VYPR

CVEs

378,628 total · page 448 of 7,573

  • CVE-2026-14313MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-woocommerce), all versions up to and including 2.8.0 (latest on wordpress.org; no fixed version available at the time of writing), is…

  • CVE-2026-14240MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory with no access control, allowing unauthenticated users to download the exported customers' personal information once an…

  • CVE-2026-14204MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a logged-in user into overwriting their own 2FA secret with an attacker-controlled value, which enables two-factor authentication and…

  • CVE-2026-13703MedAug 6, 2026
    risk 0.35cvss 5.4epss 0.00

    The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any logged-in user such as a subscriber to read the site's configured 301 redirect rules, including their source and destination URLs.

  • CVE-2026-13154HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before querying it in one of its public REST routes, allowing unauthenticated users to read published entries of custom post types that the site…

  • CVE-2026-13153HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.01

    The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public WooCommerce per-product sales metric into the response, allowing unauthenticated users to read the lifetime number of units sold…

  • CVE-2026-12713CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by…

  • CVE-2026-11588MedAug 6, 2026
    risk 0.40cvss 6.1epss 0.00

    The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisation before saving the post, allowing unauthenticated attackers to create administrator-attributed published posts containing…

  • CVE-2025-15678MedAug 6, 2026
    risk 0.40cvss 6.1epss 0.00

    The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Author by default), allowing them to upload a file containing malicious JavaScript that executes when the file is accessed, leading to…

  • CVE-2026-19000HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The attack can be initiated remotely. The…

  • CVE-2026-18998MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper authorization. It is possible to launch the…

  • CVE-2026-18997MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrect authorization. It is possible to…

  • CVE-2026-15459HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.01

    The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that keys the WDP-AUTH request signature…

  • CVE-2026-18996MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Such manipulation leads to incorrect…

  • CVE-2026-18995MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information disclosure. The attack is possible to be…

  • CVE-2026-18993MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent/model_tools.py of the component Memory Toolset. The manipulation results in improper access controls. The attack can be executed…

  • CVE-2026-18992MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/executor.py of the component Self-Evolution Review Agent. Performing a manipulation results in incorrect authorization. The attack is…

  • CVE-2026-18909MedAug 6, 2026
    risk 0.31cvss 4.7epss 0.00

    A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and ETDSMBus.sys). During Intel SMBus recovery, ETDSMBus.sys does not enforce an upper-bound check on the hardware-derived report count, allowing an out-of-range…

  • CVE-2026-18325HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.00

    The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record via Select Field in all versions up to, and including, 1.56.1 due to insufficient input sanitization and output…

  • CVE-2026-16636HigAug 6, 2026
    risk 0.47cvss 7.2epss 0.00

    The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipient Display Name (to.name) in Email Logs in all versions up to, and including, 2.2.95 due to…

  • CVE-2026-15991HigAug 6, 2026
    risk 0.57cvss 8.8epss 0.01

    The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read…

  • CVE-2026-18991HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp-tools/core.ts of the component send_file. Such manipulation leads to path traversal. The attack can be executed remotely. The…

  • CVE-2026-18990HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Route. The manipulation results in missing authentication. The attack may be performed from remote. The exploit is now public and…

  • CVE-2026-18980MedAug 6, 2026
    risk 0.34cvss 6.3epss 0.01

    A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs. Such manipulation leads to command injection. The attack may be launched remotely. The exploit is publicly available and might…

  • CVE-2026-18976MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init.py of the component disabled_toolsets Handler. This manipulation causes incorrect privilege assignment. The attack may be…

  • CVE-2026-18974MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the component execute_tool_manually Endpoint. The manipulation of the argument tool_name/tool_params results in information disclosure. The…

  • CVE-2026-18973HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file server.py of the component extension_proxy Route. The manipulation of the argument url leads to server-side request forgery. The attack…

  • CVE-2026-67873CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the…

  • CVE-2026-67872HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling

  • CVE-2026-67871HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sopc_node_mgt_helper_internal.c, and toolkit_test_server

  • CVE-2026-67870CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing…

  • CVE-2026-67869HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input arguments against runtime-resolved InputArguments metadata

  • CVE-2026-67531CriAug 6, 2026
    risk 0.53cvss —epss 0.01

    FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own…

  • CVE-2026-52466CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not…

  • CVE-2026-19028MedAug 6, 2026
    risk 0.44cvss —epss 0.00

    H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows…

  • CVE-2026-19027MedAug 6, 2026
    risk 0.45cvss —epss 0.00

    The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows…

  • CVE-2026-18970HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to…

  • CVE-2026-18969HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the file /dm/dispatch/userinfo/upload. Performing a manipulation of the argument File results in unrestricted upload. It is possible to…

  • CVE-2026-18968MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting. The attack may be performed from…

  • CVE-2023-54389Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54388Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54387Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54386Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54385Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54384Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54383Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.

  • CVE-2023-54382Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54381Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54380Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.

  • CVE-2023-54379Aug 6, 2026
    risk 0.00cvss —epss —

    Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.