VYPR

CVEs

386,521 total · page 601 of 7,731

  • CVE-2025-15674LowAug 6, 2026
    risk 0.18cvss 2.7epss 0.00

    The Passster WordPress plugin before 4.3.7 does not restrict low-privilege users holding the edit_posts capability from reading globally password-protected content through the WordPress core REST API when global protection is enabled, allowing any Contributor or higher to read…

  • CVE-2025-14561CriAug 6, 2026
    risk 0.52cvss 9.0epss 0.00

    In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user…

  • CVE-2025-12317MedAug 6, 2026
    risk 0.33cvss 5.0epss 0.00

    When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issued authentication tokens associated with that user. This vulnerability could allow users to retain their previous access privileges even after their roles have…

  • CVE-2024-6541MedAug 6, 2026
    risk 0.37cvss 6.8epss 0.00

    The Class Mediator fails to correctly validate or sanitize `messageContext` properties when they are used to populate dynamic values. This allows authenticated users to potentially access or modify data across different system invocations that should be isolated. This weakness…

  • CVE-2024-39024HigAug 6, 2026
    risk 0.57cvss 8.8epss 0.01

    In Packetfence 13.2.0, the WebGui interface setting allows authenticated remote code execution.

  • CVE-2026-16633higAug 6, 2026
    risk 0.45cvss —epss —

    ### Impact If PDF.js is used to load a malicious PDF, and PDF.js is configured with `enableScripting` set to true (which is the default value) and no CSP for disallowing script-src, unrestricted attacker-controlled JavaScript will be executed in the context of the hosting…

  • CVE-2026-68750HigAug 6, 2026
    risk 0.42cvss 7.5epss 0.01

    Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU and memory via a flat run of sibling elements in sanitized HTML. The list clause of…

  • CVE-2026-68749HigAug 6, 2026
    risk 0.42cvss 7.5epss 0.01

    Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in HtmlSanitizeEx.Scrubber.CSS.scrub/1…

  • CVE-2026-68747MedAug 6, 2026
    risk 0.33cvss 6.1epss 0.00

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to inject CSS at-rules, including an import of a remote stylesheet, into a…

  • CVE-2026-66843MedAug 6, 2026
    risk 0.33cvss 6.1epss 0.01

    Inclusion of Functionality from Untrusted Control Sphere vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to load a document of their choosing into a trusted page via the data attribute of an element in sanitized HTML. object is…

  • CVE-2026-66829MedAug 6, 2026
    risk 0.33cvss 6.1epss 0.01

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows a remote attacker to force visitors of a page to navigate to a site of the attacker's choosing via a element in sanitized HTML.…

  • CVE-2026-66370MedAug 6, 2026
    risk 0.33cvss 6.1epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the HTML5 scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to retarget a form already on the rendering page and receive whatever the victim submits, including credentials, via the…

  • CVE-2026-5423HigAug 6, 2026
    risk 0.46cvss —epss 0.01

    @neo4j/graphql library versions prior to 7.5.6 fail to verify the authenticity of a client-supplied, pre-decoded JWT object passed through GraphQL subscription connectionParams. As a result, any unauthenticated remote client that can open a GraphQL-over-WebSocket connection…

  • CVE-2026-53985HigAug 6, 2026
    risk 0.42cvss 7.5epss 0.01

    Ground Station prior to 0.6.0 contains an unauthenticated denial-of-service vulnerability in the Socket.IO server's service_control event handler that allows any unauthenticated network peer to forcibly terminate the ground-station process by sending a single restart_service…

  • CVE-2026-53977HigAug 6, 2026
    risk 0.42cvss 7.5epss 0.01

    OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express…

  • CVE-2026-43622HigAug 6, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap metadata corruption. Attackers can trigger…

  • CVE-2026-3430HigAug 6, 2026
    risk 0.56cvss 8.6epss 0.00

    The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL statement, leading to an unauthenticated SQL injection when the abandoned cart email is managed by creative mail.

  • CVE-2026-19047MedAug 6, 2026
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/executeCommand of the file src/ludusMCP/cliWrapper.ts of the component ludus_cli_execute. Performing a manipulation of the argument command/args results in…

  • CVE-2026-19046LowAug 6, 2026
    risk 0.21cvss 3.3epss 0.00

    A security vulnerability has been detected in NocteDefensor LudusMCP up to 1.0.24. The impacted element is an unknown function of the file src/tools/ludusEnvironmentGuidesSearch.ts of the component ludus_environment_guides_search. Such manipulation of the argument guide_name…

  • CVE-2026-18427HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.01

    @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching…

  • CVE-2026-18359HigAug 6, 2026
    risk 0.55cvss 8.5epss 0.00

    Server-side request forgery in the METS and IIIF import URI handling in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to make the server issue arbitrary HTTP requests to internal hosts, including the cloud instance metadata service, via the mets_uri or…

  • CVE-2026-18277HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the…

  • CVE-2026-18276MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing authorization in the websocket consumer in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to subscribe to any document's event stream and observe another user's segmentation, transcription, import, export and training activity via the object_cls…

  • CVE-2026-18275MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Authorization bypass in the process and annotation taxonomy serializers in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to run segmentation and transcription against other users' document parts, overwriting their content, via part primary keys supplied…

  • CVE-2026-18258HigAug 6, 2026
    risk 0.57cvss 8.8epss 0.01

    Authorization bypass in the Line, LineTranscription, VirtualCollection, tag and process API endpoints in Scripta/eScriptorium through 26.04.1 allows a remote authenticated user to read, modify and delete other users' transcription content via primary keys supplied in the request…

  • CVE-2026-70646HigAug 6, 2026
    risk 0.42cvss 7.5epss 0.01

    aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON…

  • CVE-2026-70637MedAug 6, 2026
    risk 0.38cvss 5.9epss 0.00

    LightFTP through 2.4 contains multiple data race vulnerabilities in ftpserv.c that allow anonymous attackers to cause undefined behavior by issuing LIST followed by ABOR commands without authentication. The control thread closes data_socket and file_fd descriptors while worker…

  • CVE-2026-67261CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.02

    Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary…

  • CVE-2026-66712HigAug 6, 2026
    risk 0.49cvss 7.5epss 0.00

    Unauthenticated Broken Access Control in Simple Membership <= 4.7.8 versions.

  • CVE-2026-66711HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.

  • CVE-2026-66710HigAug 6, 2026
    risk 0.53cvss 8.1epss 0.00

    Unauthenticated Local File Inclusion in e2pdf <= 1.32.40 versions.

  • CVE-2026-66709CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

  • CVE-2026-66708HigAug 6, 2026
    risk 0.53cvss 8.2epss 0.00

    Unauthenticated Broken Access Control in Total Upkeep <= 1.17.2 versions.

  • CVE-2026-66707HigAug 6, 2026
    risk 0.39cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.

  • CVE-2026-66706MedAug 6, 2026
    risk 0.38cvss 5.9epss 0.00

    Author Cross Site Scripting (XSS) in Subscribe to Comments <= 2.3.1 versions.

  • CVE-2026-66705HigAug 6, 2026
    risk 0.39cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.

  • CVE-2026-66703MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in MailOptin <= 1.2.78.0 versions.

  • CVE-2026-66702HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.

  • CVE-2026-66701MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

  • CVE-2026-66699MedAug 6, 2026
    risk 0.27cvss 5.3epss 0.00

    Custom role Broken Access Control in Dokan <= 5.0.10 versions.

  • CVE-2026-66696MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions.

  • CVE-2026-66695MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Path Traversal in W3 Total Cache <= 2.10.2 versions.

  • CVE-2026-66694HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.

  • CVE-2026-66692MedAug 6, 2026
    risk 0.28cvss 4.3epss 0.00

    Customer Insecure Direct Object References (IDOR) in Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.10.0 versions.

  • CVE-2026-66690HigAug 6, 2026
    risk 0.46cvss 7.1epss 0.00

    Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.

  • CVE-2026-66688MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Contributor Cross Site Scripting (XSS) in Ultimate Addons for Elementor <= 1.45.2 versions.

  • CVE-2026-66686MedAug 6, 2026
    risk 0.42cvss 6.5epss 0.00

    Unauthenticated Cross Site Request Forgery (CSRF) in Plugins Garbage Collector (Database Cleanup) <= 0.14 versions.

  • CVE-2026-66685MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.

  • CVE-2026-66684MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.

  • CVE-2026-66683MedAug 6, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.