VYPR

CVEs

37,837 total · page 51 of 757

  • CVE-2026-73355CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

  • CVE-2026-73343CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

  • CVE-2026-73341CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

  • CVE-2026-73339CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

  • CVE-2026-73187CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

  • CVE-2026-66627CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in EDGE22 Studios Ltd. GP Premium allows Remote Code Inclusion. This issue affects GP Premium: from n/a through 2.5.5.

  • CVE-2026-59940CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without…

  • CVE-2026-32474CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

  • CVE-2026-32470CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

  • CVE-2026-32463CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

  • CVE-2026-32444CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.01

    Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

  • CVE-2026-28192CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.00

    Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

  • CVE-2026-75874CriAug 18, 2026
    risk 0.65cvss 10.0epss 0.00

    Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154, Thunderbird 154, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.

  • CVE-2026-75783CriAug 18, 2026
    risk 0.62cvss 9.6epss 0.01

    A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /sbin/netifd of the component DHCP blobmsg Handler. The manipulation leads to stack-based buffer overflow. The attack must be…

  • CVE-2026-74990CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-74989CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 154 and…

  • CVE-2026-74988CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in…

  • CVE-2026-74987CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This…

  • CVE-2026-74986CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74985CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74979CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74964CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74961CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.00

    Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74959CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74956CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.01

    Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74944CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74943CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74940CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-74938CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.00

    Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

  • CVE-2026-74936CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.01

    Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

  • CVE-2026-23933CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.00

    In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known exploitation scenario is for deployments that utilize both - SAML authentication and guest users. In such cases the key can be used…

  • CVE-2026-75854CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attackers to read, write, and delete data. Attackers can connect to the Redis port and execute arbitrary commands against any database on…

  • CVE-2026-75852CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers can issue insert, find, update, delete, and create commands against any database by connecting to port 27017 without credentials.

  • CVE-2026-75851CriAug 18, 2026
    risk 0.64cvss 9.9epss 0.00

    ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When an HTTP command is submitted with awaitResponse:false, it executes on an async worker whose DatabaseContext…

  • CVE-2026-75843CriAug 18, 2026
    risk 0.57cvss 9.9epss 0.00

    ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated readers to execute JavaScript commands without scripting authorization checks. Attackers can execute executeCommand with a…

  • CVE-2026-75837CriAug 18, 2026
    risk 0.52cvss 9.1epss 0.00

    Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-admin, gaining scheduler and Twig evaluation…

  • CVE-2026-75627CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings,…

  • CVE-2026-75626CriAug 18, 2026
    risk 0.60cvss 9.3epss 0.00

    SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the…

  • CVE-2026-34884CriAug 18, 2026
    risk 0.57cvss 9.8epss 0.01

    SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.

  • CVE-2026-15748CriAug 18, 2026
    risk 0.64cvss 9.8epss 0.06

    The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist…

  • CVE-2026-75094CriAug 18, 2026
    risk 0.59cvss 9.1epss 0.03

    A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the…

  • CVE-2026-67919CriAug 17, 2026
    risk 0.57cvss 9.8epss 0.01

    An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

  • CVE-2026-42164CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to recall the backed-up content from another Text section.

  • CVE-2026-42162CriAug 17, 2026
    risk 0.59cvss 9.1epss 0.01

    Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact in a page is manipulated.

  • CVE-2026-38165CriAug 17, 2026
    risk 0.57cvss 9.8epss 0.01

    A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows attackers to execute arbitrary code via a crafted expression.

  • CVE-2026-71424CriAug 17, 2026
    risk 0.55cvss 9.6epss 0.00

    Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info…

  • CVE-2026-67960CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components

  • CVE-2026-67868CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This allows a remote attacker to execute arbitrary code.

  • CVE-2026-67854CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

  • CVE-2026-64849CriKEVAug 17, 2026
    risk 0.66cvss 9.3epss 0.10

    MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in…