VYPR

CVEs

386,275 total · page 583 of 7,726

  • CVE-2026-21064MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

  • CVE-2026-21063MedAug 10, 2026
    risk 0.40cvss 6.1epss 0.00

    Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.

  • CVE-2026-64940HigAug 10, 2026
    risk 0.56cvss 8.6epss 0.00

    Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular expression, which may allow an attacker who can access the affected product to log in to the management console. As a result, the attacker may perform any…

  • CVE-2026-57279MedAug 10, 2026
    risk 0.44cvss 6.8epss 0.00

    Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed in the web browser of a user logged in to the product.

  • CVE-2026-21062LowAug 10, 2026
    risk 0.21cvss 3.3epss 0.00

    Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 allows local attackers to access clipboard data.

  • CVE-2026-21061MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    Improper input validation in Samsung Dialer prior to SMR Aug-2026 Release 1 allows remote attackers to access SIM related functions. User interaction is required for triggering this vulnerability.

  • CVE-2026-21060MedAug 10, 2026
    risk 0.30cvss 4.6epss 0.00

    Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data across multiple user profiles.

  • CVE-2026-21059HigAug 10, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

  • CVE-2026-21058HigAug 10, 2026
    risk 0.46cvss 7.1epss 0.00

    Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.

  • CVE-2026-19089CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left empty, which its own documentation advertises as accepting all files, allowing unauthenticated attackers to upload arbitrary files…

  • CVE-2026-19077MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    The Duplicate Post WordPress plugin before 1.5.5 does not perform per-object authorisation checks in its bulk copy and delete operations, allowing any user whose role an administrator has granted Duplicate Post WordPress plugin before 1.5.5 access to permanently delete arbitrary…

  • CVE-2026-19075MedAug 10, 2026
    risk 0.33cvss 5.0epss 0.00

    All-in-One Video Gallery registers a public, unauthenticated file-download handler triggered by `?vdl=<post_id>` on any `aiovg_videos` post (`public/video.php`, `AIOVG_Public_Video::download_video()`), which reads the post's `mp4` meta value and streams that URL's response back…

  • CVE-2026-19074MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticated sensitive information exposure via the AJAX action `acadp_public_custom_fields_listings`.

  • CVE-2026-19053CriAug 10, 2026
    risk 0.59cvss 9.1epss 0.00

    The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.

  • CVE-2026-19049HigAug 10, 2026
    risk 0.56cvss 8.6epss 0.01

    The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the…

  • CVE-2026-18960MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.

  • CVE-2026-18946HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a publicly accessible directory, allowing unauthenticated attackers to enumerate and download files submitted by other users.

  • CVE-2026-18934MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    The RSS Aggregator by Feedzy WordPress plugin before 5.2.6 does not verify that the requesting user owns or is allowed to edit the import job named in the request, allowing users with author-level access and above to permanently delete the posts created by another user's import…

  • CVE-2026-18786HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.01

    The CheckView WordPress plugin before 2.3.2 does not restrict its REST API authentication filter to its own routes and unconditionally discards the authentication error raised for any request whose URI merely contains a CheckView WordPress plugin before 2.3.2-specific string,…

  • CVE-2026-18666MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    The Library Management System WordPress plugin before 3.6.7 does not sanitize and escape a user-supplied parameter before using it in a SQL statement, allowing users with a role as low as Subscriber to perform SQL injection and extract arbitrary data from the database, including…

  • CVE-2026-18470HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email…

  • CVE-2026-18469HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The Login & Register Forms WordPress plugin before 4.0.2 does not enforce its password reset attempt limit against a server-derived value, keying both the verification code and the per-source attempt counter on client-controlled data, allowing unauthenticated attackers to reset…

  • CVE-2026-18468HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take…

  • CVE-2026-18200MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    The FoodBoxBooker WordPress plugin before 1.0.8 does not verify that the user account being updated belongs to the user making the request, allowing authenticated users, with Subscriber-level access and above, to modify the profile details of arbitrary users, including…

  • CVE-2026-18030HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The BricksForge WordPress plugin before 3.1.8.8 does not verify the identity of the requester when processing a password change submitted through one of its form actions, allowing unauthenticated attackers to set an arbitrary password for any user, including administrators, and…

  • CVE-2026-17542HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types…

  • CVE-2026-17541HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who…

  • CVE-2026-17540HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.00

    The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of…

  • CVE-2026-17023MedAug 10, 2026
    risk 0.31cvss 4.8epss 0.00

    The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth state value on its Google Calendar authorization callback, which is also hooked for unauthenticated users, allowing an unauthenticated attacker to overwrite the…

  • CVE-2026-17022HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wizard confirmation steps, allowing unauthenticated attackers to disclose other customers' booking records, including personal…

  • CVE-2026-17021MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modification AJAX actions and does not verify ownership of the targeted booking, allowing unauthenticated users to tamper with the stored total of arbitrary…

  • CVE-2026-17020MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    The Salon Booking System WordPress plugin through 10.31.0 does not verify that a requested booking belongs to the caller on one of its REST API endpoints, requiring only a basic read capability, allowing any authenticated user (including a Subscriber or self-registered customer…

  • CVE-2026-17019MedAug 10, 2026
    risk 0.40cvss 6.1epss 0.00

    The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict who can upload them, allowing unauthenticated attackers to upload a file containing malicious JavaScript that executes in the…

  • CVE-2026-17018MedAug 10, 2026
    risk 0.32cvss 4.9epss 0.00

    The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restrict which metadata keys may be requested, on one of its REST API endpoints, allowing users with the Contributor role and above to read arbitrary post metadata…

  • CVE-2026-17016LowAug 10, 2026
    risk 0.24cvss 3.7epss 0.00

    The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amount actually paid against the order total in its PayPal Data Transfer return handler, allowing a customer to pay less than the order total and still have the…

  • CVE-2026-17012MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the PayPal account which received a payment matches the merchant's configured account before marking the order as paid, allowing unauthenticated buyers to complete a…

  • CVE-2026-17010MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing users with contributor-level access and above to inject stored Cross-Site Scripting payloads that execute in the browser of a…

  • CVE-2026-16985HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.01

    The Squeeze WordPress plugin before 1.7.12 does not validate the file type or extension of the per-size image data written by one of its attachment-update actions, allowing users with the upload_files capability (Author and above) to write an executable PHP file into the…

  • CVE-2026-16949MedAug 10, 2026
    risk 0.38cvss 5.8epss 0.00

    The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

  • CVE-2026-16299CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    The Single Sign On For TNG WordPress plugin before 2.2.0 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2026-16298CriAug 10, 2026
    risk 0.64cvss 9.8epss 0.01

    The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2026-16257HigAug 10, 2026
    risk 0.53cvss 8.2epss 0.00

    The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can be bypassed by unauthenticated users through type juggling when the Arvow AI SEO Writer WordPress plugin before 1.5.4 has not been…

  • CVE-2026-15238MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticated user with a low-privileged account (Subscriber and above) to modify or overwrite the personal data of any customer by supplying…

  • CVE-2026-15237MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payment records, allowing unauthenticated users to create completed payment records against arbitrary bookings and falsely mark them as…

  • CVE-2026-15229MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated users to create bookings at an arbitrary price (including zero) and, by selecting a specific payment method, obtain an…

  • CVE-2026-15047MedAug 10, 2026
    risk 0.44cvss 6.8epss 0.00

    The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, allowing users with contributor-level access to inject arbitrary JavaScript that executes when a viewer opens the post (stored XSS).

  • CVE-2026-14941MedAug 10, 2026
    risk 0.35cvss 5.4epss 0.00

    The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX actions, allowing users with minimal permissions such as Subscribers to invoke administrative settings handlers, update Customer…

  • CVE-2026-14860MedAug 10, 2026
    risk 0.34cvss 5.3epss 0.00

    The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.

  • CVE-2026-14293HigAug 10, 2026
    risk 0.57cvss 8.8epss 0.01

    The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and does not escape that value when it is later output on the checkout page, allowing unauthenticated attackers to store JavaScript that…

  • CVE-2026-14238MedAug 10, 2026
    risk 0.27cvss 4.1epss 0.00

    The vitepos WordPress plugin before 3.6.0 does not sanitize or parameterize an identifier taken from a REST request body before using it in a database query in one of its report endpoints, allowing users with administrator-level access to perform SQL injection.