VYPR

CVEs

378,628 total · page 204 of 7,573

  • CVE-2026-66362HigSep 2, 2026
    risk 0.53cvss 8.1epss 0.00

    Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition…

  • CVE-2026-63020LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages  Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's…

  • CVE-2026-53611CriSep 2, 2026
    risk 0.57cvss 9.8epss 0.01

    Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit web UI, and a lg-cli client. Prior to…

  • CVE-2026-53600MedSep 2, 2026
    risk 0.34cvss —epss 0.00

    async-tar is a tar archive reading/writing library for async Rust. Prior to version 0.6.1, async-tar mis-applies a buffered PAX size extension to an intermediary extension header (a GNU longname L, a GNU longlink K, or a PAX x/g header) instead of to the next file entry. POSIX…

  • CVE-2026-19475MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory…

  • CVE-2026-18329HigSep 2, 2026
    risk 0.53cvss 8.2epss 0.00

    Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An…

  • CVE-2026-18058HigSep 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The mobile Smart Connect dashboard UI was subject to manipulation by 3rd party apps. When paired with a phishing attack, this manipulation could result in escalated privileges of an attacker within the system.

  • CVE-2026-14199HigSep 2, 2026
    risk 0.46cvss 7.1epss 0.00

    Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could…

  • CVE-2026-12704MedSep 2, 2026
    risk 0.44cvss 6.8epss 0.00

    When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated logins. This removes anti-replay protection, allowing an attacker who obtains a valid signed SAML assertion…

  • CVE-2026-8151MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Simple Membership MailChimp Integration WordPress plugin before 1.9.8 does not have CSRF checks in its settings page, allowing attackers to trick a logged-in administrator into changing the configured third-party API key. Once replaced, all subsequent member registration…

  • CVE-2026-83547MedSep 2, 2026
    risk 0.44cvss 6.8epss 0.00

    The Xpro Addons WordPress plugin before 1.7.4 does not properly escape some of its widgets' settings before outputting them within HTML attributes, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2026-83533MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Express Checkout WordPress plugin before 2.4.9 does not verify server-side that a payment was actually completed before marking an order as paid, allowing unauthenticated users to forge a completed order without paying.

  • CVE-2026-82955CriSep 2, 2026
    risk 0.52cvss —epss 0.00

    In the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API Gateway component had the disable_jwk_security parameter hard-coded to true, with no option to override it through the Helm chart…

  • CVE-2026-82884MedSep 2, 2026
    risk 0.44cvss 6.8epss 0.00

    The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise and escape some content stored in posts before rendering it back in the post editor, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks that trigger when…

  • CVE-2026-82293MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to unauthorized resource consumption via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user could invoke machine learning functionality beyond their…

  • CVE-2026-81571MedSep 2, 2026
    risk 0.31cvss 4.8epss 0.00

    The Brave WordPress plugin before 0.8.8 does not prevent a URL parameter used to pre-fill a form field from being passed to WordPress's shortcode engine, allowing unauthenticated attackers to have arbitrary shortcodes registered on the site executed server-side.

  • CVE-2026-79991HigSep 2, 2026
    risk 0.39cvss —epss 0.00

    Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed…

  • CVE-2026-79990HigSep 2, 2026
    risk 0.50cvss —epss 0.00

    Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed…

  • CVE-2026-79989HigSep 2, 2026
    risk 0.50cvss —epss 0.00

    The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which…

  • CVE-2026-78609MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized modification of data via Metadata Spoofing (CAPEC-690). An actor holding limited Kubernetes permissions confined to a single namespace could cause attacker-controlled certificate…

  • CVE-2026-78604HigSep 2, 2026
    risk 0.44cvss 7.8epss 0.00

    Incorrect Permission Assignment for Critical Resource (CWE-732) in Elastic Agent can lead to local privilege escalation via Replace Binaries (CAPEC-642). On Windows systems where Elastic Agent is installed in unprivileged mode, resources used by the agent service are created…

  • CVE-2026-78602MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in Elastic Maps Server can lead to information disclosure via Path Traversal (CAPEC-126). An unauthenticated attacker able to reach the service over the network could cause it to return the…

  • CVE-2026-78601MedSep 2, 2026
    risk 0.29cvss 5.5epss 0.00

    Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Privilege Abuse (CAPEC-122). An authorization control was not applied to a Kibana Entity Store configuration operation, allowing an authenticated user with elevated Kibana privileges to indirectly…

  • CVE-2026-78600LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, allowing a low-privileged tenant to…

  • CVE-2026-78599MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of internal resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet write access could cause a…

  • CVE-2026-78598MedSep 2, 2026
    risk 0.28cvss 5.4epss 0.00

    Incorrect Authorization (CWE-863) in the Kibana machine learning feature can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authenticated user holding machine learning job management privileges within a single…

  • CVE-2026-78594MedSep 2, 2026
    risk 0.25cvss 4.9epss 0.00

    Improper Handling of Highly Compressed Data (CWE-409) in APM Server can lead to a persistent denial of service via Excessive Allocation (CAPEC-130). An authenticated user with write access to source map content could store specially crafted, highly compressed content that…

  • CVE-2026-78591MedSep 2, 2026
    risk 0.34cvss 6.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of resources via Path Traversal (CAPEC-126). A low-privileged user could cause a subsequent action taken by a…

  • CVE-2026-78590HigSep 2, 2026
    risk 0.40cvss 7.3epss 0.00

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22) in the Kibana Fleet feature can lead to the unauthorized deletion of privileged resources via Path Traversal (CAPEC-126). A low-privileged user holding Fleet Settings write access could cause…

  • CVE-2026-78588MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Filebeat can lead to a denial of service via Excessive Allocation (CAPEC-130). An attacker able to reach the Filebeat HTTP ingestion endpoint could send specially crafted compressed requests that exhaust the…

  • CVE-2026-78587LowSep 2, 2026
    risk 0.20cvss 3.1epss 0.00

    Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privilege Abuse (CAPEC-122). Fleet Server does not correctly verify session ownership during multi-part data upload operations, allowing any authenticated agent to…

  • CVE-2026-78586MedSep 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user with low-level privileges could submit a specially crafted request that causes Kibana to consume an unbounded…

  • CVE-2026-78584MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Observable Response Discrepancy (CWE-204) in the Kibana Osquery feature can lead to information disclosure via Query System for Information (CAPEC-54). An authenticated user holding Osquery live-query privileges could determine whether a scheduled query identifier exists in a…

  • CVE-2026-78153MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Restrict User Access WordPress plugin before 2.8.1 does not normalise the REST API route before checking it against the routes its content protection covers, allowing unauthenticated users to bypass that protection and read restricted content and enumerate users.

  • CVE-2026-77794MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate a client-supplied quantity multiplier when calculating the total price of a paid registration, allowing unauthenticated users to register without paying and obtain an activated account holding the role the…

  • CVE-2026-77793MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.9 does not validate the total price of a paid registration server-side, allowing unauthenticated users to complete a paid registration without paying and obtain an activated account.

  • CVE-2026-77009CriSep 2, 2026
    risk 0.64cvss 9.9epss 0.00

    The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.

  • CVE-2026-4357CriSep 2, 2026
    risk 0.65cvss 10.0epss 0.00

    The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

  • CVE-2026-2811MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. This makes it possible for unauthenticated attackers to inject arbitrary HTTP headers.

  • CVE-2026-2688MedSep 2, 2026
    risk 0.42cvss 6.5epss 0.00

    The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks for this value to skip nonce validation entirely. This allows unauthenticated attackers to access…

  • CVE-2026-19698LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using them to build the CSS it outputs on the front end, allowing users with the Contributor role and above to inject arbitrary CSS into pages served to other users…

  • CVE-2026-17563MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The User Frontend WordPress plugin before 4.3.11 does not enforce its subscription-purchase requirement when processing frontend post submissions, only when rendering the form, allowing unauthenticated users to create and, depending on the form's configuration, immediately…

  • CVE-2026-14326LowSep 2, 2026
    risk 0.25cvss 3.8epss 0.00

    The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff role to modify, disable, or take over appointments belonging to other staff members.

  • CVE-2026-14255MedSep 2, 2026
    risk 0.36cvss 5.5epss 0.00

    A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.…

  • CVE-2026-10821MedSep 2, 2026
    risk 0.43cvss 6.6epss 0.01

    The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file when the file-based redirect mode is enabled, and the redirect-creation endpoint is reachable by users with…

  • CVE-2025-9314CriSep 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

  • CVE-2025-8945MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.

  • CVE-2025-15692LowSep 2, 2026
    risk 0.23cvss 3.5epss 0.00

    The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users with the Administrator role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2025-15490MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs

  • CVE-2025-15489MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content