VYPR

CVEs

386,275 total · page 584 of 7,726

  • CVE-2026-14237HigAug 10, 2026
    risk 0.47cvss 7.2epss 0.00

    The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-sale password-reset API and grant the custom Outlet Manager role an over-broad password-reset capability by default, allowing an…

  • CVE-2026-14211LowAug 10, 2026
    risk 0.25cvss 3.8epss 0.00

    The Booking for Appointments and Events Calendar WordPress plugin before 9.7 does not verify that an authenticated employee (provider) is related to the customer whose record is being accessed, allowing any employee with an Employee Panel login to read and modify the stored…

  • CVE-2026-14206HigAug 10, 2026
    risk 0.49cvss 7.5epss 0.00

    The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing unauthenticated users to read the personal data (name, email, phone, address) stored in form drafts.

  • CVE-2026-13701MedAug 10, 2026
    risk 0.31cvss 4.8epss 0.00

    The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it on the front end of the site, which could allow administrators (including those without the unfiltered_html capability, such as on multisite) to perform Stored…

  • CVE-2026-13600HigAug 10, 2026
    risk 0.53cvss 8.1epss 0.00

    The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator authentication cookie during its scheduled content-synchronization task. On server configurations where the scheduled task executes…

  • CVE-2026-13170HigAug 10, 2026
    risk 0.47cvss 7.2epss 0.01

    The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing users with editor-level access and above to include and execute arbitrary local PHP files.

  • CVE-2026-13133HigAug 10, 2026
    risk 0.55cvss —epss 0.00

    A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path without a secure DLL search path, allowing a malicious DLL placed in the installer's directory to be loaded ahead of the legitimate…

  • CVE-2026-12971LowAug 10, 2026
    risk 0.14cvss 2.2epss 0.00

    The LearnPress WordPress plugin before 4.4.4 does not validate a user-supplied URL before the server fetches it, allowing users with the instructor role to induce the server to issue requests to arbitrary external hosts, a blind and bounded server-side request forgery.

  • CVE-2026-12570MedAug 10, 2026
    risk 0.29cvss 5.5epss 0.00

    A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape…

  • CVE-2026-17519Aug 10, 2026
    risk 0.00cvss —epss —

    Rejected reason: This is rejected.

  • CVE-2026-72522MedAug 10, 2026
    risk 0.33cvss 6.2epss 0.00

    libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions.

  • CVE-2026-19389HigAug 10, 2026
    risk 0.46cvss 7.1epss 0.01

    Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objects from crafted ASF, WMV, or WMA files. Insufficient validation of attacker-controlled length and size values can bypass bounds…

  • CVE-2026-19387HigAug 10, 2026
    risk 0.49cvss 7.6epss 0.00

    A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient validation of the per-block sample count for multi-channel streams allows a crafted WAV file to cause writes beyond the allocated…

  • CVE-2026-19384HigAug 10, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admin/ajax.php?action=set_appointment. This manipulation of the argument ID causes sql injection. The attack may be initiated…

  • CVE-2026-19383MedAug 10, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_exec of the file /app/saipackage/install/upload of the component Plugin Upload Endpoint. The manipulation leads to unrestricted upload. Remote exploitation of…

  • CVE-2026-19382LowAug 10, 2026
    risk 0.15cvss 2.3epss 0.00

    A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be executed locally. The exploit has been made…

  • CVE-2026-19381HigAug 10, 2026
    risk 0.51cvss 7.8epss 0.00

    A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library NTIOLib_KSFX.sys of the component Driver. Performing a manipulation results in improper privilege management. The attack needs to…

  • CVE-2026-19380LowAug 10, 2026
    risk 0.15cvss 2.3epss 0.00

    A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is…

  • CVE-2026-19379HigAug 10, 2026
    risk 0.48cvss 7.3epss 0.03

    A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. This manipulation of the argument fname causes os command injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-19378MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in cross site scripting. It is possible to…

  • CVE-2026-19376HigAug 10, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php of the component File API. The manipulation leads to permission issues. It is possible to initiate the attack remotely. The…

  • CVE-2026-19375MedAug 10, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_mcp/server.py. The manipulation of the argument url results in server-side request forgery. The attack may be performed from…

  • CVE-2026-19374HigAug 9, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file app/api/proxy/route.ts of the component Proxy API Endpoint. The manipulation of the argument url leads to server-side…

  • CVE-2026-19373MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index.ts of the component BaseConfigSchema. Executing a manipulation of the argument apiUrl can lead to server-side request forgery. It…

  • CVE-2026-19372MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSync of the file src/index.ts of the component upload_document. Performing a manipulation of the argument File results in path…

  • CVE-2026-19371MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the component comfy_upload_image. Such manipulation of the argument image_path leads to path traversal. An attack has to be approached…

  • CVE-2026-12372LowAug 9, 2026
    risk 0.17cvss 3.7epss 0.00

    A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. The `nltk.pathsec.validate_network_url()` function, intended to prevent SSRF by rejecting internal network addresses, fails to reject IPs in the RFC 6598 shared…

  • CVE-2026-19370MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file index.ts of the component geminithinking. This manipulation of the argument sessionCommand/sessionPath causes path traversal. The…

  • CVE-2026-19369MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attachment_from_public_url. The manipulation of the argument imageUrl results in server-side request forgery. The attack requires a…

  • CVE-2026-19368LowAug 9, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in PV-Bhat gemsuite-mcp 1.0.0. Affected by this issue is some unknown functionality of the file src/handlers/unified-gemini.ts of the component gemini_search/gemini_reason/gemini_process/gemini_analyze. The manipulation of the argument…

  • CVE-2026-19367MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/rangeConfig.ts of the component read_range_config. The manipulation of the argument Source leads to server-side request forgery. The…

  • CVE-2026-70395LowAug 9, 2026
    risk 0.07cvss —epss 0.00

    Improper Neutralization of Special Elements in Data Query Logic vulnerability in ash-project ash allows an attacker to forge a relationship to a record they cannot name, and to recover the secret value used to look it up. When manage_relationship is used with on_lookup: :relate…

  • CVE-2026-19366MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/insertCredsRangeConfig.ts of the component insert_creds_range_config. Executing a manipulation of the argument configPath/outputPath can lead to path traversal.…

  • CVE-2026-19365MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the file src/index.ts of the component upscale_images. Such manipulation of the argument output_path leads to path traversal. The attack must be carried out locally.…

  • CVE-2026-69659MedAug 9, 2026
    risk 0.29cvss 5.5epss 0.00

    Uncontrolled Resource Consumption vulnerability in ash-project ash allows an attacker to exhaust the memory of the node via a crafted keyset pagination cursor. Read actions with keyset pagination deserialize the client-supplied page[:after] or page[:before] cursor in…

  • CVE-2026-19364MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /viewdoctorconsultancycharge.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out…

  • CVE-2026-19363MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda Authorizer. The manipulation results in sensitive information in log files. The attack can be executed remotely. `src/handler.rs`…

  • CVE-2026-19362MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_header of the file src/parse_token_from_header.rs of the component Authorization Header Parsing. The manipulation of the argument authorization_token leads to…

  • CVE-2026-19361LowAug 9, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is…

  • CVE-2026-15534MedAug 9, 2026
    risk 0.30cvss 5.7epss 0.00

    Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch. The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit…

  • CVE-2026-19360MedAug 9, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunction of the component Lambda Function Handler. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The…

  • CVE-2026-19359MedAug 9, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function SitewiseCustomFunction of the component Lambda Function Handler. Such manipulation leads to improper access controls. The attack can be launched remotely.…

  • CVE-2026-19358MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in 3CORESec Trapdoor up to 1.2.2. Affected by this vulnerability is the function DefaultFunction. This manipulation causes improper access controls. The attack can be initiated remotely. The vendor was contacted early about this disclosure.

  • CVE-2026-19357MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released…

  • CVE-2026-19356MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly…

  • CVE-2026-19355HigAug 9, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be…

  • CVE-2026-19354MedAug 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in lock-upme OPMS up to 831440f37a92c1568f2e071d5233bc873a9d8b09. The impacted element is an unknown function of the file controllers/messages/message.go of the component IN Clause Handler. Performing a manipulation of the argument ids results in sql…

  • CVE-2026-19353MedAug 9, 2026
    risk 0.33cvss 5.0epss 0.00

    A vulnerability has been found in DedeCMS up to 5.7.118 UTF8SP2. The affected element is the function _4_Setup of the file install/index.php of the component Installation Wizard. Such manipulation leads to file inclusion. The attack can be executed remotely. This attack is…

  • CVE-2026-19352LowAug 9, 2026
    risk 0.13cvss 3.1epss 0.00

    A vulnerability was determined in mifi lossless-cut up to 3.69.0. Affected by this issue is some unknown functionality of the file src/main/httpServer.ts of the component Built-in HTTP API Service. Executing a manipulation can lead to server-side request forgery. The attack…

  • CVE-2026-19351HigAug 9, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql…