VYPR

CVEs

378,628 total · page 193 of 7,573

  • CVE-2026-85525HigSep 4, 2026
    risk 0.41cvss 7.4epss 0.00

    Improper OCSP response validation in the Snowflake Python, Go, JDBC, and Node.js drivers allowed a revoked TLS certificate to be accepted as valid, because OCSP responses were not reliably bound to the certificate being validated and definitive verification failures were treated…

  • CVE-2026-85311MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: from n/a through 2.1.60.

  • CVE-2026-81665HigSep 4, 2026
    risk 0.42cvss 7.5epss 0.00

    A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send…

  • CVE-2026-81302HigSep 4, 2026
    risk 0.51cvss 7.8epss 0.00

    PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.

  • CVE-2026-57777HigSep 4, 2026
    risk 0.42cvss 7.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Automattic WooCommerce allows Blind SQL Injection. This issue affects WooCommerce: from n/a before 11.0.

  • CVE-2026-32480MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membership: from n/a through 2.11.11.

  • CVE-2026-27432MedSep 4, 2026
    risk 0.35cvss 5.4epss 0.00

    Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Rentals: from n/a before 3.16.0.

  • CVE-2026-15937MedSep 4, 2026
    risk 0.27cvss —epss 0.00

    Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against agent receiver endpoints in either direction, because the endpoints do not verify that the certificate was…

  • CVE-2026-85229MedSep 4, 2026
    risk 0.40cvss 6.1epss 0.00

    ** UNSUPPORTED WHEN ASSIGNED ** Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache SkyWalking Booster UI. This issue affects Apache SkyWalking UI : from 10.2.0 through 10.4.0. Users are recommended to upgrade to…

  • CVE-2026-85197HigSep 4, 2026
    risk 0.49cvss 7.6epss 0.00

    A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY…

  • CVE-2026-80190MedSep 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Apache Allura: stored XSS via SVN code repositories.  Git repositories are not known to be affected.  The vulnerability is likely mitigated via default CSP headers. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0,…

  • CVE-2026-6217MedSep 4, 2026
    risk 0.41cvss 6.3epss 0.00

    Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: through 3.5.1.

  • CVE-2026-85094HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.

  • CVE-2026-85085CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.00

    The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

  • CVE-2026-84146MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summary from a supplied product identifier, allowing unauthenticated visitors to retrieve the title, price,…

  • CVE-2026-84066LowSep 4, 2026
    risk 0.20cvss 3.1epss 0.00

    The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify that the requesting user owns the post being modified before writing uploaded file references to its metadata, allowing users with the subscriber role and above…

  • CVE-2026-82194MedSep 4, 2026
    risk 0.36cvss 5.5epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing administrators to delete arbitrary files on the server, including files outside the web root.

  • CVE-2026-82193MedSep 4, 2026
    risk 0.36cvss 5.5epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing administrators to write files of permitted types to arbitrary locations on the server and to overwrite existing…

  • CVE-2026-82186MedSep 4, 2026
    risk 0.27cvss 4.1epss 0.00

    The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator privileges to perform SQL injection attacks.

  • CVE-2026-81347MedSep 4, 2026
    risk 0.38cvss 5.9epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing unauthenticated attackers to delete index.php and .htaccess files outside the intended directory, including…

  • CVE-2026-81270HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Apache Allura: exposure of non-public information via search. This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • CVE-2026-80438MedSep 4, 2026
    risk 0.38cvss 5.9epss 0.00

    The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific capability as equivalent to full site administration, which allows any user granted that capability to read…

  • CVE-2026-80181CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • CVE-2026-80180MedSep 4, 2026
    risk 0.40cvss 6.1epss 0.00

    Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • CVE-2026-79632MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipients and subject from the request, allowing unauthenticated users to make the site send emails to arbitrary…

  • CVE-2026-79631MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing unauthenticated users to download customer order details and opt-in form submissions when logging is enabled.

  • CVE-2026-79630MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured for, allowing unauthenticated users to obtain any purchasable product at a discount intended for a different…

  • CVE-2026-74853MedSep 4, 2026
    risk 0.44cvss 6.8epss 0.00

    The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitrary files from the server, including files outside the web root. Only sites using the restricted…

  • CVE-2026-71216MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a redirect. That does not remove the exposure. The initial POST -- including the JSON body containing the routing…

  • CVE-2026-70403CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

  • CVE-2026-69657CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

  • CVE-2026-66840HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497). Sensitive system information may be leaked.

  • CVE-2026-62928CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

  • CVE-2026-19224HigSep 4, 2026
    risk 0.47cvss 7.2epss 0.00

    The Hummingbird Performance WordPress plugin before 3.21.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

  • CVE-2026-17517MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attackers to obtain the title and content of non-public posts, such as draft, pending, private and scheduled…

  • CVE-2026-16281HigSep 4, 2026
    risk 0.46cvss 7.1epss 0.00

    The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or attaches media, allowing any authenticated user, including a subscriber, to permanently delete attachments…

  • CVE-2026-15354CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling…

  • CVE-2025-15691MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying on a value supplied in the request instead, allowing unauthenticated attackers to create WordPress user…

  • CVE-2026-85509CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

  • CVE-2026-85508CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).

  • CVE-2026-85507CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).

  • CVE-2026-85506CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).

  • CVE-2026-85505HigSep 4, 2026
    risk 0.49cvss 7.5epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).

  • CVE-2026-85504CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.

  • CVE-2026-85409MedSep 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire Service. Such manipulation of the argument file_name leads to path traversal. The attack may be performed…

  • CVE-2026-85408MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations//events of the component Conversation Handler. This manipulation of the argument createdBy causes dynamically-determined object…

  • CVE-2026-85407MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations//events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The…

  • CVE-2026-11613CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the…

  • CVE-2026-85406LowSep 4, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the…

  • CVE-2026-85405LowSep 4, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAddAction.do. Executing a manipulation of the argument name/username can lead to cross site scripting. The attack may be launched remotely. The exploit has been…