VYPR

CVEs

378,628 total · page 218 of 7,573

  • CVE-2026-4560Aug 31, 2026
    risk 0.00cvss —epss —

    Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

  • CVE-2026-82957HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side…

  • CVE-2026-82954CriAug 31, 2026
    risk 0.57cvss 9.9epss 0.01

    A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the argument path results in path traversal. The attack can…

  • CVE-2026-82922HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2026-82921HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-82882HigAug 31, 2026
    risk 0.50cvss 8.8epss 0.00

    Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can query the endpoint with arbitrary project, environment, and…

  • CVE-2026-82398MedAug 31, 2026
    risk 0.38cvss —epss 0.00

    pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without whitespace. The function repeatedly…

  • CVE-2026-82397HigAug 31, 2026
    risk 0.42cvss 7.5epss 0.00

    Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses…

  • CVE-2026-82396MedAug 31, 2026
    risk 0.28cvss 5.4epss 0.00

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and its administration variant to honor the…

  • CVE-2026-82395MedAug 31, 2026
    risk 0.27cvss —epss 0.00

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual source collection, and…

  • CVE-2026-82394MedAug 31, 2026
    risk 0.27cvss —epss 0.00

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permission for the target resource…

  • CVE-2026-82393HigAug 31, 2026
    risk 0.42cvss 7.5epss 0.00

    pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the…

  • CVE-2026-77353MedAug 31, 2026
    risk 0.23cvss 4.6epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedding raw CRLF sequences in subscription names or notes.…

  • CVE-2026-77352MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP connections to internal/link-local addresses, by setting…

  • CVE-2026-77351LowAug 31, 2026
    risk 0.16cvss 3.5epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in their personal email notification settings, with no…

  • CVE-2026-77348HigAug 31, 2026
    risk 0.46cvss 8.2epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.php by disabling cURL proxying (CURLOPT_PROXY = '' +…

  • CVE-2026-83596HigAug 31, 2026
    risk 0.50cvss 8.8epss 0.00

    A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.

  • CVE-2026-82919HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. The attack may be performed from remote. The exploit is…

  • CVE-2026-82914HigAug 31, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2026-82909MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be…

  • CVE-2026-82908HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulation of the argument count/elementSize results in integer…

  • CVE-2026-82906LowAug 31, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulation causes missing authentication. Remote exploitation of the…

  • CVE-2026-82852MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in MapSVG <= 8.15.0 versions.

  • CVE-2026-82392HigAug 31, 2026
    risk 0.39cvss 7.1epss 0.00

    pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and…

  • CVE-2026-82346HigAug 31, 2026
    risk 0.46cvss —epss 0.00

    A potential security vulnerability has been identified in the HP ImageDiags for versions prior to 5.0.0.36. The vulnerability could potentially allow a local attacker to escalate privileges due to insufficient access controls.

  • CVE-2026-82229HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.

  • CVE-2026-82228HigAug 31, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Bypass Vulnerability in SiteGround Security <= 1.6.6 versions.

  • CVE-2026-82226CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Tickera <= 3.6.0.2 versions.

  • CVE-2026-82225HigAug 31, 2026
    risk 0.48cvss 7.4epss 0.00

    Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.9.8 versions.

  • CVE-2026-82224HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.

  • CVE-2026-82221HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.

  • CVE-2026-81892HigAug 31, 2026
    risk 0.46cvss 8.1epss 0.00

    EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuItem::linkToRoute()), swaps the executed…

  • CVE-2026-81891HigAug 31, 2026
    risk 0.46cvss 8.1epss 0.01

    elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar,…

  • CVE-2026-81890MedAug 31, 2026
    risk 0.28cvss 5.4epss 0.00

    elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing…

  • CVE-2026-81889HigAug 31, 2026
    risk 0.49cvss 8.6epss 0.00

    elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates…

  • CVE-2026-81888MedAug 31, 2026
    risk 0.28cvss 5.4epss 0.00

    @hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a callback that never came from a genuine…

  • CVE-2026-81887MedAug 31, 2026
    risk 0.26cvss —epss 0.01

    Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __proto__, constructor, and prototype path…

  • CVE-2026-81780CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.00

    Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

  • CVE-2026-81779CriAug 31, 2026
    risk 0.65cvss 10.0epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.

  • CVE-2026-81778MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Cross Site Scripting (XSS) in Kalles Addons <= 1.0.6 versions.

  • CVE-2026-81768HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.

  • CVE-2026-81765HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.

  • CVE-2026-81764HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.

  • CVE-2026-81763CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Throws SPAM Away <= 3.8.2 versions.

  • CVE-2026-81762MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Broken Access Control in Booking and Rental Manager <= 2.7.6 versions.

  • CVE-2026-81758MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    Subscriber Broken Access Control in OwnerRez API <= 1.2.6 versions.

  • CVE-2026-81756CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Smart Marketing SMS and Newsletters Forms <= 5.1.24 versions.

  • CVE-2026-81298HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.

  • CVE-2026-81297HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.

  • CVE-2026-81296HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Fluent Forms Pro Add On Pack <= 6.2.12 versions.