VYPR

CVEs

385,816 total · page 516 of 7,717

  • CVE-2026-15162HigAug 15, 2026
    risk 0.49cvss 7.5epss 0.01

    The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push…

  • CVE-2026-15001HigAug 15, 2026
    risk 0.57cvss 8.8epss 0.01

    The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions `save_bloyal_configuration_data` and `save_bloyal_accesskeyverification_data` being registered…

  • CVE-2026-14484CriAug 15, 2026
    risk 0.59cvss 9.1epss 0.01

    The RapiSafe – Secure Multi File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the handleAjaxRemoveUpload function in all versions up to, and including, 1.0.4. This makes it possible for…

  • CVE-2026-14433HigAug 15, 2026
    risk 0.47cvss 7.2epss 0.00

    The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-12128MedAug 15, 2026
    risk 0.34cvss 5.3epss 0.01

    The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to Price Manipulation via the `cart_data` parameter in all versions up to, and including, 2.9.9.6.8. This is due to the `dopbsp_woocommerce_add_to_cart` AJAX action being registered via…

  • CVE-2026-74250MedAug 14, 2026
    risk 0.41cvss 6.3epss 0.00

    In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment with, or changing to, the autodetect deploy interface.

  • CVE-2026-74247MedAug 14, 2026
    risk 0.27cvss 4.2epss 0.00

    A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests…

  • CVE-2026-74245MedAug 14, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Red Hat Quay's exported logs feature. An unauthenticated attacker with a valid file ID could download exported action logs without proper authorization. While file IDs are complex, they can be intercepted from plaintext email or webhook callbacks. This…

  • CVE-2026-74244MedAug 14, 2026
    risk 0.38cvss 5.9epss 0.00

    A flaw was found in Red Hat Quay's Stripe billing webhook handler. This vulnerability allows an unauthenticated attacker to forge billing events by sending crafted JSON requests to the `/webhooks/stripe` endpoint without validating the Stripe-Signature header. Successful…

  • CVE-2026-74243MedAug 14, 2026
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST requests to the security scanner notification endpoint. This allows the attacker to flood the notification queue and inject path…

  • CVE-2026-74242MedAug 14, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (UUID), can read the notification configuration, including sensitive details like webhook URLs, Slack tokens, and email addresses.…

  • CVE-2026-74241MedAug 14, 2026
    risk 0.31cvss 4.8epss 0.00

    A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When an LDAP referral is returned during authentication, the system does not properly escape the username input. This allows an attacker to inject LDAP filter…

  • CVE-2026-74240MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple issues related to audience verification and the enforcement of `azp` and `sub` claims were identified. These flaws could allow an…

  • CVE-2026-63650LowAug 14, 2026
    risk 0.06cvss —epss 0.00

    OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

  • CVE-2026-63649MedAug 14, 2026
    risk 0.20cvss —epss 0.00

    The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks

  • CVE-2026-18932Aug 14, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-73683HigAug 14, 2026
    risk 0.46cvss 8.1epss 0.01

    Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php.…

  • CVE-2026-69414HigAug 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".

  • CVE-2026-74248MedAug 14, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) policy authorization. By associating another project's QoS policy with an amphora, an authenticated user may prevent deletion of that policy. All Octavia deployments are affected.

  • CVE-2026-73682Aug 14, 2026
    risk 0.00cvss —epss 0.02

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. CVE-2026-73294 published by GitHub

  • CVE-2026-71570MedAug 14, 2026
    risk 0.33cvss —epss 0.00

    Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_icagenda` only could enumerate Joomla user profiles.

  • CVE-2026-67366MedAug 14, 2026
    risk 0.34cvss —epss 0.00

    Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.

  • CVE-2026-50523HigAug 14, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

  • CVE-2026-73680HigAug 14, 2026
    risk 0.50cvss 8.8epss 0.03

    Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The…

  • CVE-2026-71571HigAug 14, 2026
    risk 0.56cvss —epss 0.00

    Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

  • CVE-2026-67365CriAug 14, 2026
    risk 0.60cvss —epss 0.00

    Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

  • CVE-2026-64887HigAug 14, 2026
    risk 0.46cvss —epss 0.00

    Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1.

  • CVE-2026-39925Aug 14, 2026
    risk 0.00cvss —epss —

    Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

  • CVE-2026-34492HigAug 14, 2026
    risk 0.46cvss —epss 0.00

    External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1.

  • CVE-2026-27871LowAug 14, 2026
    risk 0.19cvss —epss 0.00

    Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63.

  • CVE-2026-19910HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.00

    PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit…

  • CVE-2026-19909HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. …

  • CVE-2026-19908HigAug 14, 2026
    risk 0.46cvss 7.1epss 0.00

    PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this…

  • CVE-2026-18554HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-18178MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

  • CVE-2026-17227MedAug 14, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of special elements used in an SQL command.

  • CVE-2026-17209MedAug 14, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.

  • CVE-2026-17186CriAug 14, 2026
    risk 0.64cvss 9.9epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special elements in a command.

  • CVE-2026-17184CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

  • CVE-2026-17182CriAug 14, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improper validation of request URI path segments.

  • CVE-2026-17181CriAug 14, 2026
    risk 0.60cvss 9.3epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

  • CVE-2026-17179HigAug 14, 2026
    risk 0.55cvss 8.5epss 0.03

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.

  • CVE-2026-17177HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

  • CVE-2026-17175HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

  • CVE-2026-17173MedAug 14, 2026
    risk 0.42cvss 6.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file paths.

  • CVE-2026-17081HigAug 14, 2026
    risk 0.53cvss 8.2epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-17079MedAug 14, 2026
    risk 0.41cvss 6.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to the ability to disable server-side input validation via a request parameter.

  • CVE-2026-16915HigAug 14, 2026
    risk 0.49cvss 7.5epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.

  • CVE-2026-16905MedAug 14, 2026
    risk 0.34cvss 5.3epss 0.00

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication.

  • CVE-2026-16879HigAug 14, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.