VYPR

CVEs

386,521 total · page 600 of 7,731

  • CVE-2026-19137HigAug 6, 2026
    risk 0.54cvss 8.3epss 0.00

    Use after free in WebGL in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-19127MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an…

  • CVE-2026-19111HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.01

    Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote authenticated users to access, modify, or delete memories belonging to other tenants by influencing the LLM to emit…

  • CVE-2026-19110LowAug 6, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlRenderer of the file HtmlTplDashboardWidgetHtmlRenderer.java of the component Chart Name Handler. This manipulation of the argument Title causes cross site…

  • CVE-2026-19108MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function deleteDataSetValuesShadowBuffer of the file src/iec61850/server/mms_mapping/reporting.c of the component URCB Revalidation. The manipulation results in use after free. The…

  • CVE-2026-19071MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. It is possible to initiate the attack remotely. The exploit has been published…

  • CVE-2026-19070MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipulation of the argument delid results in sql injection. The attack may be performed from remote. The exploit is now public and may…

  • CVE-2026-19069MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /treatmentrecord.php. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-19068MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /treatmentdetail.php. Executing a manipulation of the argument patientid can lead to sql injection. The attack can be executed remotely. The…

  • CVE-2026-19067MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible.…

  • CVE-2026-19066MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in SourceCodester Online Examination & Learning Management System 1.0. Impacted is an unknown function of the file view_students.php. Such manipulation of the argument class_group leads to authorization bypass. The attack may be launched remotely.

  • CVE-2026-19065MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in SourceCodester Online Examination & Learning Management System 1.0. This issue affects some unknown processing of the file upload_files.php. This manipulation causes unrestricted upload. The attack may be initiated remotely.

  • CVE-2026-19064MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.

  • CVE-2026-19062HigAug 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in chiuwingyan house up to dea6bcceaebe2b364a5a209747f48ecc2b2dc670. This affects an unknown part of the file /paid/selectall.action. The manipulation of the argument zuname leads to sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2026-19061LowAug 6, 2026
    risk 0.24cvss 3.7epss 0.00

    A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndDownloadFileList of the component Firmware Update Handler. Executing a manipulation can lead to insufficient verification of data authenticity. It is possible…

  • CVE-2026-19060MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early…

  • CVE-2026-19059LowAug 6, 2026
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. This affects the function read of the file metagpt/tools/libs/editor.py. This manipulation causes path traversal. The attack needs to be launched locally. The exploit has been publicly disclosed and may be…

  • CVE-2026-19058MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was found in FoundationAgents MetaGPT up to 0.8.2. The impacted element is the function DataInterpreter of the file metagpt/roles/di/data_interpreter.py. The manipulation results in code injection. The attack must be initiated from a local position. The exploit…

  • CVE-2026-19054MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in Lspace-io lspace-server up to 79f02fe5aa8970b210a6a05cf097155f8d9ffd71. This issue affects the function fileExists/readFile/writeFile/deleteFile of the file src/core/repository.ts of the component Repositories File API. Performing a manipulation…

  • CVE-2026-18487MedAug 6, 2026
    risk 0.35cvss 5.4epss 0.00

    A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:[email protected]/](https://trusted.com:8…

  • CVE-2026-18367CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.

  • CVE-2026-17032CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attackers to deploy a second-stage payload that exfiltrates credentials and other sensitive data and grants full control of affected sites.

  • CVE-2026-16620HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The WPC Name Your Price for WooCommerce WordPress plugin before 2.2.5 does not enforce its server-side price allowlist for products configured in "Select" price mode, allowing an unauthenticated visitor to add such a product to the cart at an arbitrary value below the…

  • CVE-2026-16619HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The miniOrange 2FA WordPress plugin before 6.2.8 does not correctly limit the number of second-factor verification attempts, tracking them against a client-supplied identifier that is reissued on every login, allowing an attacker who already knows a user's password to guess the…

  • CVE-2026-16067MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the server during its native (non-WooCommerce) checkout, trusting the per-ticket price supplied by the client instead of re-deriving the event's configured price.…

  • CVE-2026-15734CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary code as root.

  • CVE-2026-15733CriAug 6, 2026
    risk 0.65cvss 9.8epss 0.10

    A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

  • CVE-2026-15732CriAug 6, 2026
    risk 0.57cvss 9.8epss 0.01

    A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.

  • CVE-2026-15256MedAug 6, 2026
    risk 0.31cvss 4.8epss 0.00

    The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site…

  • CVE-2026-15208MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, payee, or prior use against the registration it is finalising: its server-side check only confirms the capture status is COMPLETED. An unauthenticated attacker…

  • CVE-2026-15152MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment made to the site's own merchant account, nor that the paid amount matches the booking total, allowing unauthenticated users to have their bookings marked as…

  • CVE-2026-15149MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total are non-negative when placing a booking, and relies on client-controlled cart data, allowing unauthenticated users to create confirmed reservations for free or…

  • CVE-2026-15147MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming payment notifications, failing to validate the payment recipient, amount, and status or to bind the notification to the intended booking, allowing unauthenticated…

  • CVE-2026-14936MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the site's own configured merchant account before activating a membership, allowing unauthenticated users to activate or extend a membership using a payment made to…

  • CVE-2026-14842MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record being charged, allowing unauthenticated attackers to pay a low amount for a cheap booking and have a separate, higher-priced booking marked as fully paid.

  • CVE-2026-14831MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking duration on the server side when adding to cart and calculating the booking price, allowing unauthenticated users to place below-minimum bookings and complete…

  • CVE-2026-14812CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an…

  • CVE-2026-14306MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    The Tutor LMS WordPress plugin before 3.9.14 does not properly verify enrollment when restricting access to protected course content, allowing authenticated users with subscriber-level access and above who are enrolled in at least one course to view paid lesson, quiz, and…

  • CVE-2026-14225LowAug 6, 2026
    risk 0.18cvss 2.7epss 0.00

    The Easy Appointments WordPress plugin before 3.12.28 does not correctly validate shortcode input in one of its block-rendering actions, checking only the first tag of the supplied string against an allowlist while rendering the entire string, allowing users with…

  • CVE-2026-13399HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Payment Plugins for PayPal WooCommerce WordPress plugin before 2.0.20 does not have proper authorization checks on a REST endpoint, allowing unauthenticated users to bypass payments

  • CVE-2026-13342MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the…

  • CVE-2026-12901MedAug 6, 2026
    risk 0.38cvss 5.9epss 0.00

    The GetPaid WordPress plugin before 2.8.55 does not verify the authenticity of incoming Worldpay payment notifications, allowing unauthenticated attackers to forge a notification that marks a pending invoice as paid without any payment being made.

  • CVE-2026-12584HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Payment Gateway for Redsys & WooCommerce Lite WordPress plugin before 7.0.2 does not verify the authenticity of incoming payment-provider notifications for one of its payment methods before marking orders as paid, allowing unauthenticated attackers to forge a…

  • CVE-2026-12501MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent to the site's configured merchant account, nor that the paid amount matches the order total, before marking a booking as paid, allowing unauthenticated…

  • CVE-2026-11976CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct…

  • CVE-2026-11803HigAug 6, 2026
    risk 0.51cvss 7.8epss 0.00

    A maliciously crafted PDF file, when parsed through certain Autodesk products, can force a Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

  • CVE-2026-11361MedAug 6, 2026
    risk 0.38cvss 5.9epss 0.00

    The Formidable Forms WordPress plugin before 6.32.1 does not properly validate the status of a PayPal subscription payment before marking it complete, allowing unauthenticated users to bypass payment and trigger paid form actions — such as digital content access, license…

  • CVE-2026-10599HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The Integrate PhonePe with WooCommerce WordPress plugin through 1.2.1 does not validate that a verified payment transaction belongs to the order being marked as paid, nor does it verify the authenticity of its payment-completion request, allowing unauthenticated attackers to…

  • CVE-2026-10524HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    The CoCart WordPress plugin before 4.9.0 does not validate a user-supplied price value against the actual product price when items are added to the cart through one of its public REST API endpoints, allowing unauthenticated users to set arbitrary product prices and complete…

  • CVE-2025-6508MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    The Swagger UI Try-out console within the API Publisher documentation allows an external Swagger API definition URL to be loaded, overriding the existing API definitions within the Publisher portal. By exploiting this vulnerability, malicious actors can deceive users into…