VYPR

CVEs

386,750 total · page 690 of 7,735

  • CVE-2026-64873CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

  • CVE-2026-64872MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

  • CVE-2026-64871MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not consistently require a valid token and cache-management permission.

  • CVE-2026-64799HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they…

  • CVE-2026-16078MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.01

    The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.9.8 via the 'type' parameter parameter. This makes it possible for authenticated attackers, with shop manager-level access…

  • CVE-2026-15906MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.0.4 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15827MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/mailchimp/get/lists and /wp-json/gutenkit/v1/mailchimp/get/interests REST API endpoints in versions up to, and including, 2.4.12.…

  • CVE-2026-15794MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-15786MedJul 23, 2026
    risk 0.00cvss 4.4epss 0.01

    The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.8.6.6 via the 'imploded' parameter parameter. This makes it possible for…

  • CVE-2026-15761MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15647MedJul 23, 2026
    risk 0.00cvss 4.4epss 0.00

    The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15646MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…

  • CVE-2026-15448MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in all versions up to, and including, 3.6.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15404MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to insufficient input sanitization and output escaping in the lpagery_add_filter_text_template_post() function, which is hooked to…

  • CVE-2026-15394MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code' Snippet Meta in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-15348MedJul 23, 2026
    risk 0.00cvss 6.3epss 0.01

    The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 7.0.4 via the `wpdmppdl` parameter. This is due to the `download()` function — hooked to the unauthenticated WordPress `wp`…

  • CVE-2026-15017HigJul 23, 2026
    risk 0.00cvss 8.8epss 0.01

    The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to missing capability checks and nonce verification in the `MDJM_Permissions::set_permissions()` and `MDJM_Employee_Manager::init()`…

  • CVE-2026-15015CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for…

  • CVE-2026-15011CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, and including, 6.0.5 due to the use of dynamic function invocation on an attacker-controlled value with insufficient validation.…

  • CVE-2026-14481MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'html' parameter in all versions up to, and including, 1.46.0 due to insufficient input sanitization and output…

  • CVE-2026-14282CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.01

    The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 1.12.2. This is due to insufficient file type validation in the…

  • CVE-2026-13119MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The Registrations For The Events Calendar plugin for WordPress is vulnerable to SQL Injection via JSON keys in the 'standard' parameter handled by the rtec_records_edit AJAX action in versions up to and including 3.2. The handler decodes attacker-controlled JSON from…

  • CVE-2026-13009MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    The AI Copilot – Content Generator plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and including, 1.5.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-52688HigJul 23, 2026
    risk 0.42cvss 7.5epss 0.00

    RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation

  • CVE-2026-52686LowJul 23, 2026
    risk 0.17cvss 3.7epss 0.00

    The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.

  • CVE-2026-52684LowJul 23, 2026
    risk 0.00cvss 3.7epss 0.00

    If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data. This does not happen on regular resolve as then then the child records are used immediately if not expired and thus valid, or the records are expired, and…

  • CVE-2026-16723CriJul 23, 2026
    risk 0.00cvss 9.0epss 0.01

    A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock default configuration — no AutoType enablement required, no classpath gadget required.

  • CVE-2026-16287HigJul 23, 2026
    risk 0.00cvss 7.8epss 0.01

    Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-update allows OS Command Injection. This issue affects pardus-update: from 0.6.6 before 0.7.0.

  • CVE-2024-58330HigJul 23, 2026
    risk 0.49cvss 7.5epss 0.01

    A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.

  • CVE-2024-58023HigJul 23, 2026
    risk 0.55cvss 8.4epss 0.00

    Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.

  • CVE-2026-9729MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' parameters in versions up to, and including, 4.39.0. This is due to insufficient input sanitization in the…

  • CVE-2026-9713HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed by the checkout AJAX action in versions up to, and including, 2.1.1. This is due to insufficient escaping…

  • CVE-2026-9635MedJul 23, 2026
    risk 0.00cvss 6.4epss 0.00

    The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and including, 1.4.17. This is due to insufficient input sanitization and output escaping in the mts_tabs()…

  • CVE-2026-59678HigJul 23, 2026
    risk 0.00cvss —epss 0.00

    An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe.

  • CVE-2026-59677MedJul 23, 2026
    risk 0.00cvss —epss 0.00

    A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10.

  • CVE-2026-12421HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The ARforms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'password' Field Values in all versions up to, and including, 7.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2026-9577MedJul 23, 2026
    risk 0.00cvss 4.8epss 0.00

    The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?page=post-status-notifier-lite`), leading to a Reflected Cross-Site Scripting vulnerability that fires in…

  • CVE-2026-9066MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of JavaScript files emitted on the page, leading to Reflected XSS. When a visitor follows a crafted link, the WP…

  • CVE-2026-59676MedJul 23, 2026
    risk 0.00cvss —epss 0.00

    A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10.

  • CVE-2026-14291HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.01

    The security-ninja-premium WordPress plugin before 5.290 does not verify the second authentication factor in one of its two-factor authentication code paths, allowing an unauthenticated attacker who knows a user's password to complete authentication without the one-time code and…

  • CVE-2026-12082HigJul 23, 2026
    risk 0.00cvss 7.5epss 0.00

    The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

  • CVE-2026-7534HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The SUMO Reward Points plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REST API endpoint `/wp-json/wc-srp/v1/earning` in versions up to, and including, 32.7.0. This is due to the `user_has_cap` filter in the `SRP_REST_Earning_Controller`…

  • CVE-2026-7232HigJul 23, 2026
    risk 0.00cvss 7.2epss 0.00

    The FormCraft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '[parameter name]' parameter in all versions up to, and including, 3.9.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

  • CVE-2026-64600HigJul 23, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapping. Unfortunately, these two helpers…

  • CVE-2026-63226MedJul 23, 2026
    risk 0.00cvss 5.8epss 0.00

    Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other…

  • CVE-2026-6390MedJul 23, 2026
    risk 0.44cvss 6.8epss 0.00

    A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted filename containing printf format specifiers can be reinterpreted. This format string vulnerability may…

  • CVE-2026-7120MedJul 23, 2026
    risk 0.27cvss 5.3epss 0.00

    @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to and including 10.1.1 are affected. An unauthenticated attacker can bypass allowedPath restrictions by…

  • CVE-2026-15074HigJul 23, 2026
    risk 0.42cvss 7.5epss 0.01

    @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library…

  • CVE-2026-21723MedJul 23, 2026
    risk 0.34cvss 5.3epss 0.00

    The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is…

  • CVE-2026-16653MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public Folder Handler. Performing a manipulation results in path traversal. Remote exploitation of the attack is…