VYPR

CVEs

378,628 total · page 469 of 7,573

  • CVE-2026-59641MedAug 3, 2026
    risk 0.27cvss 5.3epss 0.00

    In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcmail-fips and bcjmail-fips 1.0.7 (1.0.X series),…

  • CVE-2026-59640MedAug 3, 2026
    risk 0.27cvss 5.3epss 0.00

    In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpg-fips 1.0.13 (1.0.X series), 2.0.13 (2.0.X series)…

  • CVE-2026-59639HigAug 3, 2026
    risk 0.42cvss 7.5epss 0.00

    In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series)…

  • CVE-2026-59638MedAug 3, 2026
    risk 0.35cvss 6.5epss 0.00

    In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bctls-fips 1.0.24 (1.0.X series), 2.0.24…

  • CVE-2026-18581LowAug 3, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected by this issue is some unknown functionality of the file common/jinja/parser.cpp of the component Jinja Minja Template Parser. Executing a manipulation with the input {{9|9|{ can lead to reachable assertion.…

  • CVE-2026-15055HigAug 3, 2026
    risk 0.46cvss 8.2epss 0.00

    In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java LTS before 2.73.12, and Bouncy Castle for Java FIPS (BC-FJA) before bcpkix-fips 1.0.12 (1.0.X series), 2.0.12 (2.0.X series) and…

  • CVE-2026-12185HigAug 3, 2026
    risk 0.49cvss 8.6epss 0.00

    In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Castle for Java LTS before 2.73.12.

  • CVE-2026-3245HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.00

    A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

  • CVE-2026-18577HigKEVAug 2, 2026
    risk 0.12cvss 8.1epss 0.54

    An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

  • CVE-2026-10848HigAug 2, 2026
    risk 0.39cvss 7.0epss 0.00

    The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helper, extract_string_field(), that copied the message's uid and action fields with strncpy(out_buf, token + 1, outlen - 1) and then…

  • CVE-2026-9856HigAug 2, 2026
    risk 0.39cvss 7.1epss 0.00

    A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue resides in the `save_pretrained()` methods of `PreTrainedTokenizerBase` and `ProcessorMixin`, where keys from the `chat_template`…

  • CVE-2026-65321CriAug 2, 2026
    risk 0.57cvss 9.8epss 0.01

    PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that…

  • CVE-2026-10774LowAug 2, 2026
    risk 0.09cvss 2.4epss 0.00

    Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_BEACONS (enabled by default), but…

  • CVE-2026-68583MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the…

  • CVE-2026-68582MedAug 2, 2026
    risk 0.35cvss 6.5epss 0.00

    Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1/projects/{project}/views/{view}/tasks). The endpoint loads the requested project view from the URL path without verifying the…

  • CVE-2026-68581HigAug 2, 2026
    risk 0.46cvss 8.1epss 0.00

    Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independent numeric sequences and both resolve through a generic web.Auth.GetID() interface, a link-share JWT whose numeric ID equals a…

  • CVE-2026-68580HigAug 2, 2026
    risk 0.42cvss 7.5epss 0.00

    FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket…

  • CVE-2026-68579CriAug 2, 2026
    risk 0.55cvss 9.6epss 0.00

    FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows/wf_cliprdr.c). When an OLE paste consumer (e.g. explorer.exe) calls IStream::Read with a fixed-size buffer of cb bytes,…

  • CVE-2026-68578HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently pass as no-ops. Non-root MCP-allowed users can perform arbitrary database writes, DDL, schema mutations, and execute arbitrary…

  • CVE-2026-67357HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.clusterToken in cleartext. Attackers with MCP access can retrieve the cluster token and use it with X-ArcadeDB-Cluster-Token and…

  • CVE-2026-67356HigAug 2, 2026
    risk 0.57cvss 8.8epss 0.00

    ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSecurity().createUser() without permission checks. Attackers with UPDATE_SCHEMA permission can create triggers that execute…

  • CVE-2025-71401MedAug 2, 2026
    risk 0.31cvss 5.9epss 0.00

    better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An attacker able to make the very first request to the server after startup can poison the router's base path, causing all routes to…

  • CVE-2025-71400HigAug 2, 2026
    risk 0.39cvss 7.1epss 0.00

    better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows authenticated users to delete arbitrary passkeys by ID. Attackers with valid sessions can submit crafted requests to the…

  • CVE-2025-71399HigAug 2, 2026
    risk 0.49cvss 8.6epss 0.00

    Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments, so /path, //path, and ///path resolve to the same route. In Better Auth versions prior to 1.4.5 (which bundles the fixed rou3),…

  • CVE-2026-12231MedAug 2, 2026
    risk 0.35cvss 6.4epss 0.00

    The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all versions up to, and including, 2.7.9.8 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-18573MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs when a realm administrator configures client policies to enforce specific authentication requirements on confidential clients. Due…

  • CVE-2026-18572MedAug 2, 2026
    risk 0.42cvss 6.5epss 0.00

    Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in their authorization request…

  • CVE-2026-18571MedAug 2, 2026
    risk 0.43cvss 6.6epss 0.00

    A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to…

  • CVE-2026-18570MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The issue occurs because the…

  • CVE-2026-16540HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own records, allowing unauthenticated users to retrieve the personal data of all appointments across the site and, on premium editions,…

  • CVE-2026-16292MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that…

  • CVE-2026-16291MedAug 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The ProfileGrid WordPress plugin before 5.9.9.8 does not verify that a notification belongs to the requesting user before deleting it, allowing any authenticated user such as a Subscriber to delete other users' notifications by enumerating notification identifiers.

  • CVE-2026-16285HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, allowing unauthenticated users to download any attachment — including private or unlinked uploads — by enumerating its numeric…

  • CVE-2026-16273MedAug 2, 2026
    risk 0.30cvss 4.6epss 0.00

    The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field or escape it when rendering, allowing users with contributor-level access and above to store JavaScript that executes in the browser of any higher-privileged…

  • CVE-2026-16261HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's…

  • CVE-2026-16256CriAug 2, 2026
    risk 0.64cvss 9.8epss 0.00

    The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers…

  • CVE-2026-16064MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the object being modified when quick-editing events, only checking a global capability, allowing users with the Contributor role and above to modify the title and…

  • CVE-2026-16063MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline content submitted by users with post-editing access before storing it and rendering it on the public event page, allowing users with the Author role and above to…

  • CVE-2026-16062MedAug 2, 2026
    risk 0.43cvss 6.6epss 0.00

    The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not prevent the deserialization of user-controlled input in some of its event content fields, allowing users with Contributor-level access and above to inject PHP objects. No POP chain is present in…

  • CVE-2026-16042MedAug 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The LWS Optimize WordPress plugin before 3.4 does not perform a capability check on its cache-clearing actions, allowing any authenticated user, including Subscribers, to flush the site's caches and force repeated cache rebuilds.

  • CVE-2026-15939LowAug 2, 2026
    risk 0.18cvss 2.7epss 0.00

    The Simple Restrict WordPress plugin before 1.2.9 does not enforce its content-restriction permission check on the REST API the way it does on the front end, relying there on a generic capability check instead of the Simple Restrict WordPress plugin before 1.2.9's own permission…

  • CVE-2026-15385MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-menu configuration and per-menu-item settings; its only gate is a nonce that any logged-in user can read from a standard admin page. A subscriber-level user can…

  • CVE-2026-15248MedAug 2, 2026
    risk 0.36cvss 5.5epss 0.00

    The Meta Box WordPress plugin before 5.13.1 does not verify that a user is authorized to delete the supplied attachment before deleting it, allowing users with a low-privilege role such as Contributor to permanently delete arbitrary media attachments belonging to other users.

  • CVE-2026-15241HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and,…

  • CVE-2026-15236HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The Gallery for Google Photos WordPress plugin before 1.2.1 does not properly restrict access to the stored third-party OAuth credentials of the connected account, exposing the persistent access and refresh tokens to unauthenticated users and allowing long-term compromise of…

  • CVE-2026-15206HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The SMS Alert WordPress plugin before 3.9.8 does not bind its "mobile verified" session flag to the phone number that was actually verified: after an attacker verifies an OTP sent to their own phone, the signup/login handler reads a fresh, attacker-supplied phone number to…

  • CVE-2026-15151HigAug 2, 2026
    risk 0.49cvss 7.5epss 0.00

    The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not perform a capability check on one of its AJAX actions, allowing users with the lowest booking-management role (which by default cannot access the Five Star Restaurant Reservations WordPress plugin…

  • CVE-2026-14938MedAug 2, 2026
    risk 0.28cvss 4.3epss 0.00

    The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages…

  • CVE-2026-14920HigAug 2, 2026
    risk 0.53cvss 8.2epss 0.00

    ## Summary

  • CVE-2026-14864MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its shortcodes, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks that execute in the context of higher-privileged…