VYPR

CVEs

383,661 total · page 359 of 7,674

  • CVE-2026-19760HigAug 26, 2026
    risk 0.47cvss 7.2epss 0.00

    The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-19718HigAug 26, 2026
    risk 0.53cvss 8.1epss 0.00

    The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a…

  • CVE-2026-19226MedAug 26, 2026
    risk 0.44cvss 6.8epss 0.00

    The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputting them inside an HTML attribute, which could allow users with the Contributor role and above to perform Stored Cross-Site Scripting attacks.

  • CVE-2026-19220LowAug 26, 2026
    risk 0.24cvss 3.7epss 0.00

    The Forminator Forms WordPress plugin before 1.57.1 does not verify that site registration is enabled on the network before creating a site signup, allowing unauthenticated visitors to create a new site on a WordPress multisite network and gain administrator privileges on it.

  • CVE-2026-19094MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restrict which template file a request may load, allowing unauthenticated users to inject SQL and to read question and answer content belonging to courses that are…

  • CVE-2026-16986MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored service price, deriving the expected charge from attacker-supplied request values instead, so an unauthenticated attacker can pay an arbitrary fraction of a…

  • CVE-2026-16984MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin before 3.7.1 does not include an authorization check on a REST route that returns stored account data, allowing unauthenticated visitors to retrieve the connected…

  • CVE-2026-15203CriAug 26, 2026
    risk 0.60cvss —epss 0.00

    Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via…

  • CVE-2026-14550MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through its REST API, verifying only a publicly available nonce, allowing unauthenticated users to submit reservations with an arbitrary approval status and bypass the…

  • CVE-2026-14216MedAug 26, 2026
    risk 0.42cvss 6.5epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before processing its pending notification queue, allowing an unauthenticated user to force the dispatch of queued notifications and integration callbacks.

  • CVE-2026-14212MedAug 26, 2026
    risk 0.31cvss 4.7epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated employee (provider) owns the provider account being updated, allowing any employee with an Employee Panel login to overwrite another employee's cabinet password…

  • CVE-2026-13406MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before returning taxonomy term data for an arbitrary, caller-supplied taxonomy, allowing unauthenticated users to disclose the names and IDs of terms belonging to…

  • CVE-2026-13404MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (relying only on a publicly-scrapeable nonce) before writing like-count and visitor-tracking post meta keyed on an arbitrary post ID, allowing unauthenticated…

  • CVE-2026-13172MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in one of its REST API namespaces, allowing unauthenticated users to retrieve draft, pending and private posts belonging to other users, along with the passwords…

  • CVE-2026-9805LowAug 26, 2026
    risk 0.18cvss 2.7epss 0.00

    SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32, read and write data without checking buffer size and could cause buffer overflow.

  • CVE-2026-80214HigAug 26, 2026
    risk 0.49cvss —epss 0.01

    LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can execute arbitrary code on the host server.

  • CVE-2026-80202HigAug 26, 2026
    risk 0.50cvss 8.8epss 0.00

    Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet…

  • CVE-2026-80201LowAug 26, 2026
    risk 0.06cvss 2.0epss 0.00

    Kimai before 2.53.0 fails to block sensitive User methods in the Twig invoice template sandbox, allowing admins to call getApiToken() and getPlainApiToken() methods. Attackers with template creation permissions can embed these method calls in invoice templates to leak hashed API…

  • CVE-2026-80200MedAug 26, 2026
    risk 0.24cvss 4.7epss 0.00

    Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unvalidated RelayState POST parameters as redirect destinations. Attackers with IdP access can supply malicious RelayState values to redirect authenticated users…

  • CVE-2026-80199LowAug 26, 2026
    risk 0.17cvss 3.7epss 0.00

    Kimai before 2.54.0 contains a timing oracle vulnerability in TokenAuthenticator that allows unauthenticated attackers to enumerate valid usernames via X-AUTH-USER header. Attackers can measure response time differences when the password hasher runs only for existing users,…

  • CVE-2026-80198HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.00

    Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets…

  • CVE-2026-80197MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai before 2.57.0 contains an improper authorization vulnerability in the favorite timesheet add and remove endpoints that allows authenticated users to manipulate other users' bookmarks. Attackers can add or remove timesheet entries from another user's favorite list by…

  • CVE-2026-80196HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.01

    Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up…

  • CVE-2026-80195MedAug 26, 2026
    risk 0.28cvss 5.4epss 0.00

    Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PATCH /api/teams/{id}), which removes all existing team members before validating the submitted replacement member list. An authenticated teamlead (or other…

  • CVE-2026-80194MedAug 26, 2026
    risk 0.21cvss 4.3epss 0.00

    Kimai before 2.64.0 contains a missing authorization vulnerability in the ProjectViewController export route (report_project_view_export). The authorization guards are attached to the sibling __invoke method rather than at the class level, so the export route inherits no…

  • CVE-2026-80193HigAug 26, 2026
    risk 0.50cvss 8.8epss 0.00

    Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the…

  • CVE-2026-80192HigAug 26, 2026
    risk 0.46cvss 8.1epss 0.00

    @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an…

  • CVE-2026-80191HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.00

    GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a…

  • CVE-2026-80189MedAug 26, 2026
    risk 0.35cvss 6.5epss 0.01

    LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in internal/importer/zip_extractor.go opens each entry and copies it to the destination with io.Copy, which runs to the end of the decompressed stream, so only the…

  • CVE-2026-76149MedAug 26, 2026
    risk 0.22cvss 4.4epss 0.00

    CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.

  • CVE-2026-76148HigAug 26, 2026
    risk 0.44cvss 7.8epss 0.00

    CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.

  • CVE-2026-73335MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.00

    Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing…

  • CVE-2026-58092HigAug 26, 2026
    risk 0.46cvss 8.1epss 0.00

    In FreeBSD 15.0, the kernel structure used to represent user credentials changed: previously the primary group ID was stored in the first element of the array containing the list of supplementary group IDs, whereas now the primary group ID is stored in a dedicated field. This…

  • CVE-2026-58091HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The implementation of this ioctl attempts to acquire locks on all channels in a sync group. If locking a channel would block, it releases the sync group list lock and sleeps. Upon reawakening, it is possible that the sync group structure is freed, but the implementation did…

  • CVE-2026-58090HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    The SOCK_STREAM receive path in the unix socket implementation failed to fully detach control messages from the socket buffer before processing them. Some error paths would free those messages, leaving freed data mbufs in the receive socket buffer. An unprivileged local user…

  • CVE-2026-58089HigAug 26, 2026
    risk 0.51cvss 7.8epss 0.00

    When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can…

  • CVE-2026-57171HigAug 26, 2026
    risk 0.43cvss 7.7epss 0.00

    Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an…

  • CVE-2026-57170HigAug 26, 2026
    risk 0.44cvss 7.8epss 0.00

    Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown…

  • CVE-2026-54467HigAug 26, 2026
    risk 0.46cvss 7.0epss 0.00

    On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, unvalidated, supplied pointer.

  • CVE-2026-52776HigAug 26, 2026
    risk 0.49cvss —epss 0.00

    Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach…

  • CVE-2026-29988HigAug 26, 2026
    risk 0.49cvss 7.6epss 0.00

    A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D…

  • CVE-2026-19632CriAug 26, 2026
    risk 0.57cvss 9.8epss 0.09

    The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the 'trp_get_translations_regular' AJAX action. This makes it possible for unauthenticated…

  • CVE-2026-74749modAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: rseq: Prevent hard lockup on granted time slice extension

  • CVE-2026-80529modAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: don't swallow dquot recovery verification errors

  • CVE-2026-80532lowAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: fix another iunlink infinite loop bug in online fsck

  • CVE-2026-80533lowAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: don't walk off the end of a null sc->sa.agi_bp in AGI repair

  • CVE-2026-80535lowAug 26, 2026
    risk 0.29cvss 5.5epss 0.00

    kernel: xfs: don't double-lock when deleting a self-referential directory

  • CVE-2026-80138CriAug 25, 2026
    risk 0.57cvss 9.8epss 0.01

    ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_filepath value to execute arbitrary…

  • CVE-2026-79912HigAug 25, 2026
    risk 0.54cvss 8.3epss 0.02

    A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The impacted element is the function getCurrentTime of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument ntp_server results in command injection. The attack can be initiated remotely.…

  • CVE-2026-79911CriAug 25, 2026
    risk 0.65cvss 10.0epss 0.01

    A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument Hostname leads to stack-based buffer…