VYPR

CVEs

383,015 total · page 316 of 7,661

  • CVE-2026-82453HigAug 29, 2026
    risk 0.49cvss 7.5epss 0.00

    rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.

  • CVE-2026-82452CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.01

    rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly…

  • CVE-2026-82451MedAug 29, 2026
    risk 0.33cvss 6.1epss 0.00

    Formwork before 2.3.11 contains a stored cross-site scripting vulnerability in visit tracking that records the Referer header host unescaped. Unauthenticated attackers can craft malicious Referer headers to inject markup that executes in administrator browsers when viewing the…

  • CVE-2026-82450HigAug 29, 2026
    risk 0.50cvss 8.8epss 0.01

    BookStack before 26.05.4 contains a remote code execution vulnerability in the portable ZIP import functionality that allows users with Import Content and Create Books permissions to upload a PHP polyglot file as a book cover. Attackers can bypass image extension validation by…

  • CVE-2026-82449MedAug 29, 2026
    risk 0.27cvss 5.3epss 0.00

    Cockpit CMS before 2.14.1 contains an account enumeration vulnerability in the auth check endpoint due to timing discrepancies in password verification. Attackers can measure response times across multiple requests to determine which accounts exist by observing that existing…

  • CVE-2026-82448CriAug 29, 2026
    risk 0.57cvss 9.8epss 0.01

    Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then…

  • CVE-2026-82447HigAug 29, 2026
    risk 0.50cvss 8.8epss 0.01

    Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters…

  • CVE-2026-14494CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.01

    The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.5 via the handle_form_submission function. This is due to the plugin dynamically granting the unfiltered_upload capability to all users during form…

  • CVE-2026-82364MedAug 29, 2026
    risk 0.27cvss 4.2epss 0.00

    A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is possible to initiate the attack remotely. The attack is…

  • CVE-2026-80725Aug 29, 2026
    risk 0.00cvss —epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: net: gro: properly validate BIG TCP aggregation criteria When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP (with…

  • CVE-2026-81346MedAug 29, 2026
    risk 0.28cvss 4.3epss 0.00

    The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.

  • CVE-2026-81342MedAug 29, 2026
    risk 0.31cvss 4.7epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied during user registration before using it, allowing unauthenticated attackers to redirect users to arbitrary external URLs.

  • CVE-2026-81200LowAug 29, 2026
    risk 0.18cvss 2.7epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.42 does not correctly restrict access to order information, allowing any user with the instructor role to read other users' order billing details, including name, email address, phone number and postal address, by…

  • CVE-2026-81026MedAug 29, 2026
    risk 0.31cvss 4.8epss 0.00

    The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 does not verify the amount, receiver, currency or status of a payment notification before marking the corresponding order completed, allowing unauthenticated users to complete full-price orders and gain access…

  • CVE-2026-80488MedAug 29, 2026
    risk 0.27cvss 4.1epss 0.00

    The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allow high privilege users such as admin to perform SQL injection attacks.

  • CVE-2026-80311MedAug 29, 2026
    risk 0.28cvss 4.3epss 0.00

    The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.5 does not verify that a subscription belongs to the customer bound to the requesting customer-portal session before cancelling it, allowing a user with a confirmed portal session to cancel subscriptions…

  • CVE-2026-77786MedAug 29, 2026
    risk 0.32cvss 4.9epss 0.00

    The Rank Math SEO WordPress plugin before 1.0.277 does not check that the user requesting an automated SEO fix holds the capability WordPress itself requires for the settings being changed, allowing users with the Editor role to modify site-wide core WordPress settings that are…

  • CVE-2026-77704LowAug 29, 2026
    risk 0.18cvss 2.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not check that a user holds the required capability before letting them change an appointment's status, allowing customers to set arbitrary statuses on appointments they are booked on, including…

  • CVE-2026-77012CriAug 29, 2026
    risk 0.60cvss 9.3epss 0.00

    The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated…

  • CVE-2026-77010MedAug 29, 2026
    risk 0.42cvss 6.5epss 0.00

    The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class access code, allowing unauthenticated users to obtain a signed meeting join link for…

  • CVE-2026-77008MedAug 29, 2026
    risk 0.42cvss 6.5epss 0.00

    The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated users to overwrite them and repoint every online classroom, along with the shared…

  • CVE-2026-77007HigAug 29, 2026
    risk 0.49cvss 7.5epss 0.00

    The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to…

  • CVE-2026-76586HigAug 29, 2026
    risk 0.49cvss 7.5epss 0.00

    The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.6.3 does not verify the amount actually paid against the server-side price staged for a booking when confirming an online payment, allowing unauthenticated users to have a paid appointment…

  • CVE-2026-76548HigAug 29, 2026
    risk 0.53cvss 8.2epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts,…

  • CVE-2026-76547MedAug 29, 2026
    risk 0.43cvss 6.6epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not validate the type of data being deserialized when importing a configuration file, allowing high privilege users such as administrators to conduct PHP Object Injection. The affected feature is a free add-on which is…

  • CVE-2026-76546MedAug 29, 2026
    risk 0.44cvss 6.8epss 0.00

    The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, allowing users with a role as low as contributor to perform Stored Cross-Site Scripting attacks against any user viewing the affected content, including…

  • CVE-2026-19430MedAug 29, 2026
    risk 0.34cvss 5.3epss 0.00

    The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never…

  • CVE-2026-18234MedAug 29, 2026
    risk 0.42cvss 6.5epss 0.00

    The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark…

  • CVE-2026-18233MedAug 29, 2026
    risk 0.42cvss 6.5epss 0.00

    The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made.

  • CVE-2026-17522MedAug 29, 2026
    risk 0.35cvss 5.4epss 0.00

    The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters…

  • CVE-2026-17520MedAug 29, 2026
    risk 0.31cvss 4.8epss 0.00

    The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers…

  • CVE-2026-16947CriAug 29, 2026
    risk 0.59cvss 9.1epss 0.00

    The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to…

  • CVE-2026-16600HigAug 29, 2026
    risk 0.50cvss 7.7epss 0.00

    The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary…

  • CVE-2026-16259CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every…

  • CVE-2026-16061HigAug 29, 2026
    risk 0.56cvss 8.6epss 0.00

    The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

  • CVE-2026-10522CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site…

  • CVE-2026-41012HigAug 29, 2026
    risk 0.50cvss 7.7epss 0.00

    Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. …

  • CVE-2026-55867MedAug 28, 2026
    risk 0.27cvss —epss 0.01

    Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java…

  • CVE-2026-55860MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the AuthenticationPlugin interface has no capability for a…

  • CVE-2026-55859MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A server can announce a mid-session change to…

  • CVE-2026-55858MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.01

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character…

  • CVE-2026-55857MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password…

  • CVE-2026-55856MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure…

  • CVE-2026-55855MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the…

  • CVE-2026-55854MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure…

  • CVE-2026-55848HigAug 28, 2026
    risk 0.49cvss 8.6epss 0.01

    mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by…

  • CVE-2026-55841HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and…

  • CVE-2026-55785LowAug 28, 2026
    risk 0.17cvss 3.7epss 0.00

    free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmRequestProcedure compares RES* and…

  • CVE-2026-55784HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by SUPI. Every request handled by…

  • CVE-2026-55779MedAug 28, 2026
    risk 0.28cvss 5.4epss 0.00

    Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment,…