VYPR

CVEs

378,628 total · page 339 of 7,573

  • CVE-2026-45129MedAug 18, 2026
    risk 0.23cvss 4.6epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Recovery Codes module does not validate requests correctly, allowing same-site attackers to rotate a victim administrator's recovery codes with a specially crafted URL. The Admin CP Home, Preferences,…

  • CVE-2026-45128LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the ACP Users View Manager module does not validate requests correctly, allowing same-site attackers to change a victim administrator's default user list view by embedding a specially crafted URL. The Set as Default…

  • CVE-2026-45127LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the ACP Mass Mail module does not validate certain requests correctly, allowing same-site attackers to create draft entries from archived entries by embedding a specially crafted URL. The Resend route in Admin CP,…

  • CVE-2026-45126LowAug 18, 2026
    risk 0.16cvss 3.5epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP Security Questions module does not validate the anti-CSRF token correctly, allowing same-site attackers to enable or disable registration challenge questions with a specially crafted URL. The controller…

  • CVE-2026-45125MedAug 18, 2026
    risk 0.27cvss 5.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail header injection. member.php?action=do_emailuser accepts the fromname HTTP parameter for guests or the stored username for…

  • CVE-2026-45124MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Mod CP Report Center does not check permissions consistently, allowing moderators without report-management permission to mark reports as resolved. The modcp.php?action=do_reports Mark Selected as Read handler is…

  • CVE-2026-45123MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the remote requests feature does not correctly handle IPv6 addresses, resulting in a server-side request forgery vulnerability. The default disallowed remote hosts list does not include IPv6 addresses. Verification in…

  • CVE-2026-45122MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not validate moderation permissions for the destination calendar when moving events. A user with moderation permission for the source calendar can move an event to a calendar where the user…

  • CVE-2026-45121MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not check permissions consistently when listing calendars, allowing authenticated users to access titles of calendars that are otherwise inaccessible. The affected calendar-selection paths in…

  • CVE-2026-45120MedAug 18, 2026
    risk 0.28cvss 5.4epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users with viewing and moderation permissions to access and moderate private events. The private-event check used by get_events() in…

  • CVE-2026-45119MedAug 18, 2026
    risk 0.23cvss 4.6epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Admin CP UTF-8 Conversion module does not validate certain requests correctly, allowing same-site attackers to alter table encoding and deny service with a specially crafted URL. The do=all control flow in…

  • CVE-2026-45118CriAug 18, 2026
    risk 0.53cvss 9.3epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in an open redirect and reflected JavaScript code injection. contact.php accepts the redirect target from the from HTTP parameter in…

  • CVE-2026-45117CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configuration values written to the configuration file, resulting in PHP code injection and remote code execution when the installer is…

  • CVE-2026-45116HigAug 18, 2026
    risk 0.50cvss 8.7epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field types, resulting in stored JavaScript code injection. UserDataHandler::verify_profile_fields() only performs the specialized…

  • CVE-2026-45115HigAug 18, 2026
    risk 0.50cvss 8.7epss 0.00

    MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to perform JavaScript code injection through a specially crafted username. The User CP Buddy/Ignore list and the Select Buddies list…

  • CVE-2026-19501HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form field names before generating CSV exports, which allows a remote attacker to execute spreadsheet formulas on an administrator's…

  • CVE-2026-19500HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or submitted content during processing and rendering, which allows a remote attacker to exhaust server resources, prevent administrators…

  • CVE-2026-15806MedAug 18, 2026
    risk 0.32cvss —epss 0.00

    The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an…

  • CVE-2026-12564CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault…

  • CVE-2026-75898HigAug 18, 2026
    risk 0.48cvss 8.5epss 0.00

    RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The component builds an outbound request URL from canvas configuration and runtime template variables and passes it to requests.get,…

  • CVE-2026-75890Aug 18, 2026
    risk 0.00cvss —epss —

    Rejected reason: Duplicate of CVE-2026-50236. This CVE ID was reserved in error for a finding that already had an existing CVE assignment.

  • CVE-2026-75872MedAug 18, 2026
    risk 0.38cvss —epss 0.01

    HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send a message carrying arbitrary HTML, to an attacker-chosen address and from the form owner's configured sending identity, via the…

  • CVE-2026-75784CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx of the component HTTP Header Handler. The manipulation of the argument Server results in stack-based buffer overflow. The attack…

  • CVE-2026-75032MedAug 18, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile (AVRCP) implementation allows a malicious Bluetooth device within range to cause an out-of-bounds memory read. This vulnerability,…

  • CVE-2026-74015CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

  • CVE-2026-74012HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.

  • CVE-2026-74009MedAug 18, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

  • CVE-2026-74008MedAug 18, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.

  • CVE-2026-74007MedAug 18, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions.

  • CVE-2026-74006MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Contributor Broken Access Control in WP Table Builder <= 2.2.0 versions.

  • CVE-2026-74004MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    Subscriber Broken Access Control in Gravity Booster – Styles & Layouts for Gravity Forms <= 6.0 versions.

  • CVE-2026-74003MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Contributor Broken Access Control in RomethemeForm For Elementor <= 1.2.6 versions.

  • CVE-2026-73997HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions.

  • CVE-2026-73996CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

  • CVE-2026-73995MedAug 18, 2026
    risk 0.35cvss 5.4epss 0.00

    Subscriber Broken Authentication in User Registration <= 5.2.6 versions.

  • CVE-2026-73994HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions.

  • CVE-2026-73426MedAug 18, 2026
    risk 0.23cvss 4.6epss 0.00

    Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Prior to 2.1.17, Trix is vulnerable to cross-site scripting when a data-trix-serialized-attributes attribute bypasses the DOMPurify sanitizer. An attacker can craft HTML containing a…

  • CVE-2026-73404MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

  • CVE-2026-73400HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions.

  • CVE-2026-73399MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

  • CVE-2026-73398MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

  • CVE-2026-73397CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

  • CVE-2026-73396HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Broken Authentication in MWB HubSpot for WooCommerce <= 1.6.7 versions.

  • CVE-2026-73395MedAug 18, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versions.

  • CVE-2026-73393HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Subscribe2 <= 10.46 versions.

  • CVE-2026-73392Aug 18, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate to CVE-2026-12965.

  • CVE-2026-73383MedAug 18, 2026
    risk 0.32cvss 4.9epss 0.00

    Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.

  • CVE-2026-73382HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Site Reviews <= 8.2.0 versions.

  • CVE-2026-73381CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

  • CVE-2026-73380CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.