VYPR

CVEs

383,885 total · page 391 of 7,678

  • CVE-2026-75866CriAug 22, 2026
    risk 0.59cvss 9.1epss 0.01

    Punk::OAuth2::Server versions through 0.03 for Perl issue access tokens outside a client's registered scopes and grant types because no authorization path reads them. Punk::OAuth2::Server::Store registers scopes and grant_types per client and documents both as client…

  • CVE-2026-71514LowAug 22, 2026
    risk 0.09cvss 2.5epss 0.00

    NLTK 3.9.4 through 3.10.2 contains a path traversal vulnerability in CrubadanCorpusReader. _load_lang_ngrams joins the corpus root with crubadan_code, the column-0 value read from the corpus table.txt mapping file, and opens the result with the builtin open() rather than the…

  • CVE-2026-71513HigAug 22, 2026
    risk 0.50cvss 8.8epss 0.01

    NLTK before 3.10.3 contains a remote code execution vulnerability in AllowlistUnpickler that validates only the pickle module string and not the global name, allowing attackers to resolve dotted names by attribute traversal to callables outside the allowlisted namespace.…

  • CVE-2026-68769Aug 22, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-5093MedAug 22, 2026
    risk 0.21cvss 4.3epss 0.00

    The GreenShift – Animation and Page Builder Blocks plugin for WordPress is vulnerable to unauthorized modification of data in versions up to, and including, 12.8.9. This is due to a missing capability check on the 'gspb_update_global_wp_settings' function that only verifies…

  • CVE-2026-4561MedAug 22, 2026
    risk 0.35cvss 6.4epss 0.00

    The MC4WP: Mailchimp for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form response message post meta fields (e.g., 'text_subscribed', 'text_error') in all versions up to, and including, 4.12.0 due to insufficient input sanitization and…

  • CVE-2026-4559MedAug 22, 2026
    risk 0.35cvss 6.4epss 0.00

    The Image Photo Gallery Final Tiles Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'delay' shortcode attribute in all versions up to, and including, 3.6.12 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-2996HigAug 22, 2026
    risk 0.42cvss 7.5epss 0.01

    The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated…

  • CVE-2026-62382MedAug 22, 2026
    risk 0.38cvss —epss 0.01

    PasswordPusher versions v1.45.11 through v2.9.5 contain an improper authorization vulnerability in the push deletion logic. The ownership check compares @push.user against current_user; for an anonymously created push both values are nil, and Ruby evaluates nil == nil as true,…

  • CVE-2026-62381MedAug 22, 2026
    risk 0.43cvss 6.6epss 0.00

    luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255…

  • CVE-2026-62380HigAug 22, 2026
    risk 0.49cvss 7.5epss 0.00

    Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential injection vulnerabilities in the SOCKS4 (Socks4ClientEncoder) and SOCKS5 (Socks5ClientEncoder) client encoders, which fail to…

  • CVE-2026-62243HigAug 22, 2026
    risk 0.49cvss 7.5epss 0.00

    Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on the SslProvider.OPENSSL client path when a plain (non-extended) X509TrustManager is used and Unsafe-based trust-manager wrapping…

  • CVE-2026-62204MedAug 22, 2026
    risk 0.43cvss 6.6epss 0.00

    SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with same-origin access can overwrite existing trusted plugins by supplying mismatched packageName and repoURL parameters, achieving…

  • CVE-2026-60084HigAug 22, 2026
    risk 0.57cvss 8.7epss 0.01

    SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated path parameter passed directly to os.RemoveAll. Authenticated admin attackers can supply absolute filesystem paths to recursively…

  • CVE-2026-60083MedAug 22, 2026
    risk 0.25cvss 4.9epss 0.00

    SiYuan versions before v3.8.0 contain an incomplete path blocklist in the MCP file tool that fails to restrict access to sensitive workspace files protected by the HTTP API. Authenticated administrators can read plaintext publish-mode passwords from…

  • CVE-2026-59809MedAug 22, 2026
    risk 0.25cvss 4.9epss 0.00

    SiYuan before v3.8.0 interpolates secret placeholders into the destination URL parameter of the http_request MCP tool, allowing attackers to exfiltrate stored secrets. An MCP client can craft a request with an attacker-controlled URL containing secret placeholders to send…

  • CVE-2026-59808HigAug 22, 2026
    risk 0.57cvss 8.8epss 0.01

    AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless…

  • CVE-2026-59256HigAug 22, 2026
    risk 0.49cvss 7.5epss 0.00

    WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token…

  • CVE-2026-58003HigAug 22, 2026
    risk 0.46cvss 7.1epss 0.00

    WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session…

  • CVE-2026-58002MedAug 22, 2026
    risk 0.35cvss 6.5epss 0.00

    WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the counterparty's agreement…

  • CVE-2026-58001MedAug 22, 2026
    risk 0.37cvss 5.7epss 0.00

    WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfers video ownership to an…

  • CVE-2026-57998HigAug 22, 2026
    risk 0.44cvss 7.8epss 0.00

    better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec()…

  • CVE-2026-57944MedAug 22, 2026
    risk 0.35cvss 5.4epss 0.00

    AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying…

  • CVE-2026-56380MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.00

    AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by…

  • CVE-2026-4244MedAug 22, 2026
    risk 0.21cvss 4.3epss 0.00

    The Post Duplicator plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `duplicate_post()` function in all versions up to, and including, 3.0.11. This is due to the function not verifying that the user has…

  • CVE-2026-11948Aug 22, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-11947Aug 22, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-77988MedAug 22, 2026
    risk 0.43cvss 6.6epss 0.02

    A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration Tool. This manipulation causes command injection. The attack is possible to be carried out remotely. The exploit has been made…

  • CVE-2026-66917HigAug 22, 2026
    risk 0.56cvss —epss 0.01

    Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image causing JS execution in every visitor's browser.

  • CVE-2026-66916MedAug 22, 2026
    risk 0.45cvss —epss 0.00

    Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access control bypass exists in JoomGallery's category JSON view. When a gallery category is protected with a password, the HTML view…

  • CVE-2026-4245MedAug 22, 2026
    risk 0.21cvss 4.3epss 0.00

    The Post Duplicator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.0.11. This is due to the `duplicate_post_permissions()` permission callback only verifying the `duplicate_posts` capability without checking whether the…

  • CVE-2026-3424MedAug 22, 2026
    risk 0.27cvss 5.3epss 0.01

    The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.4.10.3. This is due to the software allowing users to execute an action that does not properly validate the…

  • CVE-2026-77946CriAug 22, 2026
    risk 0.65cvss 10.0epss 0.01

    A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/apply_time.cgi of the component NTP Timezone Configuration Handler. Executing a manipulation of the argument…

  • CVE-2026-77945HigAug 22, 2026
    risk 0.48cvss 7.4epss 0.02

    A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Performing a manipulation of the argument filename results in command injection. The attack may be initiated remotely. The exploit…

  • CVE-2026-78003CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including 2.2.0. This is due to insufficient input validation in the add_list() function, which accepts user-controlled array keys from…

  • CVE-2026-12710CriAug 22, 2026
    risk 0.60cvss —epss 0.00

    A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows an external attacker to access sensitive internal data. The issue was patched on April 4, 2026; no customer action is required.

  • CVE-2026-77002CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, allowing unauthenticated users to log in as any registered account, including administrators.

  • CVE-2026-77001CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or nonce checks in one of its publicly accessible login handlers, allowing unauthenticated attackers to obtain a valid session as any…

  • CVE-2026-77000CriAug 22, 2026
    risk 0.64cvss 9.8epss 0.01

    The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before authenticating a visitor, allowing unauthenticated attackers to log in as any existing user, including administrators, by…

  • CVE-2026-76793HigAug 22, 2026
    risk 0.53cvss 8.1epss 0.00

    The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including…

  • CVE-2026-76789HigAug 22, 2026
    risk 0.57cvss 8.8epss 0.01

    The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request handlers, and does not escape a stored setting before outputting it, allowing unauthenticated users to store malicious JavaScript…

  • CVE-2026-19222MedAug 22, 2026
    risk 0.43cvss 6.6epss 0.00

    The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing users who are permitted to build forms to configure one that assigns the administrator role to any visitor who registers through…

  • CVE-2026-19221HigAug 22, 2026
    risk 0.47cvss 7.2epss 0.01

    The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.

  • CVE-2026-19093MedAug 22, 2026
    risk 0.44cvss 6.8epss 0.00

    The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor role to read arbitrary files on the server, including files outside the web root. The readable files include the WordPress…

  • CVE-2026-18052HigAug 22, 2026
    risk 0.53cvss 8.1epss 0.00

    The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the…

  • CVE-2026-16738MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as…

  • CVE-2026-16612MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product…

  • CVE-2026-16260MedAug 22, 2026
    risk 0.44cvss 6.8epss 0.00

    The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript…

  • CVE-2026-14187LowAug 22, 2026
    risk 0.18cvss 2.7epss 0.00

    The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

  • CVE-2026-76074MedAug 22, 2026
    risk 0.28cvss 4.3epss 0.00

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is…