VYPR

CVEs

378,628 total · page 341 of 7,573

  • CVE-2026-66635HigAug 18, 2026
    risk 0.48cvss 7.4epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.

  • CVE-2026-66634MedAug 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Subscriber Insecure Direct Object References (IDOR) in Modal Survey <= 2.0.2.2.3 versions.

  • CVE-2026-66633HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.

  • CVE-2026-66629HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.

  • CVE-2026-66627CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.

  • CVE-2026-66622HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.

  • CVE-2026-66621HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MapSteps UG Ultimate Dashboard Pro allows DOM-Based XSS. This issue affects Ultimate Dashboard Pro: from n/a through 3.11.2.

  • CVE-2026-66620HigAug 18, 2026
    risk 0.47cvss 7.2epss 0.00

    Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

  • CVE-2026-66046HigAug 18, 2026
    risk 0.42cvss 7.5epss 0.01

    Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to…

  • CVE-2026-63639HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.01

    Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a…

  • CVE-2026-63632LowAug 18, 2026
    risk 0.14cvss 3.3epss 0.00

    Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0, onnx.version_converter.convert_version() can perform an out-of-bounds read in Gemm_7_6::adapt_gemm_7_6() in onnx/version_converter/adapters/gemm_7_6.h when a…

  • CVE-2026-61407HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.

  • CVE-2026-59949MedAug 18, 2026
    risk 0.35cvss 6.5epss 0.00

    yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(),…

  • CVE-2026-59940CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without…

  • CVE-2026-59825HigAug 18, 2026
    risk 0.41cvss 7.4epss 0.00

    Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses…

  • CVE-2026-56684HigAug 18, 2026
    risk 0.42cvss 7.5epss 0.01

    Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and…

  • CVE-2026-50187HigAug 18, 2026
    risk 0.50cvss 8.8epss 0.00

    Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell…

  • CVE-2026-50139MedAug 18, 2026
    risk 0.31cvss 5.9epss 0.00

    goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the lock, serves the file, then re-acquires the lock to increment the counter. Concurrent requests all read the same…

  • CVE-2026-50138HigAug 18, 2026
    risk 0.46cvss 8.1epss 0.00

    goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to…

  • CVE-2026-48798HigAug 18, 2026
    risk 0.39cvss 7.1epss 0.00

    SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trusts file and directory names returned by a remote SCP server and combines them with the requested local directory without…

  • CVE-2026-45733HigAug 18, 2026
    risk 0.47cvss 8.3epss 0.00

    Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in…

  • CVE-2026-32553HigAug 18, 2026
    risk 0.47cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.

  • CVE-2026-32549HigAug 18, 2026
    risk 0.42cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.

  • CVE-2026-32547HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.

  • CVE-2026-32481HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.

  • CVE-2026-32474CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

  • CVE-2026-32473HigAug 18, 2026
    risk 0.47cvss 7.2epss 0.00

    Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.

  • CVE-2026-32472HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.

  • CVE-2026-32470CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

  • CVE-2026-18534HigAug 18, 2026
    risk 0.48cvss 7.4epss 0.00

    ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to imitate browser interface elements and increasing spoofing risk.

  • CVE-2026-73692Aug 18, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-50575HigAug 18, 2026
    risk 0.43cvss 7.7epss 0.00

    BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No…

  • CVE-2026-32468HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.

  • CVE-2026-32467MedAug 18, 2026
    risk 0.39cvss 6.0epss 0.00

    Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.

  • CVE-2026-32466HigAug 18, 2026
    risk 0.55cvss 8.5epss 0.00

    Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

  • CVE-2026-32465HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

  • CVE-2026-32464HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Theme Test Drive <= 2.9.1 versions.

  • CVE-2026-32463CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

  • CVE-2026-32444CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

  • CVE-2026-32333HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <= 5.4.7 versions.

  • CVE-2026-28571HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions.

  • CVE-2026-28570HigAug 18, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0 versions.

  • CVE-2026-28569HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in SSL Zen <= 4.7.43 versions.

  • CVE-2026-28568HigAug 18, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Quill Forms <= 5.7.1 versions.

  • CVE-2026-28567HigAug 18, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in WP Sort Order <= 1.3.5 versions.

  • CVE-2026-28192CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

  • CVE-2026-28191HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.00

    Subscriber Privilege Escalation in The Grid <= 2.7.9.1 versions.

  • CVE-2026-24301HigAug 18, 2026
    risk 0.57cvss 8.8epss 0.03

    Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2026-17084MedAug 18, 2026
    risk 0.32cvss —epss 0.01

    The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna"…

  • CVE-2026-75874CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.00

    Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.