VYPR

CVEs

381,724 total · page 245 of 7,635

  • CVE-2026-86145HigSep 5, 2026
    risk 0.46cvss 8.2epss 0.00

    PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write because reuse of a cached workspace block, in a recursive DFA matching workspace, lacks a size check (even though a newly allocated block, for the same purpose, does have a size check). This outcome requires an…

  • CVE-2026-83628MedSep 5, 2026
    risk 0.21cvss 4.3epss 0.00

    The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup`…

  • CVE-2026-83627CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written…

  • CVE-2026-77263HigSep 5, 2026
    risk 0.40cvss 7.2epss 0.00

    The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 3.13.4 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-77233HigSep 5, 2026
    risk 0.40cvss 7.2epss 0.01

    The iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via AdSense Regex Rewrite in all versions up to, and including, 3.13.4 due to insufficient input sanitization and…

  • CVE-2026-18404MedSep 5, 2026
    risk 0.42cvss 6.4epss 0.00

    The Social Chat – Click To Chat App Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'consent_message' JSON Attribute in .qlwapp data-box in all versions up to, and including, 8.6.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-13447CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates…

  • CVE-2025-14945MedSep 5, 2026
    risk 0.28cvss 5.4epss 0.00

    The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up to, and including, 7.3.3. This is due to insufficient input sanitization when storing attribute values…

  • CVE-2026-86144MedSep 5, 2026
    risk 0.29cvss 5.6epss 0.00

    In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external…

  • CVE-2026-86143MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that…

  • CVE-2026-86142MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

  • CVE-2026-86141LowSep 5, 2026
    risk 0.12cvss 2.9epss 0.00

    xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

  • CVE-2026-86140HigSep 5, 2026
    risk 0.45cvss 8.0epss 0.00

    In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

  • CVE-2026-86139MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

  • CVE-2026-86138MedSep 5, 2026
    risk 0.38cvss 6.9epss 0.00

    In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

  • CVE-2026-86137LowSep 5, 2026
    risk 0.12cvss 2.9epss 0.00

    In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

  • CVE-2026-86100MedSep 5, 2026
    risk 0.35cvss 6.4epss 0.00

    Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side…

  • CVE-2026-52777CriSep 5, 2026
    risk 0.54cvss —epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

  • CVE-2026-52775HigSep 5, 2026
    risk 0.50cvss 8.8epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id}…

  • CVE-2026-52774MedSep 5, 2026
    risk 0.33cvss 6.1epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quotes, an attacker can break out of the attribute value,…

  • CVE-2026-52773MedSep 5, 2026
    risk 0.33cvss 6.1epss 0.01

    YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. Because MySQL coerces malformed DATETIME strings, an…

  • CVE-2026-52772MedSep 5, 2026
    risk 0.29cvss 5.5epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders. This issue has been patched in version 4.6.6.

  • CVE-2026-52771HigSep 5, 2026
    risk 0.47cvss 8.3epss 0.01

    YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag is attacker-controlled —…

  • CVE-2026-52770HigSep 5, 2026
    risk 0.42cvss 7.5epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose value structure is numeric, YesWiki escapes the…

  • CVE-2026-52769HigSep 5, 2026
    risk 0.47cvss 8.3epss 0.00

    YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route - exposed publicly with acl:"public" - accepts an HTTP Signature header whose keyId parameter is a URL. HttpSignatureService::verifySignature()…

  • CVE-2026-52767HigSep 5, 2026
    risk 0.46cvss 8.2epss 0.00

    YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation - if (!openssl_verify(...)) { throw ... }. PHP's openssl_verify has four…

  • CVE-2026-52766CriSep 5, 2026
    risk 0.52cvss 9.1epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in…

  • CVE-2026-52763MedSep 5, 2026
    risk 0.35cvss 6.5epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form against ['day','week','month']. The action-argument form…

  • CVE-2026-52762HigSep 5, 2026
    risk 0.39cvss —epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki Bazar contains a stored Server-Side Template Injection (SSTI) vulnerability in the semantic template feature that can be escalated to confirmed Remote Code Execution (RCE). An authenticated administrator…

  • CVE-2026-86098HigSep 4, 2026
    risk 0.41cvss 7.4epss 0.01

    ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted network packet data including TLS SNI, HTTP headers,…

  • CVE-2026-86097MedSep 4, 2026
    risk 0.35cvss 6.5epss 0.00

    PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'param select' or 'param select-backup' commands with no…

  • CVE-2026-86096MedSep 4, 2026
    risk 0.31cvss 5.9epss 0.00

    PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via shell commands to write to freed heap memory, corrupting…

  • CVE-2026-86095HigSep 4, 2026
    risk 0.44cvss 7.8epss 0.00

    Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files with oversized attribute names to overflow the…

  • CVE-2026-48019HigSep 4, 2026
    risk 0.51cvss 8.9epss 0.01

    Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to…

  • CVE-2026-86091HigSep 4, 2026
    risk 0.39cvss 7.1epss 0.01

    ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the delete pools endpoint to irreversibly destroy every host…

  • CVE-2026-86090HigSep 4, 2026
    risk 0.39cvss 7.1epss 0.00

    ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured notification endpoints and recipients, silencing all alerts.

  • CVE-2026-82684HigSep 4, 2026
    risk 0.53cvss 8.1epss 0.00

    Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents.

  • CVE-2026-77393HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.01

    In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on…

  • CVE-2026-76925MedSep 4, 2026
    risk 0.38cvss 5.8epss 0.00

    A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatpak.SystemHelper` component. This vulnerability occurs because a privileged `chmod` operation executes before the OSTree repository validation within the…

  • CVE-2026-75925CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending…

  • CVE-2026-46636HigSep 4, 2026
    risk 0.50cvss —epss 0.01

    Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes…

  • CVE-2026-85787MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before version 1.1.7 might allow an unauthenticated actor to modify data beyond the read-only scope by placing crafted SQL into the content that is submitted when an…

  • CVE-2026-85704LowSep 4, 2026
    risk 0.24cvss 3.7epss 0.00

    A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function getJailbreak of the file server/config.py of the component Jailbreak Mode. The manipulation results in race condition. It is possible…

  • CVE-2026-85703MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.01

    A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this issue is the function getJailbreak of the file server/backend.py of the component Jailbreak Mode. Executing a manipulation can lead to allocation of resources.…

  • CVE-2026-85702HigSep 4, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected is the function _conversation of the file server/backend.py of the component Backend Conversation API. Such manipulation of the argument model leads…

  • CVE-2026-85701MedSep 4, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue affects the function ChatCompletion.create of the file g4f/__init__.py of the component Authentication Check. Such manipulation leads to missing…

  • CVE-2026-82712HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.00

    Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a cross-site request forgery vulnerability. This could allow an attacker to perform state changing operations on the device.

  • CVE-2026-79426HigSep 4, 2026
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file deletion vulnerability in the /adminapi/file/video_data_save component of CRMEB v6.0.0 allows authenticated attackers to delete arbitrary files via crafted POST request.

  • CVE-2026-79423HigSep 4, 2026
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2026-77847MedSep 4, 2026
    risk 0.42cvss 6.5epss 0.00

    Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability. This could allow an attacker to intercept sensitive information or credentials.