epss 0.00

    strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

  • CVE-2026-84941MedSep 11, 2026
    risk 0.45cvss epss 0.00

    An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful…