VYPR

CVEs

37,851 total · page 64 of 758

  • CVE-2026-15733CriAug 6, 2026
    risk 0.65cvss 9.8epss 0.10

    A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attackers to execute arbitrary commands as root.

  • CVE-2026-15732CriAug 6, 2026
    risk 0.57cvss 9.8epss 0.01

    A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated attackers to make arbitrary HTTP requests and retrieve responses.

  • CVE-2026-14812CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an…

  • CVE-2026-11976CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) and the version MonsterInsights rolled back to (10.2.0) contain a malicious file, `class-system-check.php`. Three distinct…

  • CVE-2025-14561CriAug 6, 2026
    risk 0.52cvss 9.0epss 0.00

    In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user…

  • CVE-2026-67261CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.02

    Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary…

  • CVE-2026-66709CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

  • CVE-2026-66665CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

  • CVE-2026-66662CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

  • CVE-2026-66447CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

  • CVE-2026-65581CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

  • CVE-2026-65579CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

  • CVE-2026-65578CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

  • CVE-2026-65577CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

  • CVE-2026-65576CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

  • CVE-2026-65575CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

  • CVE-2026-65574CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

  • CVE-2026-65573CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

  • CVE-2026-65572CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

  • CVE-2026-65571CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

  • CVE-2026-65556CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

  • CVE-2026-65553CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.01

    Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

  • CVE-2026-65552CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

  • CVE-2026-65548CriAug 6, 2026
    risk 0.64cvss 9.9epss 0.01

    Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

  • CVE-2026-65546CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

  • CVE-2026-65520CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

  • CVE-2026-65508CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

  • CVE-2026-65507CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

  • CVE-2026-54489CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session…

  • CVE-2026-53976CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.03

    OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an…

  • CVE-2026-53975CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.02

    OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any…

  • CVE-2026-34191CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

  • CVE-2026-32327CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

  • CVE-2026-28139CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

  • CVE-2026-28005CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

  • CVE-2026-5134CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure…

  • CVE-2026-12605CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the…

  • CVE-2026-68079CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be…

  • CVE-2026-65583CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not…

  • CVE-2026-63687CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can…

  • CVE-2026-61466CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.01

    In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning…

  • CVE-2026-66909CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to…

  • CVE-2026-64597CriAug 6, 2026
    risk 0.57cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the…

  • CVE-2026-5430CriKEVAug 6, 2026
    risk 0.70cvss 10.0epss 0.01

    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful…

  • CVE-2026-1728CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full…

  • CVE-2025-15039CriAug 6, 2026
    risk 0.61cvss 9.4epss 0.01

    The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate…

  • CVE-2026-16054CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload…

  • CVE-2026-12713CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by…

  • CVE-2026-67873CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the…

  • CVE-2026-67870CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing…