VYPR

CVEs

37,847 total · page 59 of 757

  • CVE-2026-67285CriAug 12, 2026
    risk 0.60cvss —epss 0.01

    Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can perform includes to arbitrary PHP files that are accessible by the system.

  • CVE-2025-59326CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned code to be executed from these locations.

  • CVE-2026-26035CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to…

  • CVE-2026-67282CriAug 12, 2026
    risk 0.65cvss —epss 0.01

    Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code by using the frontend listfilter model.

  • CVE-2025-41769CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

  • CVE-2026-66659CriAug 12, 2026
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Injection. This issue affects Tablesome Table: from n/a through 1.2.9.

  • CVE-2026-18391CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Order Storage enabled, leading to a PHP Object Injection issue which unauthenticated users can escalate to Remote Code Execution via a…

  • CVE-2026-18366CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to…

  • CVE-2026-16538CriAug 12, 2026
    risk 0.59cvss 9.1epss 0.00

    The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wallet, allowing customers to top up their wallet balance for less than its value.

  • CVE-2026-16051CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to…

  • CVE-2026-15039CriAug 12, 2026
    risk 0.64cvss 9.8epss 0.01

    The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users to upload arbitrary files, including PHP code, which can lead to remote code execution.

  • CVE-2026-72526CriAug 12, 2026
    risk 0.64cvss 9.9epss 0.01

    A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from an Application Custom Resource (CR) without proper validation. A tenant with permissions to create Applications on the hub…

  • CVE-2026-70398CriAug 12, 2026
    risk 0.62cvss 9.6epss 0.01

    A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive…

  • CVE-2026-68431CriAug 12, 2026
    risk 0.52cvss 9.1epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applies the minimum SMB2 PDU size check only when ProtocolId is SMB2_PROTO_NUMBER. A packet carrying SMB2_TRANSFORM_PROTO_NUM bypasses…

  • CVE-2026-68067CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the account matching the supplied email address. An attacker could use an email address to control cloud accounts and access hormone record…

  • CVE-2026-67568CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which could result in forgery, deletion, or destruction of health information.

  • CVE-2026-71290CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effect when used with the async version of HttpClient. An attacker that can intercept and modify traffic between the client and the…

  • CVE-2026-66147CriAug 11, 2026
    risk 0.61cvss 9.4epss 0.02

    An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote attacker to perform remote code execution through specially crafted requests.

  • CVE-2026-48765CriAug 11, 2026
    risk 0.57cvss 9.9epss 0.00

    TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from a readable bot configuration and then overwrite that credential through `handleUpdateOAuthCredentials()` by supplying an…

  • CVE-2026-73242CriAug 11, 2026
    risk 0.52cvss 9.1epss 0.00

    FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets,…

  • CVE-2026-73034CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.06

    DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the server by injecting directory traversal sequences into the user_id HTTP header of the Python file-upload endpoint. Attackers can…

  • CVE-2026-73032CriAug 11, 2026
    risk 0.55cvss 9.6epss 0.01

    PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM endpoint that is passed unsanitized to window.eval() in views.ts. Attackers can exploit this through prompt…

  • CVE-2026-66145CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacker to read sensitive data and perform arbitrary file write via zipslip.

  • CVE-2026-45618CriAug 11, 2026
    risk 0.58cvss 10.0epss 0.01

    LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

  • CVE-2026-16230CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the…

  • CVE-2026-73211CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled ActivityPub actor inboxUrl into an SQL query, allowing an unauthenticated remote server to read and write PeerTube database tables,…

  • CVE-2026-73090CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.00

    PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Update containing a Video object without verifying that byActor.url is authorized for the host in videoObject.id, allowing a…

  • CVE-2026-71398CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not…

  • CVE-2026-71362CriKEVAug 11, 2026
    risk 0.64cvss 9.1epss 0.88

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

  • CVE-2026-69102CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthenticated attackers to forge valid JWT tokens and authenticate as any user by exploiting the password-skipped login endpoint. Attackers…

  • CVE-2026-48381CriAug 11, 2026
    risk 0.59cvss 9.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to…

  • CVE-2026-47705CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.01

    TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sanitize or escape user-supplied input when generating CSV files. An attacker can inject spreadsheet formulas into input fields, which…

  • CVE-2026-27302CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not…

  • CVE-2026-71384CriAug 11, 2026
    risk 0.62cvss 9.6epss 0.00

    is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read and write access, potentially resulting in an application…

  • CVE-2026-70306CriAug 11, 2026
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2026-69223CriAug 11, 2026
    risk 0.59cvss 9.1epss 0.01

    Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue.

  • CVE-2026-65791CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62893CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62878CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Windows DNS allows an unauthorized attacker to execute code over a network.

  • CVE-2026-62815CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    Use after free in Microsoft QUIC allows an unauthorized attacker to execute code over a network.

  • CVE-2026-59124CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.02

    Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.

  • CVE-2026-50516CriAug 11, 2026
    risk 0.61cvss 9.4epss 0.01

    Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2026-48362CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.04

    ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute…

  • CVE-2026-12571CriAug 11, 2026
    risk 0.64cvss 9.8epss 0.03

    An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.

  • CVE-2026-73080CriAug 11, 2026
    risk 0.53cvss 9.3epss 0.01

    SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supplied remote endpoint through weed/remote_storage/s3/s3_storage_client.go and writes the response into a needle. The RPC performs…

  • CVE-2026-73069CriAug 11, 2026
    risk 0.52cvss 9.1epss 0.01

    Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MODEL permission to supply settings.asExpression for the system TS_VECTOR field searchVector through PATCH /rest/metadata/fields/:id…

  • CVE-2025-31114CriAug 11, 2026
    risk 0.54cvss —epss 0.01

    Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the…

  • CVE-2026-72920CriAug 11, 2026
    risk 0.57cvss 9.8epss 0.01

    SeaweedFS is a distributed storage system. Prior to 4.24, the filer registers the SeaweedIdentityAccessManagement gRPC service without mandatory authentication when jwt.filer_signing.key is unset, allowing any client that can reach the filer gRPC port to invoke CreateUser,…

  • CVE-2026-47702CriAug 11, 2026
    risk 0.52cvss —epss 0.00

    TypeBot is a chatbot builder tool. In version 3.16.1, API tokens (bearer credentials used to authenticate against the builder API) are stored in the database as cleartext strings. An attacker who gains read access to the database (e.g., via SQL injection, backup exposure, or…

  • CVE-2026-17061CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.01

    A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthenticated remote code execution.