VYPR

CVEs

384,091 total · page 396 of 7,682

  • CVE-2026-18052HigAug 22, 2026
    risk 0.53cvss 8.1epss 0.00

    The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the…

  • CVE-2026-16738MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bind the confirmed payment to the targeted order or verify its amount, allowing unauthenticated attackers to mark arbitrary orders as…

  • CVE-2026-16612MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.00

    The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, allowing unauthenticated users to disclose and enumerate password-protected products and their metadata without entering the product…

  • CVE-2026-16260MedAug 22, 2026
    risk 0.44cvss 6.8epss 0.00

    The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before outputting it in an HTML attribute on the admin edit screen, allowing users with the Contributor role and above to inject JavaScript…

  • CVE-2026-14187LowAug 22, 2026
    risk 0.18cvss 2.7epss 0.00

    The Tutor LMS WordPress plugin before 4.0.6 does not enforce per-object ownership checks on its course content type, allowing any user with the instructor role to read the content of private courses belonging to other instructors.

  • CVE-2026-76074MedAug 22, 2026
    risk 0.28cvss 4.3epss 0.00

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-76057MedAug 22, 2026
    risk 0.28cvss 4.3epss 0.00

    The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is…

  • CVE-2026-75027MedAug 22, 2026
    risk 0.34cvss 5.3epss 0.01

    The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…

  • CVE-2026-19883HigAug 22, 2026
    risk 0.50cvss 8.8epss 0.01

    The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the wpematico_import_settings function in all versions up to, and including, 2.8.24. This makes it…

  • CVE-2026-77781HigAug 22, 2026
    risk 0.42cvss 7.5epss 0.01

    Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the…

  • CVE-2026-16658impAug 22, 2026
    risk 0.64cvss 9.9epss —

    community.proxmox: community.general: community.proxmox: proxmox_pct_remote shel injection via unquoted pct exec command allows

  • CVE-2026-9052Aug 21, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-76069Aug 21, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-73323Aug 21, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-53541MedAug 21, 2026
    risk 0.21cvss 4.3epss 0.00

    OliveTin gives access to predefined shell commands from a web interface. The `filterToDefinedArgumentsOnly` function in the executor is intended to discard any arguments not explicitly defined in the action's configuration. However, prior to commit…

  • CVE-2026-53525HigAug 21, 2026
    risk 0.41cvss 7.4epss 0.00

    WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constant-time string comparison functions (weechat_strcasecmp and strcmp) to verify password hashes and plaintext passwords. An attacker…

  • CVE-2026-53524MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-deflate decompression function relay_websocket_inflate() has no upper bound on output size. An authenticated relay user can send a…

  • CVE-2026-53499HigAug 21, 2026
    risk 0.40cvss —epss 0.00

    FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versions through 1.6.7 contain an origin-validation error in their RRDP processing: a delegated CA under the same Trust Anchor Locator…

  • CVE-2026-49360HigAug 21, 2026
    risk 0.44cvss —epss 0.01

    Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the server to an untrusted network without authentication are vulnerable to unauthenticated SQL execution through the query run API. When…

  • CVE-2026-48106HigAug 21, 2026
    risk 0.47cvss —epss 0.00

    Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/cluster/replication/receiver.go` validates only the wire-format envelope (length, opcode) of inbound messages. The…

  • CVE-2026-48105HigAug 21, 2026
    risk 0.54cvss —epss 0.00

    Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals without validating them against the…

  • CVE-2026-48050HigAug 21, 2026
    risk 0.50cvss —epss 0.01

    Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` via `app.Use(pprof.New())` in `internal/api/server.go`, and `/debug/pprof` is added to `PublicPrefixes` in `cmd/arc/main.go`. The…

  • CVE-2026-47735HigAug 21, 2026
    risk 0.39cvss —epss 0.00

    Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQLRequest`) blocked only `read_parquet(` and `arc_partition_agg(` via regex denylist. The broader DuckDB I/O function family —…

  • CVE-2026-34949MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a file created during the setup process that prevents users from performing write actions. This issue has been fixed in version…

  • CVE-2026-34948HigAug 21, 2026
    risk 0.43cvss 7.7epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access check in OQL. This issue has been fixed in version 3.2.3.

  • CVE-2026-11805Aug 21, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-11615Aug 21, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-11609Aug 21, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-11418Aug 21, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-53531MedAug 21, 2026
    risk 0.38cvss —epss 0.00

    RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\left`, `\sqrt{`, `^{`, etc, with no maximum depth limit. A short, ~10 KB input of…

  • CVE-2026-53530HigAug 21, 2026
    risk 0.50cvss —epss 0.00

    RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` panics on the 9-byte input `\verbéxé` (i.e. `\verb` followed by the non-ASCII delimiter `é`). When handling a `\verb` command,…

  • CVE-2026-53529MedAug 21, 2026
    risk 0.31cvss —epss 0.00

    LeafWiki is a self-hosted wiki. Prior to version 0.10.2, page titles returned by the search API could be rendered as raw HTML in the frontend. A user with editor or administrator permissions could create or modify a page title containing an HTML/JavaScript payload. When another…

  • CVE-2026-53528HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.01

    LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authenticated user with editor permissions could move files that are accessible to the LeafWiki server process into a page’s asset…

  • CVE-2026-53527HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.00

    LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user could update their own account role and escalate privileges from a regular user, such as `viewer`, to `admin`. Exploitation…

  • CVE-2026-53509MedAug 21, 2026
    risk 0.30cvss 5.7epss 0.00

    CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and sparql_query that accept a base_url parameter had the risk of making HTTP requests to arbitrary endpoints without restriction. A…

  • CVE-2026-53497MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the other_sessions array, which exposes metadata of all active sessions — including originating IP addresses, User-Agent strings,…

  • CVE-2026-53487MedAug 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated Kite users with any role can request `/api/v1/overview` for a cluster that their roles do not permit by selecting that cluster with `x-cluster-name`. The overview route is registered before…

  • CVE-2026-53468MedAug 21, 2026
    risk 0.23cvss 4.6epss 0.00

    Typemill is a flat-file, Markdown-based content management system designed for informational documentation websites. Versions prior to 2.23.0 are vulnerable to stored HTML attribute injection in the page metadata fields (`og:title` and `og:description`). An authenticated user…

  • CVE-2026-49849CriAug 21, 2026
    risk 0.52cvss 9.1epss 0.01

    xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administrator to upload executable files (e.g., .php). By uploading a specially crafted php file, an attacker can achieve Remote Code…

  • CVE-2026-43980MedAug 21, 2026
    risk 0.34cvss 6.3epss 0.00

    Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, short_name) received via MQTT are stored in SQLite without sanitization and rendered into the DOM without escaping. Any…

  • CVE-2026-34836MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for document access without checking on user permissions. This issue has been fixed in version 3.2.3.

  • CVE-2026-34741HigAug 21, 2026
    risk 0.49cvss 8.6epss 0.01

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbitrary PHP files from the env-production directory on a new iTop instance in the production environment. This issue has been fixed…

  • CVE-2026-33333LowAug 21, 2026
    risk 0.16cvss 3.5epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is sensitive information disclosure in the error messages. This issue has been fixed in version 3.2.3.

  • CVE-2026-33240HigAug 21, 2026
    risk 0.50cvss 8.8epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This issue has been fixed in version 3.2.3.

  • CVE-2026-33047MedAug 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3.

  • CVE-2026-31936HigAug 21, 2026
    risk 0.50cvss 8.8epss 0.00

    Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operation. This issue has been fixed in version 3.2.3.

  • CVE-2026-77811HigAug 21, 2026
    risk 0.57cvss 8.7epss 0.01

    Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions to OpenSearch Dashboards saved objects to execute arbitrary JavaScript in the context of other users' browser sessions by uploading…

  • CVE-2026-77415CriAug 21, 2026
    risk 0.54cvss —epss 0.01

    JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weaknesses to execute arbitrary code. The chain could overwrite $clone to mutate objects through evaluateTransformExpression, expose…

  • CVE-2026-77414CriAug 21, 2026
    risk 0.53cvss —epss 0.01

    JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOwnProperty check. Crafted expressions could use $hasOwnProperty, $spread, $string, prototype access, and $constructor to reach the…

  • CVE-2026-77413CriAug 21, 2026
    risk 0.54cvss —epss 0.01

    JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwnProperty check and allowed crafted expressions to access inherited prototype members. An attacker able to supply an expression…