VYPR

CVEs

378,628 total · page 219 of 7,573

  • CVE-2026-81293CriAug 31, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.

  • CVE-2026-81291HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.

  • CVE-2026-81290HigAug 31, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.

  • CVE-2026-81287HigAug 31, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in Charitable <= 1.8.12.1 versions.

  • CVE-2026-81280MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.

  • CVE-2026-81278MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Missing Authorization vulnerability in WPExperts Post SMTP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post SMTP: from 4.0.0 through beta.1.

  • CVE-2026-79483MedAug 31, 2026
    risk 0.27cvss 5.3epss 0.00

    FastGPT Community Edition 4.10.0 through 4.14.0 are vulnerable to a NoSQL injection in the POST /api/core/chat/getHistories endpoint. An unauthenticated attacker can inject malicious NoSQL operators via crafted JSON payloads to bypass authorization checks, resulting in…

  • CVE-2026-79408CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.01

    An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.

  • CVE-2026-79407HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    A path traversal vulnerability in the SPO extension of MetaGPT 0.8.1 allows an attacker to read arbitrary files via the FILE_NAME value used by set_file_name() and load_meta_data() in metagpt/ext/spo/utils/load.py. The vulnerable code joins the attacker-controlled FILE_NAME…

  • CVE-2026-75594HigAug 31, 2026
    risk 0.46cvss —epss 0.01

    Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated parent media directory. On nginx, PHP's…

  • CVE-2026-75592MedAug 31, 2026
    risk 0.38cvss —epss 0.00

    Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Kirby\Filesystem\Dir::realpath() and…

  • CVE-2026-75460MedAug 31, 2026
    risk 0.42cvss 6.5epss 0.00

    XueZhiSi Open Source Exam System <= 3.9.0 has a privilege escalation vulnerability in the teacher-end interface POST /api/teacher/user/page/list. The role parameter in UserPageRequestVM is fully controllable by the requester.

  • CVE-2026-75458HigAug 31, 2026
    risk 0.53cvss 8.1epss 0.00

    The teacher-end interface POST /api/teacher/user/delete/{id} in XueZhiSi Open Source Exam System <= 3.9.0 contains a vertical privilege escalatio vulnerability. This interface accepts a user ID and then executes getUserById(id), setDeleted(true), updateByIdFilter() in sequence,…

  • CVE-2026-71415HigAug 31, 2026
    risk 0.39cvss —epss 0.00

    Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Api\Upload::processChunk() persisted chunk…

  • CVE-2026-62993MedAug 31, 2026
    risk 0.38cvss —epss 0.00

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and src/FunctionHandler/Fetch.php used…

  • CVE-2026-61641HigAug 31, 2026
    risk 0.46cvss 8.1epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email claim alone, without verifying that the IdP marked that email…

  • CVE-2026-61640HigAug 31, 2026
    risk 0.48cvss —epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in curl_init() with zero SSRF filtering. Unlike logo/webhook URLs…

  • CVE-2026-61639HigAug 31, 2026
    risk 0.48cvss —epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads crafted zip with entry logos/../../endpoints/shell.php to…

  • CVE-2026-61638HigAug 31, 2026
    risk 0.46cvss —epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF validation. PHPMailer connects to attacker-supplied host:port.…

  • CVE-2026-54600HigAug 31, 2026
    risk 0.46cvss —epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured install), an unauthenticated attacker can replace the entire…

  • CVE-2026-54599HigAug 31, 2026
    risk 0.42cvss —epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback without comparing the incoming state against the session…

  • CVE-2026-54598HigAug 31, 2026
    risk 0.42cvss 7.5epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any unauthenticated attacker can trigger pending migration files against…

  • CVE-2026-54179MedAug 31, 2026
    risk 0.22cvss 4.4epss 0.00

    backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/SingleBase64Image.php methods…

  • CVE-2026-50199MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential for the authenticated user. As a result, a normal…

  • CVE-2026-50198MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID belonging to another user. The write is accepted, and later the…

  • CVE-2026-38577CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers to gain root access.

  • CVE-2025-63607MedAug 31, 2026
    risk 0.40cvss 6.1epss 0.00

    TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter verbatim into the rendered page, permitting execution of attacker-supplied JavaScript in users browser.

  • CVE-2026-82905MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in sdcb chats up to 1.12.0. This affects the function McpController of the file src/BE/web/Controllers/Users/Mcps/McpController.cs of the component fetch-tools Endpoint. The manipulation results in server-side request forgery. The attack may be…

  • CVE-2026-82835MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A weakness has been identified in caoqianming django-vue-admin 1.0. This vulnerability affects unknown code of the file /api/file/. Executing a manipulation of the argument file_id can lead to improper access controls. The attack can be executed remotely. The exploit has been…

  • CVE-2026-82834MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A security flaw has been discovered in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. This affects the function LabelList of the file /v1/projects/1/category-types of the…

  • CVE-2026-82833MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in Doccano Open Source Annotation Tools for Machine Learning Practitioners and Auto Labeling Pipeline Module to Annotate a Document Automatically up to 1.8.5. Affected by this issue is the function ExampleDetail of the file /v1/projects/1/examples/…

  • CVE-2026-81267MedAug 31, 2026
    risk 0.35cvss 5.4epss 0.00

    A malicious webpage could stall a popup's cross-origin navigation after commit, causing the address bar to display the destination origin while continuing to render attacker-controlled content. This vulnerability was fixed in Firefox for iOS 155.0.

  • CVE-2026-52730MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.3, missing Authorization in Module::settingsForm allows to view (not change) super admin-restricted module settings and leak the full module…

  • CVE-2026-51740CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the killProcess function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to terminate critical services via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51739MedAug 31, 2026
    risk 0.38cvss 5.9epss 0.00

    Incorrect access control in the CloudSrvVersionCheck function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger cloud update checks via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51738Aug 31, 2026
    risk 0.00cvss —epss 0.00

    Incorrect access control in the LoadDefSettings function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to reset the device configuration and reboot the device via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51737MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the clearTracerouteLog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase traceroute logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51736CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the clearSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to erase system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51735HigAug 31, 2026
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in the showSyslog function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to retrieve recent system logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51734CriAug 31, 2026
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in the informSlaveUpdate function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger mesh slave update coordination via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51733Aug 31, 2026
    risk 0.00cvss —epss 0.00

    Incorrect access control in the FirmwareUpgrade function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51732MedAug 31, 2026
    risk 0.34cvss 5.3epss 0.00

    Incorrect access control in the delWiFiScheduleCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi schedule entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51731CriAug 31, 2026
    risk 0.59cvss 9.1epss 0.00

    Incorrect access control in the delVlanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove VLAN entries via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-14697MedAug 31, 2026
    risk 0.35cvss 6.5epss 0.00

    net_ipv6_send_ns() in subsys/net/ip/ipv6_nbr.c allocates a transmit net_pkt for a Neighbor Solicitation. When it is called with a data packet pending on an unresolved neighbor and that neighbor's pending_queue is already non-empty (an NS is already outstanding), the function…

  • CVE-2026-13732HigAug 31, 2026
    risk 0.46cvss 7.0epss 0.00

    A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to…

  • CVE-2026-83589impAug 31, 2026
    risk 0.40cvss 6.1epss —

    oauth-proxy: Open Redirect via /\ and /\t Bypass in Post-Login Redirect

  • CVE-2026-83497HigAug 31, 2026
    risk 0.57cvss 8.8epss 0.01

    Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with basic read/search permissions to execute arbitrary code on the server by sending a crafted cursor parameter to the plugins/sql…

  • CVE-2026-82821MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was determined in FLVMeta up to 1.2.2. Affected by this vulnerability is the function amf_object_get of the file src/amf.c of the component AMF Object Parsing. This manipulation causes null pointer dereference. The attack may be initiated remotely. The exploit…

  • CVE-2026-82820MedAug 31, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was found in FLVMeta up to 1.2.2. Affected is the function amf_string_new of the file src/amf.c of the component AMF String Processing. The manipulation of the argument length results in heap-based buffer overflow. The attack can be launched remotely. The exploit…

  • CVE-2026-82818MedAug 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in dibo-software diboot 3.8.0. This affects an unknown part of the file /api/iam/tenant/resource of the component Tenant Resource Assignment Handler. Executing a manipulation of the argument tenantId can lead to improper access controls. The attack…