VYPR

CVEs

384,119 total · page 401 of 7,683

  • CVE-2026-16650MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, allowing unauthenticated attackers to forge webhook notifications that mark donations as paid without any real payment.

  • CVE-2026-15150MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured merchant account, allowing unauthenticated attackers to have arbitrary amounts of the site's in-site currency credited to an…

  • CVE-2026-15046MedAug 21, 2026
    risk 0.27cvss 4.2epss 0.00

    The LitExtension WordPress plugin through 1.2.5 does not verify a nonce before an administrative action that overwrites the store-migration connector's authentication token, allowing attackers to take over the connector token by tricking a logged-in administrator into clicking a…

  • CVE-2026-13176LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    The Eventin WordPress plugin before 4.1.21 does not validate a user-supplied webhook URL stored on events nor verify event ownership, allowing users with contributor-level access and above to trigger blind server-side requests to arbitrary hosts.

  • CVE-2026-77769MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboardId). The enforceAccess middleware in packages/trpc/src/trpc.ts verified membership for the supplied projectId, but nothing…

  • CVE-2026-77768MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.00

    The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAccess middleware in packages/trpc/src/trpc.ts evaluates membership only when the input carries a projectId or organizationId key,…

  • CVE-2026-77767HigAug 21, 2026
    risk 0.42cvss 7.5epss 0.00

    Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role, so controllers without their own attribute reject anonymous callers. The report preview action in…

  • CVE-2026-77763MedAug 21, 2026
    risk 0.35cvss 6.5epss 0.01

    The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from path(key), which returned either filepath.Join(d.root, key) or filepath.Clean(d.root + key) with no check that the result stayed…

  • CVE-2026-77761MedAug 21, 2026
    risk 0.34cvss —epss 0.01

    A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused. Several STIX 1 and STIX 2 parser…

  • CVE-2026-77686MedAug 21, 2026
    risk 0.28cvss 5.4epss 0.00

    A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This manipulation of the argument ID causes improper authorization. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-77683CriAug 21, 2026
    risk 0.64cvss 9.9epss 0.03

    A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET&section=ntp_timezone. The manipulation of the argument timestr results in command injection. The attack can be launched…

  • CVE-2026-77086CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers with admin access can write arbitrary files to any location…

  • CVE-2026-59296MedAug 21, 2026
    risk 0.38cvss 5.9epss 0.00

    Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-purpose instrumentation should never perform. Micrometer 1.17.0 Micrometer 1.16.0 - 1.16.6 Micrometer 1.15.0 - 1.15.12 Micrometer…

  • CVE-2026-15576MedAug 21, 2026
    risk 0.38cvss —epss 0.00

    Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate verification of relay endpoints by supplying a fixed placeholder identity in the request URL, resulting in limited impact on…

  • CVE-2026-14208HigAug 21, 2026
    risk 0.47cvss —epss 0.00

    Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), granting FULL CONTROL (F) to the built-in Everyone group (BUILTIN\Everyone, S-1-1-0). A Windows service running as NT…

  • CVE-2026-77755HigAug 21, 2026
    risk 0.50cvss —epss 0.00

    A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code used sys.exit() to handle several parsing and loading failures. Because SystemExit inherits from BaseException rather than…

  • CVE-2026-77751HigAug 21, 2026
    risk 0.50cvss —epss 0.01

    A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. MISP object names are passed to PyMISP's object-template resolution mechanism, which constructs a filesystem path by joining the configured MISP…

  • CVE-2026-77681MedAug 21, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/update-profile.php. The manipulation of the argument Name leads to unrestricted upload. The attack can be initiated remotely. The…

  • CVE-2026-59323MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded object allocation when extracting incoming baggage headers. Micrometer Tracing 1.7.0 Micrometer Tracing 1.6.0 - 1.6.6 Micrometer…

  • CVE-2026-48590LowAug 21, 2026
    risk 0.07cvss —epss 0.00

    XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.element/1,…

  • CVE-2026-47827HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.02

    Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vulnerabilities

  • CVE-2026-47080LowAug 21, 2026
    risk 0.07cvss —epss 0.00

    XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, XML Injection. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1, XmlBuilder.generate/2, XmlBuilder.escape/1. The…

  • CVE-2026-47079LowAug 21, 2026
    risk 0.07cvss —epss 0.00

    Inappropriate Encoding for Output Context vulnerability in joshnuss xml_builder (XmlBuilder module) allows Content Spoofing, Cross-site Scripting. This vulnerability is associated with program files lib/xml_builder.ex and program routines XmlBuilder.generate/1,…

  • CVE-2026-77710MedAug 21, 2026
    risk 0.38cvss —epss 0.00

    A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX import logic automatically selected between the internal MISP parser and the external STIX parser based on metadata contained in the…

  • CVE-2026-74866MedAug 21, 2026
    risk 0.38cvss 5.8epss 0.00

    @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-return line-feed sequence, so a lone carriage return or line feed embedded in a part header is not treated as a line break and is…

  • CVE-2026-68745HigAug 21, 2026
    risk 0.53cvss 8.1epss 0.00

    Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a SAML response to the management server. The agent will have to spoof the ip address of the IdP or get an url of its own choosing…

  • CVE-2026-66797MedAug 21, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listAnnotation APIs perform an ownership check when an entity's UUID is specified, but fail to honor its result correctly. This lets…

  • CVE-2026-66722HigAug 21, 2026
    risk 0.47cvss 7.2epss 0.01

    Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can create, update, delete, and list project roles and project role permissions for projects in any domain, not just their own. The check…

  • CVE-2026-66721LowAug 21, 2026
    risk 0.18cvss 2.7epss 0.00

    Missing authorization issue for domain admins in CloudStack's host tags listing functionality. Domain Admins, by default, have permission to call the listHostTags API, but the API returns host tags for every host in the environment without domain scoping. It should instead…

  • CVE-2026-65613MedAug 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Webhook module while listing and deleting deliveries. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended…

  • CVE-2026-63046HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager executes arbitrary shell commands via ExcuteLinux.exeCmd() with no filtering or whitelist validation. This issue affects Apache…

  • CVE-2026-62440CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cluster while adding and removing nodes. This issue affects Apache CloudStack: from 4.21.0.0 through 4.22.1.0. Users are…

  • CVE-2026-61422MedAug 21, 2026
    risk 0.28cvss 4.3epss 0.00

    Authenticated pre-validation SSRF vulnerability in Apache CloudStack's template and ISO registration functionality. When registering a template or ISO, CloudStack makes a live HTTP HEAD/GET call to determine file size for secondary storage usage-limit checks, and this happens…

  • CVE-2026-61400HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.03

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics functionality for the system VMs and virtual routers. An authenticated user holding the permissions required to invoke either…

  • CVE-2026-61399MedAug 21, 2026
    risk 0.31cvss 4.8epss 0.01

    Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or…

  • CVE-2026-61398CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affects Apache CloudStack: from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to…

  • CVE-2026-61397HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are…

  • CVE-2026-59799HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.01

    Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication disable flow. This issue affects Apache CloudStack: from 4.18.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are…

  • CVE-2026-59780HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP providers. LDAP configurations can be listed by any authenticated user with access to the listLdapConfigurations API. By…

  • CVE-2026-59657HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.00

    Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache CloudStack: from 4.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to version 4.20.3.1 or…

  • CVE-2026-59655HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth providers. This issue affects Apache CloudStack: from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are…

  • CVE-2026-59085CriAug 21, 2026
    risk 0.59cvss 9.1epss 0.01

    Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affects Apache CloudStack: from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. Users are recommended to upgrade to…

  • CVE-2026-50222HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Several userdata-related APIs in Apache CloudStack, including deleteUserData, linkUserDataToTemplate, resetUserDataForVirtualMachine,…

  • CVE-2026-50112HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.01

    SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing internal targets. The Secondary Storage VM will retrieve the data and persist it as a template file, which can later be…

  • CVE-2026-47359HigAug 21, 2026
    risk 0.57cvss 8.8epss 0.02

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider plugin. The addBackupRepository API (available since 4.20.0.0) and updateBackupRepository API (introduced in 4.22.0.0) accept…

  • CVE-2026-77264CriAug 21, 2026
    risk 0.64cvss 9.8epss 0.01

    The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic…

  • CVE-2026-73537MedAug 21, 2026
    risk 0.31cvss 4.7epss 0.00

    Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary script may be executed in the browser component (WebView) running on the affected product, resulting in the displayed content being altered.

  • CVE-2026-19441MedAug 21, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026.  NOTE: The vendor was contacted and it was learned that the product is not supported.

  • CVE-2026-16323HigAug 21, 2026
    risk 0.49cvss 7.5epss 0.01

    Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass. This issue affects ArchitectPanel Web Admin Panel: through 28072026.

  • CVE-2026-75796HigAug 21, 2026
    risk 0.47cvss 7.2epss 0.00

    The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing privileged user management operations, allowing users with the Administrator role on a Multisite sub-site to take over any account…