VYPR

CVEs

382,996 total · page 314 of 7,660

  • CVE-2026-82644HigAug 30, 2026
    risk 0.49cvss 7.5epss 0.00

    WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards…

  • CVE-2026-82643MedAug 30, 2026
    risk 0.42cvss 6.5epss 0.00

    WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger uncapped two-factor confirmation emails…

  • CVE-2026-82548MedAug 30, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was determined in Linux Foundation Magma 1.9.0. The impacted element is an unknown function of the component InitialUEMessage Handler. This manipulation causes information disclosure. The attack may be initiated remotely. The exploit has been publicly disclosed…

  • CVE-2026-82547MedAug 30, 2026
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks/amf/amf_fsm.cpp of the component Registration Complete Message Handler. The manipulation results in improper authentication. The attack can be launched…

  • CVE-2026-82545MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown function of the file /pages/sup_searchfrm.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2026-82642HigAug 30, 2026
    risk 0.50cvss 8.8epss 0.01

    Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB chapter HTML is sanitized with DOMPurify using a configuration that forbade only the tag (FORBID_TAGS: ['script']) in apps/readest-app/src/services/transformers/sanitizer.ts.…

  • CVE-2026-82641HigAug 30, 2026
    risk 0.49cvss 8.6epss 0.01

    Keploy versions 3.1.0 through 3.6.25, fixed in 3.6.26, bind the agent control-plane HTTP server to all interfaces without authentication, exposing endpoints that stream TLS session keys and traffic data. Attackers can access the /agent/pcap/keylog endpoint to retrieve NSS keylog…

  • CVE-2026-82640MedAug 30, 2026
    risk 0.29cvss 5.5epss 0.00

    browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access to the temporary settings directory can recover provider API keys from predictably-named JSON files.

  • CVE-2026-82639HigAug 30, 2026
    risk 0.42cvss 7.5epss 0.01

    NextChat versions from 2.15.8 through 2.16.1 contain an improper URL validation vulnerability in the proxy endpoint that allows attackers to obtain the server's OpenAI API key. The x-base-url header is validated using substring matching instead of hostname parsing, allowing any…

  • CVE-2026-82638HigAug 30, 2026
    risk 0.49cvss 7.5epss 0.01

    jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal…

  • CVE-2026-82637MedAug 30, 2026
    risk 0.27cvss 5.3epss 0.00

    browser-use web-ui versions 2.0.0 through 3.0.0 fail to validate browser settings paths in run_agent_task, allowing attackers to create directories at arbitrary locations by supplying absolute paths to save_recording_path, save_trace_path, save_agent_history_path, or…

  • CVE-2026-82636HigAug 30, 2026
    risk 0.51cvss 7.9epss 0.02

    Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell metacharacters. This occurs in…

  • CVE-2026-82544MedAug 30, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the…

  • CVE-2026-82635HigAug 30, 2026
    risk 0.50cvss 8.8epss 0.01

    Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path…

  • CVE-2026-82634MedAug 30, 2026
    risk 0.35cvss 6.5epss 0.00

    Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-privileged users to render arbitrary Jinja templates by supplying raw template strings. Attackers with print permission on any document can execute arbitrary…

  • CVE-2026-82633MedAug 30, 2026
    risk 0.21cvss 4.3epss 0.00

    Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers…

  • CVE-2026-82543HigAug 30, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was detected in vastsa FileCodeBox up to 2.3. This vulnerability affects the function update_file_usage of the file apps/base/views.py of the component Pickup Limit Handler. Performing a manipulation results in race condition. It is possible to initiate the…

  • CVE-2026-82542CriAug 30, 2026
    risk 0.65cvss 10.0epss 0.01

    A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to…

  • CVE-2026-82541MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The…

  • CVE-2026-82540MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/cust_searchfrm.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is…

  • CVE-2026-81318LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_sql allows a caller in a schema-based multitenant application to receive aggregate values computed from another tenant's rows. When an aggregate is computed over a distinct query, AshSql.AggregateQuery.add_single_aggs/5…

  • CVE-2026-81316LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to receive an aggregate value computed over rows a more restrictive filter should have excluded, disclosing counts, sums, or lists across an authorization or tenancy boundary. …

  • CVE-2026-80227LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Incorrect Comparison vulnerability in ash-project ash_sql allows a user to pad a string field with tab, newline, carriage-return, or form-feed characters and pass a trimmed uniqueness or equality check in the database that the same expression would fail in memory (or the…

  • CVE-2026-78691LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sql allows a user who supplies a search term to contains/2, string_starts_with/2, or string_ends_with/2 to inject live SQL LIKE wildcards, turning a literal substring search into an…

  • CVE-2026-78228MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Uncontrolled Recursion vulnerability in ash-project ash_oban allows a user who can drive a trigger's on_error action to fail on the final attempt to exhaust worker CPU and memory, denying service. The generated worker's atomic handle_error/4 runs the trigger's on_error action…

  • CVE-2026-78038MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option of AshOban.build_trigger/3 to retarget an update or destroy trigger at another record, including across…

  • CVE-2026-77454MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Incorrect Authorization vulnerability in ash-project ash_sql allows a caller to bypass a scoping or authorization filter expressed as exists/2 over a relationship that declares both a limit (or from_many?) and a parent(...)-referencing filter or sort. …

  • CVE-2026-82539CriAug 30, 2026
    risk 0.59cvss 9.1epss 0.01

    A vulnerability was determined in TOTOLINK A720R 4.1.5cu.630_B20250509. This impacts the function setMacFilterRules of the file cstecgi.cgi of the component MAC Filtering. Executing a manipulation of the argument desc can lead to memory corruption. The attack may be launched…

  • CVE-2026-82488LowAug 30, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in Beetel 450TC3 01.00.00_01. This vulnerability affects unknown code of the component User Management. The manipulation of the argument Username leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is…

  • CVE-2026-82487MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in Beetel 450TC3 01.00.00_01. This affects an unknown part. Executing a manipulation can lead to weak password recovery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted…

  • CVE-2026-82486MedAug 30, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is…

  • CVE-2026-82485MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/pro_edit.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The…

  • CVE-2026-82484MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/emp_searchfrm.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be…

  • CVE-2026-82483LowAug 30, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched…

  • CVE-2026-82482LowAug 30, 2026
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The…

  • CVE-2026-81766MedAug 30, 2026
    risk 0.43cvss 6.6epss 0.00

    The Really Simple Security WordPress plugin before 9.8.0 does not check that the user is allowed to install Really Simple Security WordPress plugin before 9.8.0 before installing one from a user-supplied URL, allowing an administrator of a subsite on a multisite network to…

  • CVE-2026-81660HigAug 30, 2026
    risk 0.57cvss 8.8epss 0.01

    The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does not validate or escape values submitted to some optional web form fields before storing them and outputting them back in an administrative area, allowing unauthenticated users to…

  • CVE-2026-78364LowAug 30, 2026
    risk 0.23cvss 3.5epss 0.00

    The MW WP Form WordPress plugin before 5.1.6 does not sanitise and escape some of its form settings before outputting them back in an admin dashboard page, which could allow users with a role as low as Editor to perform Stored Cross-Site Scripting attacks against high privilege…

  • CVE-2026-76585HigAug 30, 2026
    risk 0.57cvss 8.8epss 0.01

    The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape the content of customer reviews received via one of its endpoints, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks.

  • CVE-2026-19722MedAug 30, 2026
    risk 0.43cvss 6.6epss 0.00

    The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not validate the destination of files extracted from a backup package during restoration, allowing high privilege users such as administrators to write arbitrary files outside the intended restore…

  • CVE-2026-14835MedAug 30, 2026
    risk 0.44cvss 6.8epss 0.00

    The SOGO Add Script to Individual Pages Header Footer WordPress plugin through 3.9 does not sanitise or escape the custom header/footer script values saved from its post metabox, and does not restrict them to users with the unfiltered_html capability, allowing users with…

  • CVE-2026-14307HigAug 30, 2026
    risk 0.46cvss 7.1epss 0.00

    The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses that are served with an HTML content type, allowing unauthenticated attackers to inject arbitrary web scripts that execute when a…

  • CVE-2026-82480HigAug 30, 2026
    risk 0.48cvss 7.4epss 0.00

    A security flaw has been discovered in NASA cFS up to 7.0.1. The affected element is the function CFE_SB_GetUserDataLength of the file src/cFS/cfe/modules/sb/fsw/src/cfe_sb_util.c of the component cFE Software Bus. Performing a manipulation of the argument TotalMsgSize/HdrSize…

  • CVE-2026-82479MedAug 30, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from…

  • CVE-2026-82478HigAug 30, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was determined in NASA Trick 19.6.0. This issue affects the function JSONVariableServerThread::parse_request of the file trick_source/sim_services/JSONVariableServer/JSONVariableServerThread.cpp of the component TCP Socket Handler. This manipulation causes…

  • CVE-2026-15980CriAug 30, 2026
    risk 0.64cvss 9.8epss 0.00

    The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for…

  • CVE-2026-77846LowAug 30, 2026
    risk 0.07cvss —epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash_sqlite allows an attacker who controls a get_path/2 segment to traverse into nested JSON the application never exposed, disclosing private or sensitive? embedded fields. …

  • CVE-2026-75759HigAug 30, 2026
    risk 0.42cvss —epss 0.00

    Improper Verification of Cryptographic Signature vulnerability in erlef oidcc allows an unauthenticated attacker to impersonate an arbitrary user via an encrypted ID token or JARM response carrying no nested signature. OpenID Connect Core 1.0 section 2 requires that an encrypted…

  • CVE-2026-82562LowAug 30, 2026
    risk 0.17cvss 3.7epss 0.01

    ### Summary When `qs.parse` is called with `comma: true` and `throwOnLimitExceeded: true`, a comma-separated value under a bracket-push key (`a[]=1,2,3,4`) is split into an array without being compared against `arrayLimit`, while the same value under a flat key (`a=1,2,3,4`),…

  • CVE-2026-77970MedAug 30, 2026
    risk 0.31cvss —epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in ash-project ash_paper_trail allows an attacker with read access to the generated version resource to recover sensitive values nested inside embedded resources, unions, or lists. sensitive_attributes :redact and :ignore…