VYPR

CVEs

383,039 total · page 317 of 7,661

  • CVE-2026-19430MedAug 29, 2026
    risk 0.34cvss 5.3epss 0.00

    The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never…

  • CVE-2026-18234MedAug 29, 2026
    risk 0.42cvss 6.5epss 0.00

    The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark…

  • CVE-2026-18233MedAug 29, 2026
    risk 0.42cvss 6.5epss 0.00

    The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made.

  • CVE-2026-17522MedAug 29, 2026
    risk 0.35cvss 5.4epss 0.00

    The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its settings screens, and writes every submitted parameter into its own options, allowing attackers to make a logged in administrator overwrite arbitrary Newsletters…

  • CVE-2026-17520MedAug 29, 2026
    risk 0.31cvss 4.8epss 0.00

    The Newsletters WordPress plugin before 4.17 does not generate its API key using a sufficiently random source, deriving it from a publicly known value, allowing unauthenticated attackers to compute the key and perform privileged actions such as adding and deleting subscribers…

  • CVE-2026-16947CriAug 29, 2026
    risk 0.59cvss 9.1epss 0.00

    The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to…

  • CVE-2026-16600HigAug 29, 2026
    risk 0.50cvss 7.7epss 0.00

    The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary…

  • CVE-2026-16259CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every…

  • CVE-2026-16061HigAug 29, 2026
    risk 0.56cvss 8.6epss 0.00

    The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its public REST routes before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks.

  • CVE-2026-10522CriAug 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site…

  • CVE-2026-41012HigAug 29, 2026
    risk 0.50cvss 7.7epss 0.00

    Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, leading to complete virtualization infrastructure takeover. …

  • CVE-2026-55867MedAug 28, 2026
    risk 0.27cvss —epss 0.01

    Graylog is a free and open log management platform. From 6.2.0 until 6.3.12, 7.0.7, and 7.1.2, the DELETE /users/{userId}/tokens/{idOrToken} endpoint implemented by UsersResource.revokeToken() in graylog2-server/src/main/java/org/graylog2/rest/resources/users/UsersResource.java…

  • CVE-2026-55860MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the AuthenticationPlugin interface has no capability for a…

  • CVE-2026-55859MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A server can announce a mid-session change to…

  • CVE-2026-55858MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.01

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character…

  • CVE-2026-55857MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password…

  • CVE-2026-55856MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure…

  • CVE-2026-55855MedAug 28, 2026
    risk 0.35cvss 6.5epss 0.00

    MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the…

  • CVE-2026-55854MedAug 28, 2026
    risk 0.31cvss 5.9epss 0.00

    MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure…

  • CVE-2026-55848HigAug 28, 2026
    risk 0.49cvss 8.6epss 0.01

    mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.33.16, and 4.0.5, MapFish Print accepts an attacker-controlled GML layer url in requests to the /api/print3/print endpoint and fetches XML parsed by…

  • CVE-2026-55841HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.01

    Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/graylog2/inputs/codecs/GLFortiGateSyslogEvent.java and…

  • CVE-2026-55785LowAug 28, 2026
    risk 0.17cvss 3.7epss 0.00

    free5GC is an open-source implementation of the 5G core network. Prior to 1.4.5, the AUSF component performs cryptographic authentication comparisons in internal/sbi/processor/ue_authentication.go with ordinary equality helpers. Auth5gAkaComfirmRequestProcedure compares RES* and…

  • CVE-2026-55784HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    free5GC is an open-source implementation of the 5G core network. In version 1.4.4 and earlier, the AUSF component stores per-subscriber authentication state in a global sync.Map named AUSFContext.UePool in internal/context/context.go, keyed only by SUPI. Every request handled by…

  • CVE-2026-55779MedAug 28, 2026
    risk 0.28cvss 5.4epss 0.00

    Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() in src/RestoreAction.php builds ArchiveAdmin restore notifications rendered as CAST_HTML and inserts $restoredItem->Title, $restoredItem->URLSegment,…

  • CVE-2026-55764HigAug 28, 2026
    risk 0.50cvss —epss 0.01

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, Klever-Go allows a mint-role holder to bypass a finite per-nonce MaxSupply on the semi-fungible token add-quantity path. In core/kapp/systemAccount/systemAcount.go, SFTAddCirculation performed…

  • CVE-2026-82333HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    multer is a middleware for handling multipart/form-data in Node.js. A small multipart request with two specially crafted text field names can make multer's field parser synchronously iterate a maximum-length sparse array, blocking the event loop so the process cannot handle…

  • CVE-2026-82018MedAug 28, 2026
    risk 0.40cvss 6.1epss 0.00

    IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the GRUB boot stage that allows physically present attackers to gain unauthorized root access by placing an unsigned empty file named igel.conf on a partition.…

  • CVE-2026-82017HigAug 28, 2026
    risk 0.49cvss 7.6epss 0.00

    IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the…

  • CVE-2026-81533HigAug 28, 2026
    risk 0.46cvss 7.1epss 0.00

    An application using the MongoDB BI Connector ODBC Driver may encounter a memory-safety issue when a submitted SQL statement contains an unusually long run of digits following a LIMIT clause. The issue occurs only on connections where the driver's optional prefetch setting is…

  • CVE-2026-81532HigAug 28, 2026
    risk 0.57cvss 8.8epss 0.00

    A user able to submit SQL through an application using the MongoDB Connector for BI ODBC driver can supply a positioned-cursor statement whose cursor name exceeds the size of an internal fixed-length buffer. Because the name length is not bounded before the driver builds its…

  • CVE-2026-81520HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by beginning a SASL-based login exchange and then declining to complete it. Because the negotiation loop had no overall time bound and the read…

  • CVE-2026-81518HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    When mongosqld is configured with a client certificate authority file, the listener requests a client certificate during the TLS handshake but does not require one, so a client that presents no certificate is still accepted. In deployments that rely on client certificates as the…

  • CVE-2026-81517HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path. When a log write or log rotation operation subsequently fails, the…

  • CVE-2026-81490HigAug 28, 2026
    risk 0.50cvss 7.7epss 0.00

    A database user able to create a view in a namespace that MongoDB Connector for BI samples can cause the schema-sampling routine to stop functioning by defining a view whose evaluation reliably fails. The sampling logic classifies the resulting server message as transient and,…

  • CVE-2026-77078HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    multer is a middleware for handling multipart/form-data in Node.js. A small multipart request containing two specially crafted text field names can cause an uncaught RangeError (Invalid array length) that terminates the Node.js process. The first field uses a very large numeric…

  • CVE-2026-77063LowAug 28, 2026
    risk 0.17cvss 3.7epss 0.00

    multer is a middleware for handling multipart/form-data in Node.js. When an application uses an asynchronous fileFilter together with the fileSize limit, a race condition in multer's file stream handling can allow a file that exceeds the configured size limit to bypass the…

  • CVE-2026-77037HigAug 28, 2026
    risk 0.42cvss 7.5epss 0.00

    multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not close the underlying write file…

  • CVE-2026-76651MedAug 28, 2026
    risk 0.34cvss —epss 0.00

    A buffer overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing multipart/form-data requests. Insufficient validation of an attacker-controlled boundary parameter may allow a remote unauthenticated attacker to submit a crafted request that…

  • CVE-2026-76650MedAug 28, 2026
    risk 0.34cvss —epss 0.00

    A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP state variable query requests. A specially crafted SOAP query may trigger unexpected termination or instability of the process hosting the UPnP service. Successful…

  • CVE-2026-76649MedAug 28, 2026
    risk 0.34cvss —epss 0.00

    A NULL pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly. Successful…

  • CVE-2026-75118HigAug 28, 2026
    risk 0.57cvss —epss 0.00

    A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web…

  • CVE-2026-55891NonAug 28, 2026
    risk 0.00cvss 0.0epss 0.01

    PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, Request::getRequestUri() in lib/Request.php passes $_SERVER['REQUEST_URI'] through FILTER_SANITIZE_URL, which does not remove quotation marks, angle brackets, or apostrophes, and…

  • CVE-2026-55763HigAug 28, 2026
    risk 0.50cvss —epss 0.01

    Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, processPercentageRoyaltiesTransfer in core/kapp/accounts/accounts.go calls SubFromBalance after the split loop and after the royaltiesToPay <= 0 early return. computeSplitRoyalties rejects…

  • CVE-2026-55696MedAug 28, 2026
    risk 0.21cvss 4.3epss 0.00

    PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Prior to 2.0.5, AttachmentViewer.setAttachment in js/privatebin.js uses getAttachmentMimeType to accept attacker-controlled MIME types and uses getBlobUrl to create a same-origin blob before…

  • CVE-2026-55678MedAug 28, 2026
    risk 0.38cvss —epss 0.01

    Arc is an open, SQL-native time-series database for telemetry. From 26.02.1 until 26.06.2, Arc Enterprise clustering accepts cluster join requests without authentication when cluster.enabled is true but cluster.shared_secret is not configured. The defaults in…

  • CVE-2026-51665MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTracerouteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain traceroute diagnostic logs via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51664MedAug 28, 2026
    risk 0.28cvss 4.3epss 0.00

    Incorrect access control in the getTelnetCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain Telnet service enablement status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51663CriAug 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the getWiFiApcliScan function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to trigger wireless scans and retrieve AP-client scan results via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51662HigAug 28, 2026
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

  • CVE-2026-51661CriAug 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Incorrect access control in the getPortForwardRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain port-forwarding rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi.