VYPR

CVEs

378,655 total · page 495 of 7,574

  • CVE-2026-65890CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL in queries.

  • CVE-2026-65889HigJul 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delete directories.

  • CVE-2026-55995HigJul 29, 2026
    risk 0.42cvss —epss 0.00

    A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

  • CVE-2026-18174MedJul 29, 2026
    risk 0.34cvss 5.3epss 0.00

    @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma separated entries, the parser trims only space characters and does not strip horizontal tabs, even though RFC 7230 defines optional…

  • CVE-2026-16751MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured as a victim's emergency contact to bypass the configured recovery waiting period and take over the victim's account via a crafted…

  • CVE-2026-65946MedJul 29, 2026
    risk 0.40cvss 6.1epss 0.00

    Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

  • CVE-2026-65944HigJul 29, 2026
    risk 0.57cvss 8.8epss 0.00

    Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

  • CVE-2026-65943HigJul 29, 2026
    risk 0.49cvss 7.5epss 0.00

    Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0

  • CVE-2026-65891MedJul 29, 2026
    risk 0.42cvss 6.5epss 0.00

    Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.20.2 - Improper input validation in the file rename functionality allowed an authenticated user with file management…

  • CVE-2026-65885HigJul 29, 2026
    risk 0.57cvss 8.8epss 0.00

    Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to upload arbitrary files. Turns into an authenticated RCE if combined with CVE-2026-65884 as the required account can be created by the…

  • CVE-2026-65884CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing unauthenticated actors to register new accounts with administrative permissions.

  • CVE-2026-50641HigJul 29, 2026
    risk 0.00cvss —epss 0.00

    Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.

  • CVE-2026-44944HigJul 29, 2026
    risk 0.44cvss —epss 0.00

    An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

  • CVE-2026-44943MedJul 29, 2026
    risk 0.49cvss —epss 0.00

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through…

  • CVE-2026-33385MedJul 29, 2026
    risk 0.00cvss —epss 0.00

    A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multiple fields in administration panel allows for Blind SQL Injection attacks. The vendor states that this administration panel…

  • CVE-2026-14354HigJul 29, 2026
    risk 0.00cvss —epss 0.00

    CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and…

  • CVE-2026-12927HigJul 29, 2026
    risk 0.51cvss —epss 0.00

    CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.

  • CVE-2026-0667CriJul 29, 2026
    risk 0.00cvss —epss 0.00

    CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.

  • CVE-2026-14270HigJul 29, 2026
    risk 0.00cvss 8.8epss 0.01

    The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.3.2. This is due to missing authorization and nonce validation in the eco_save_settings()…

  • CVE-2026-8791MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17 due to a missing capability check on the `set_options` AJAX action when the plugin is operating in agency…

  • CVE-2026-7436MedJul 29, 2026
    risk 0.00cvss 6.4epss 0.00

    The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_best_seller` shortcode in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping on user…

  • CVE-2026-6089MedJul 29, 2026
    risk 0.00cvss 4.9epss 0.00

    The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in imported JSON files in all versions up to, and including, 2.1.2. This is due to the import_sidebars() function passing user-supplied URLs from imported JSON data to…

  • CVE-2026-65883CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.01

    Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

  • CVE-2026-5060MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    The MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.7.14. This is due to the `stm_lms_delete_cover()` function lacking ownership validation on the…

  • CVE-2026-56390MedJul 29, 2026
    risk 0.41cvss 6.3epss 0.00

    GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this…

  • CVE-2026-56389HigJul 29, 2026
    risk 0.56cvss 8.6epss 0.00

    GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc,…

  • CVE-2026-50642MedJul 29, 2026
    risk 0.31cvss —epss 0.00

    diff‑so‑fancy does not properly sanitize non‑SGR terminal control sequences before outputting diff data. The application only strips ANSI SGR sequences while allowing other control characters, including carriage return (\r) and escape sequences (e.g., OSC, CSI), to pass…

  • CVE-2026-4604MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    The Klubraum Membership Request plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `kr_mr_store_settings()` function in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to…

  • CVE-2026-18220HigJul 29, 2026
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled…

  • CVE-2026-16655HigJul 29, 2026
    risk 0.00cvss 7.2epss 0.00

    The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Name Field Nested `password` Member in all versions up to, and including, 6.2.7 due to insufficient input…

  • CVE-2026-16597HigJul 29, 2026
    risk 0.00cvss 7.2epss 0.00

    The GTM4WP – A Google Tag Manager (GTM) plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via WooCommerce Billing Fields in all versions up to, and including, 1.22.3 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-14900CriJul 29, 2026
    risk 0.00cvss 9.8epss 0.01

    The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to_php function. This is due to insufficient sanitization of the orderDetails[*].originalValue field, which is injected verbatim…

  • CVE-2026-14488CriJul 29, 2026
    risk 0.00cvss 9.1epss 0.00

    The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission extension in versions up to, and including, 3.8.0. This is due to the handle_request() function routing the mbfs_delete action without…

  • CVE-2026-12895HigJul 29, 2026
    risk 0.00cvss —epss 0.00

    SQL injection in Frappe's ERPNext, versions ERPNext 15.107.0 and Frappe 15.107.2. The application constructs SQL queries through direct string interpolation using `str.format()` without employing parameterized queries, allowing the name (docname) of a Supplier record containing…

  • CVE-2026-65100MedJul 29, 2026
    risk 0.24cvss 4.8epss 0.00

    Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache…

  • CVE-2026-59243CriJul 29, 2026
    risk 0.64cvss 9.8epss 0.00

    The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or unsigned (`alg:none`) ID token to the OAuth callback could bypass authentication and log in as an arbitrary user, including one…

  • CVE-2026-58189HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to…

  • CVE-2026-58188HigJul 29, 2026
    risk 0.46cvss 8.2epss 0.00

    Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or…

  • CVE-2026-58187LowJul 29, 2026
    risk 0.17cvss 3.7epss 0.00

    The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of service. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to…

  • CVE-2026-58186HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version…

  • CVE-2026-58185MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.00

    The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

  • CVE-2026-58184HigJul 29, 2026
    risk 0.46cvss 8.2epss 0.00

    The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to…

  • CVE-2026-58183MedJul 29, 2026
    risk 0.31cvss 5.9epss 0.00

    The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or…

  • CVE-2026-58182HigJul 29, 2026
    risk 0.49cvss 8.6epss 0.00

    The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version…

  • CVE-2026-58181HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version…

  • CVE-2026-58180HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4,…

  • CVE-2026-58179HigJul 29, 2026
    risk 0.46cvss 8.1epss 0.00

    The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15…

  • CVE-2026-58178HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or…

  • CVE-2026-58177HigJul 29, 2026
    risk 0.46cvss 8.1epss 0.00

    The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.

  • CVE-2026-58175HigJul 29, 2026
    risk 0.42cvss 7.5epss 0.00

    Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.