VYPR

CVEs

378,628 total · page 457 of 7,573

  • CVE-2026-67551HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

  • CVE-2026-67465HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-Dotnet: through 1.0.0. Users are recommended to upgrade to version 1.1.0, which fixes the issue.

  • CVE-2026-66839MedAug 5, 2026
    risk 0.44cvss 6.7epss 0.00

    NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

  • CVE-2026-66344MedAug 5, 2026
    risk 0.44cvss 6.7epss 0.00

    NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

  • CVE-2026-66273HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

  • CVE-2026-66257HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.

  • CVE-2026-5062MedAug 5, 2026
    risk 0.32cvss 4.9epss 0.00

    The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPress is vulnerable to SQL Injection via the 's' (search) parameter on the Pretty Links listing page in all versions up to, and including, 3.6.20. This is due…

  • CVE-2026-55707HigAug 5, 2026
    risk 0.46cvss —epss 0.00

    In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard subnets from another project's shared network into their own subnetpool, mutating the victim's subnet state and altering L3…

  • CVE-2026-18903MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This issue affects some unknown processing of the file src/main/java/com/yeqifu/sys/controller/FileController.java. This manipulation of the argument path causes path traversal. It…

  • CVE-2026-18902HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.02

    A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of the attack is…

  • CVE-2026-18322HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup…

  • CVE-2026-16143HigAug 5, 2026
    risk 0.40cvss 7.2epss 0.00

    The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field of the booking checkout form in versions up to, and including, 1.2.1. This is due to insufficient input sanitization and output…

  • CVE-2026-15941MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. The AJAX handler accepts a URL-encoded `args` parameter, parses it into a `WP_Query`, and then passes user-controlled taxonomy…

  • CVE-2026-15918HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.00

    VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls how the public reviews list is sorted is taken from the incoming request and used to build a database query without proper…

  • CVE-2026-11421MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilter' parameter in all versions up to, and including, 1.17.4 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2026-18901HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API. Such manipulation leads to exposed dangerous routine. The attack may be launched remotely. The exploit has been disclosed…

  • CVE-2026-18900HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.02

    A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit has been made…

  • CVE-2026-18898HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The manipulation of the argument timestart results in stack-based buffer overflow. The attack can be launched remotely. The exploit…

  • CVE-2026-18907HigAug 5, 2026
    risk 0.49cvss 7.5epss 0.01

    Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename.

  • CVE-2026-18897HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOneApConfTempEntry. The manipulation of the argument tempName leads to stack-based buffer overflow. The attack can be initiated…

  • CVE-2026-18896MedAug 5, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/changepass.php. Executing a manipulation of the argument oldpass can lead to sql injection. It is possible to launch the attack…

  • CVE-2026-18895HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performing a manipulation of the argument cipher results in stack-based buffer overflow. It is possible to initiate the attack remotely.…

  • CVE-2026-18859HigAug 5, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly…

  • CVE-2026-18856MedAug 5, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFile of the file modules/importer/importer.admin.controller.php of the component Data Import Module. This manipulation of the argument filename causes server-side…

  • CVE-2026-46334HigAug 5, 2026
    risk 0.50cvss —epss 0.00

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the SDP bandwidth-line parsing logic. A SIP request with Content-Type: application/sdp and a malformed session-level SDP…

  • CVE-2026-45809HigAug 5, 2026
    risk 0.50cvss —epss 0.00

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerability in the watcherinfo generation functionality. An attacker can create an oversized watcher entry by sending a SUBSCRIBE Event:…

  • CVE-2026-45705MedAug 5, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function in the multipart body parser performs an out-of-bounds read via strncmp() when searching for MIME boundary delimiters. After…

  • CVE-2026-18854HigAug 5, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClassByFilter of the file /Base/BaseService.asmx/DataService. The manipulation of the argument FilterString leads to sql injection.…

  • CVE-2026-18853MedAug 5, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the component com.zombodroid.MemeGenerator. Such manipulation leads to path traversal. Local access is required to approach this attack. The…

  • CVE-2026-18852LowAug 5, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability has been found in epsilla-cloud vectordb up to 0.3.18/df5a5f5afb85a2376a0f2f316c79dea9b2c6ac7a. This impacts the function SplitTokens/ShuntingYard of the file engine/query/expr/expr.cpp of the component Filter Parser. Such manipulation leads to improper check for…

  • CVE-2026-18103MedAug 5, 2026
    risk 0.32cvss 4.9epss 0.00

    A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Programming Interface) port, especially if not secured with TSIG (Transaction Signature) key authentication, could send a specially crafted lease creation request.…

  • CVE-2026-45537CriAug 4, 2026
    risk 0.52cvss 9.1epss 0.00

    OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concatenates multiple URI components (protocol, username, domain, port, params) into a fixed 1024-byte global BSS buffer without any…

  • CVE-2026-18819MedAug 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2026-18818MedAug 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Support Ticket Handler. Executing a manipulation can lead to authorization bypass. The attack can be executed…

  • CVE-2026-70620MedAug 4, 2026
    risk 0.37cvss 6.8epss 0.00

    Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network resources by supplying arbitrary URLs to the embedding endpoint configuration without scheme, host, IP range,…

  • CVE-2026-70619HigAug 4, 2026
    risk 0.50cvss 8.8epss 0.00

    Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin…

  • CVE-2026-70594MedAug 4, 2026
    risk 0.37cvss 6.7epss 0.00

    Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixation attacks. Successful exploitation would have required another vulnerability on the same domain where…

  • CVE-2026-70593MedAug 4, 2026
    risk 0.36cvss 6.6epss 0.00

    Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads directory. This could be used to alter the behavior of the installation through custom theme upload path traversal…

  • CVE-2026-70592MedAug 4, 2026
    risk 0.29cvss 5.5epss 0.00

    Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issues. The database export endpoint failed to…

  • CVE-2026-70591MedAug 4, 2026
    risk 0.20cvss 4.1epss 0.00

    Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was returned, but this could have been used to…

  • CVE-2026-70590MedAug 4, 2026
    risk 0.24cvss 4.8epss 0.00

    Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead to account takeover if successful, but…

  • CVE-2026-70589MedAug 4, 2026
    risk 0.24cvss 4.8epss 0.00

    Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.

  • CVE-2026-67862HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service.

  • CVE-2026-67861HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

  • CVE-2026-67860HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.

  • CVE-2026-67859HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

  • CVE-2026-67858HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated remote attacker can send a RegisterServer or RegisterServer2 request containing many unique…

  • CVE-2026-67857HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

  • CVE-2026-67856HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions requests

  • CVE-2026-67855HigAug 4, 2026
    risk 0.49cvss 7.5epss 0.00

    open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.