VYPR

CVEs

37,811 total · page 29 of 757

  • CVE-2024-11080CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in the ~/includes/blocks/form-wrap/function.php file. This makes it possible for unauthenticated attackers to…

  • CVE-2026-78362CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.01

    The SEO Flow by LupsOnline WordPress plugin before 3.0.3 does not correctly validate the credential supplied with its API requests, allowing unauthenticated users to be served as the administrator who configured the SEO Flow by LupsOnline WordPress plugin before 3.0.3 and take…

  • CVE-2026-83627CriSep 5, 2026
    risk 0.57cvss 9.8epss 0.01

    The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written…

  • CVE-2026-13447CriSep 5, 2026
    risk 0.64cvss 9.8epss 0.00

    The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates…

  • CVE-2026-52777CriSep 5, 2026
    risk 0.54cvss —epss 0.00

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, there is an authenticated PHP object injection vulnerability in BazarImportAction via unserialize. This issue has been patched in version 4.6.6.

  • CVE-2026-52766CriSep 5, 2026
    risk 0.52cvss 9.1epss 0.01

    YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag appears in that array, with no authorization check anywhere in…

  • CVE-2026-75925CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.01

    Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending…

  • CVE-2026-50894CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    easyadmin v2.0.2.2 is vulnerable to Unrestricted Upload of File with Dangerous Type in the background management interface which allows authenticated remote attackers to execute arbitrary code and gain server privileges via a crafted file upload.

  • CVE-2025-67066CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path

  • CVE-2026-79391CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT broker accepts client connections on TCP port 1883 without requiring authentication, allowing a remote attacker with network access to establish an MQTT session and perform unauthorized publish or…

  • CVE-2026-71625CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component

  • CVE-2026-71624CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in esoTalk v.1.0.0g4 allows a remote attacker to execute arbitrary code via the core/models/ETMemberModel.class.php, core/controllers/ETMemberController.class.php, and core/lib/ET.class.php components

  • CVE-2026-81939CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.01

    A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-Prem file upload and archive processing functionality allows an attacker to extract files outside the intended destination directory using a specially crafted archive.

  • CVE-2026-78328CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.00

    A missing authorization vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows a lower-privileged Admin user to escalate privileges to SuperAdmin.

  • CVE-2026-78327CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.02

    An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin privileges to inject arbitrary commands that…

  • CVE-2026-57163CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.00

    PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c).…

  • CVE-2026-57162CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This…

  • CVE-2026-78745CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in HiDPT/ Weyon HiDPTAndroid Hi3751V350 Hi3751V352E_DMO allows a remote attacker to execute arbitrary code via the Android Debug Bridge (ADB) daemon (adbd)

  • CVE-2026-75430CriSep 4, 2026
    risk 0.57cvss 9.8epss 0.01

    PowerJob Worker version 5.1.2 (and likely earlier versions) exposes the /worker/deployContainer HTTP endpoint without authentication on the default transport port. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-31020CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionality renders user-supplied prompt data using Jinja templates without input sanitization or sandboxing. An…

  • CVE-2026-75431CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256-based authentication. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-75429CriSep 4, 2026
    risk 0.57cvss 9.8epss 0.01

    PowerJob versions 4.x through 5.1.2 contain an unauthenticated remote code execution vulnerability in the /friend/process endpoint of the Server-Worker transport layer

  • CVE-2026-75171CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID session cookie handling component.

  • CVE-2026-75160CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue in X-Serie Gateway Firmware V6_00_05 allows a remote attacker to escalate privileges via the endpoints /cgi-bin/wwwugw.cgi and /cgi-bin/ugwdownload.cgi.

  • CVE-2026-44402CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Voltronic Power SNMP Web Pro 1.1 contains an unauthenticated remote code execution vulnerability in the upload.cgi firmware update endpoint that allows remote attackers to execute arbitrary commands as root by uploading a crafted tar archive without valid credentials. Attackers…

  • CVE-2026-19274CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.00

    IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated Kubernetes tenant to hijack or permanently destroy another tenant's cluster-level RBAC permissions, caused by cluster-scoped RBAC objects being keyed…

  • CVE-2026-18658CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leverage database functionality to write a web shell to the application web…

  • CVE-2026-85696CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.03

    SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the filename to break out of quoted…

  • CVE-2026-85695CriSep 4, 2026
    risk 0.61cvss 9.4epss 0.01

    FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to…

  • CVE-2026-85688CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.03

    TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests to the /api/designer/v1/file-content endpoints to read arbitrary files or write malicious…

  • CVE-2026-85684CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames containing directory traversal sequences to write arbitrary files to any location…

  • CVE-2026-85672CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.03

    zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attackers can craft document URLs with…

  • CVE-2026-85667CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthenticated attackers to inject arbitrary messages into the agent pipeline. Attackers can publish malicious messages via the /webhook_worktool handler and exploit…

  • CVE-2026-85663CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr without allowlist validation. Unauthenticated attackers can register clients, instantiate Repo resources, and invoke arbitrary methods to read experiments or delete…

  • CVE-2026-85661CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attackers to read and write arbitrary files. Attackers can supply unchecked file paths to read and write tools to access any file accessible to the process.

  • CVE-2026-85597CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.00

    Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected…

  • CVE-2026-85596CriSep 4, 2026
    risk 0.57cvss 9.8epss 0.00

    Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a…

  • CVE-2026-85595CriSep 4, 2026
    risk 0.57cvss 9.8epss 0.01

    Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty…

  • CVE-2026-85594CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned…

  • CVE-2026-85184CriSep 4, 2026
    risk 0.52cvss 9.1epss 0.01

    @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the raw request target, while the Fastify router resolves an absolute-form request target to its path before dispatching. Because the two layers evaluate different…

  • CVE-2026-82923CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its REST API routes, allowing unauthenticated attackers to install and activate plugins and themes, import content from a URL under their control, write a file of…

  • CVE-2026-85085CriSep 4, 2026
    risk 0.62cvss 9.6epss 0.00

    The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.

  • CVE-2026-80181CriSep 4, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: through 1.20.0. Users are recommended to upgrade to version 1.21.0, which fixes the issue.

  • CVE-2026-70403CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log in to the affected device.

  • CVE-2026-69657CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.01

    XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in to the affected device.

  • CVE-2026-62928CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.02

    XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

  • CVE-2026-15354CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `submit()` function, which allows unauthenticated form submissions to control the target user ID before calling…

  • CVE-2026-85509CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.

  • CVE-2026-85508CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).

  • CVE-2026-85507CriSep 4, 2026
    risk 0.64cvss 9.8epss 0.00

    ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).