VYPR

CVEs

378,628 total · page 197 of 7,573

  • CVE-2026-85242MedSep 3, 2026
    risk 0.38cvss —epss 0.00

    PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application validates the initial favicon URL to prevent requests to localhost, loopback, or other non-public network…

  • CVE-2026-85186MedSep 3, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument…

  • CVE-2026-84849MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.

  • CVE-2026-84848HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.

  • CVE-2026-84847HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.

  • CVE-2026-84836HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Insecure Direct Object References (IDOR) in WC Ukraine Shipping <= 1.22.3 versions.

  • CVE-2026-84834CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions.

  • CVE-2026-84814CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.

  • CVE-2026-84813CriSep 3, 2026
    risk 0.53cvss 9.3epss 0.00

    Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions.

  • CVE-2026-84812HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.27 versions.

  • CVE-2026-84779HigSep 3, 2026
    risk 0.53cvss 8.1epss 0.00

    Subscriber Broken Access Control in Agentimus – AI SEO, llms.txt & MCP for AI Agents <= 1.51.0 versions.

  • CVE-2026-84778HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Denial of Service Attack in Migrate Guru – Site Migration & Cloning <= 6.65 versions.

  • CVE-2026-84777HigSep 3, 2026
    risk 0.41cvss 7.4epss 0.00

    Unauthenticated Broken Authentication in Really Simple SSL <= 9.8.0 versions.

  • CVE-2026-84776HigSep 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Denial of Service Attack in MalCare Security <= 6.69 versions.

  • CVE-2026-84774MedSep 3, 2026
    risk 0.33cvss 6.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.

  • CVE-2026-84773HigSep 3, 2026
    risk 0.47cvss 7.2epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in EWWW Image Optimizer <= 8.7.6 versions.

  • CVE-2026-84769MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.

  • CVE-2026-84768CriSep 3, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions.

  • CVE-2026-84767MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.

  • CVE-2026-84766MedSep 3, 2026
    risk 0.38cvss 5.9epss 0.00

    Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.

  • CVE-2026-84765HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Breadcrumb NavXT <= 7.5.1 versions.

  • CVE-2026-84763HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in RTMKit <= 2.1.5 versions.

  • CVE-2026-84762MedSep 3, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.

  • CVE-2026-84761HigSep 3, 2026
    risk 0.47cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.

  • CVE-2026-84758MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.

  • CVE-2026-84757HigSep 3, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Settings Change in WP Compress <= 7.21.28 versions.

  • CVE-2026-84756HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.

  • CVE-2026-84755MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.

  • CVE-2026-84754MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.

  • CVE-2026-84753CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

  • CVE-2026-84752HigSep 3, 2026
    risk 0.57cvss 8.8epss 0.00

    Contributor PHP Object Injection in RTMKit <= 2.1.5 versions.

  • CVE-2026-84736HigSep 3, 2026
    risk 0.47cvss —epss 0.00

    In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or…

  • CVE-2026-84238CriSep 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

  • CVE-2026-84215MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.

  • CVE-2026-81776HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.

  • CVE-2026-81773HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

  • CVE-2026-81300HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Calculation For Contact Form 7 <= 1.0 versions.

  • CVE-2026-81295HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Under Construction <= 5.82 versions.

  • CVE-2026-81292HigSep 3, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Simple Payment <= 2.5.1 versions.

  • CVE-2026-81282MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.

  • CVE-2026-81281MedSep 3, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.

  • CVE-2026-75602MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a per-task temporary directory before…

  • CVE-2026-85239MedSep 3, 2026
    risk 0.35cvss 6.5epss 0.00

    A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template definition field. The EventTemplate::beforeValidate() method only performed semantic validation when the…

  • CVE-2026-85238MedSep 3, 2026
    risk 0.37cvss 6.8epss 0.00

    MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth, MISP stored the authenticated user identity in the existing session without first rotating the session…

  • CVE-2026-85237HigSep 3, 2026
    risk 0.46cvss 8.1epss 0.00

    A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The email_otp() endpoint did not apply brute-force protection when validating submitted OTP values. An attacker…

  • CVE-2026-85236HigSep 3, 2026
    risk 0.50cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while accepting HTTP GET requests. Because bodyless GET requests are not subject to CakePHP's CSRF validation, an…

  • CVE-2026-85138HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SeaCMS up to 13.6. Affected is the function addslashes of the file weixin/index.php of the component WeChat Module. The manipulation of the argument Content results in sql injection. The attack may be launched remotely. The exploit is now public…

  • CVE-2026-85137HigSep 3, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SeaCMS up to 13.6. This impacts the function parseIf of the file seacms_locoy_news.php of the component Locoy Collector. The manipulation of the argument pwd leads to code injection. The attack may be initiated remotely. The exploit…

  • CVE-2026-84967MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticated remote unauthorized-user who persuades…

  • CVE-2026-84966MedSep 3, 2026
    risk 0.33cvss 5.1epss 0.00

    An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an application supplies an extremely large, non-terminated field name to the builder, the library may read memory…