VYPR

CVEs

381,349 total · page 235 of 7,627

  • CVE-2026-86159HigSep 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be…

  • CVE-2026-75816CriSep 6, 2026
    risk 0.57cvss 9.8epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership check, and…

  • CVE-2026-18056HigSep 6, 2026
    risk 0.42cvss 7.5epss 0.00

    The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by…

  • CVE-2026-16310CriSep 6, 2026
    risk 0.64cvss 9.8epss 0.00

    The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the…

  • CVE-2026-86153CriSep 6, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.

  • CVE-2026-86152CriSep 6, 2026
    risk 0.65cvss 10.0epss 0.03

    A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attack may be launched remotely.

  • CVE-2026-86151CriSep 6, 2026
    risk 0.59cvss 9.1epss 0.03

    A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. The attack may be initiated remotely.

  • CVE-2026-86150MedSep 5, 2026
    risk 0.27cvss 4.1epss 0.00

    A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been…

  • CVE-2026-76161Sep 5, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-76160Sep 5, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-86149CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.03

    A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.

  • CVE-2026-86148CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.03

    A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack…

  • CVE-2026-86206MedSep 5, 2026
    risk 0.45cvss —epss 0.01

    A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

  • CVE-2026-86060CriKEVSep 5, 2026
    risk 0.76cvss 9.8epss 0.02

    RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to…

  • CVE-2026-67281HigSep 5, 2026
    risk 0.49cvss 7.5epss 0.01

    RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving…

  • CVE-2026-67279MedKEVSep 5, 2026
    risk 0.54cvss 6.5epss 0.01

    RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling…

  • CVE-2026-67278CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.00

    MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS…

  • CVE-2026-67277HigKEVSep 5, 2026
    risk 0.65cvss 8.2epss 0.02

    RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet…

  • CVE-2026-67276HigSep 5, 2026
    risk 0.53cvss 8.1epss 0.06

    RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an…

  • CVE-2026-86207HigSep 5, 2026
    risk 0.50cvss —epss 0.01

    An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

  • CVE-2026-6554MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter program can cause the interpreter to loop…

  • CVE-2026-6244MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero.

  • CVE-2026-31912MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter…

  • CVE-2026-31911MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process.

  • CVE-2026-18313MedSep 5, 2026
    risk 0.21cvss 4.3epss 0.00

    rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially…

  • CVE-2026-18238MedSep 5, 2026
    risk 0.26cvss 5.0epss 0.00

    The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if…

  • CVE-2026-0799HigSep 5, 2026
    risk 0.50cvss 8.7epss 0.00

    In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause…

  • CVE-2026-82752MedSep 5, 2026
    risk 0.31cvss —epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's String.length/1, which counts Unicode…

  • CVE-2026-86197MedSep 5, 2026
    risk 0.26cvss —epss 0.00

    Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and addCss methods on Grav\Common\Assets without proper output escaping. Page editors can inject arbitrary script by registering malicious assets or injecting…

  • CVE-2026-86196HigSep 5, 2026
    risk 0.50cvss —epss 0.00

    Grav API plugin versions before 1.0.20 build password reset links from the untrusted Host header in the forgot-password endpoint, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can send password reset requests for any…

  • CVE-2026-86195HigSep 5, 2026
    risk 0.50cvss —epss 0.00

    grav-plugin-api versions before 1.0.20 contain a privilege escalation vulnerability in the InvitationsController where the stripSuperFlags() method only removes nested super flags but fails to strip dot-keyed equivalents like api.super. A non-super user manager with api.access…

  • CVE-2026-86194MedSep 5, 2026
    risk 0.45cvss —epss 0.01

    Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing anonymous visitors to execute form actions defined on login-restricted or unpublished pages. Attackers can POST to any public page with a restricted form's name…

  • CVE-2026-86193HigSep 5, 2026
    risk 0.50cvss —epss 0.00

    grav-plugin-api before 1.0.20 fails to validate group-inherited super permissions in user-management guards, allowing non-super user managers to modify super-admin accounts. Attackers with api.access and api.users.write can patch password fields on group-super accounts to gain…

  • CVE-2026-86192MedSep 5, 2026
    risk 0.35cvss 6.5epss 0.00

    SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible documents, exposing private database contents without…

  • CVE-2026-86191MedSep 5, 2026
    risk 0.21cvss 4.3epss 0.00

    SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying parent database visibility. Attackers can access the endpoint…

  • CVE-2026-86190CriSep 5, 2026
    risk 0.59cvss 9.1epss 0.00

    WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers when a hash parameter is provided. Attackers can use the…

  • CVE-2026-86189CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.01

    WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext…

  • CVE-2026-86188HigSep 5, 2026
    risk 0.47cvss 7.2epss 0.00

    AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attackers can send crafted socket messages with callback names…

  • CVE-2026-86187MedSep 5, 2026
    risk 0.38cvss 5.9epss 0.00

    WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in minutes through offline brute-force attacks due to unsalted…

  • CVE-2026-86186MedSep 5, 2026
    risk 0.42cvss 6.5epss 0.00

    AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bot User-Agent to disable rate limiting and perform unlimited…

  • CVE-2026-86185HigSep 5, 2026
    risk 0.52cvss 8.0epss 0.00

    Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept configuration fetches, inject arbitrary JavaScript executed…

  • CVE-2026-86184CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the GET /screenshot-login/{email} endpoint…

  • CVE-2026-15550MedSep 5, 2026
    risk 0.28cvss 4.3epss 0.00

    The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability checks and nonce verification in the 'bulk_actions' function. This makes it possible for authenticated…

  • CVE-2026-12843MedSep 5, 2026
    risk 0.35cvss 5.4epss 0.00

    The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to enroll arbitrary…

  • CVE-2026-10196CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle_form_submission' function. This…

  • CVE-2025-9049HigSep 5, 2026
    risk 0.57cvss 8.8epss 0.00

    The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_permissions' function in all versions up to, and including, 1.6.4. This makes it possible for…

  • CVE-2025-15647MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenerate constraint edges through geometry data…

  • CVE-2025-15614LowSep 5, 2026
    risk 0.14cvss 3.3epss 0.00

    ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files that cause the decompressor to read one byte past the allocated heap buffer, potentially crashing the…

  • CVE-2026-86178MedSep 5, 2026
    risk 0.28cvss 5.4epss 0.00

    Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only stories. Attackers can enumerate sequential story IDs and submit reactions or comments to retrieve story media…

  • CVE-2026-86177HigSep 5, 2026
    risk 0.50cvss 8.8epss 0.01

    Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute arbitrary console commands. Attackers can create and immediately trigger scheduled tasks that run…