VYPR

CVEs

387,005 total · page 750 of 7,741

  • CVE-2024-23566MedJul 17, 2026
    risk 0.42cvss 6.5epss 0.00

    HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration

  • CVE-2024-23565MedJul 17, 2026
    risk 0.34cvss 5.3epss 0.00

    HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service,…

  • CVE-2024-23564CriJul 17, 2026
    risk 0.59cvss 9.1epss 0.00

    HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial…

  • CVE-2026-8396HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from 5.0.66 before 7.2.2.

  • CVE-2026-7189HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.

  • CVE-2026-16014HigJul 17, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2026-13410HigJul 17, 2026
    risk 0.46cvss 8.2epss 0.00

    Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled. The default user agent is initialised with SSL_verify_mode explicitly disabled. An attacker with network man-in-the-middle (MITM) capability between the Dancer application and…

  • CVE-2026-13082MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets. The random method creates the challenge text used for the CAPTCHA by sampling characters from an array using Perl's built-in rand function, and generates a (by default) six-character string. The…

  • CVE-2026-16013MedJul 17, 2026
    risk 0.28cvss 5.3epss 0.01

    A vulnerability has been found in liftoff-sr CIPster up to 632336d414ef708a542377c1aa8d6fdb7c70a760. Affected by this issue is the function CipAppPath::deserialize_symbolic of the file source/src/cip/cipepath.cc. Such manipulation leads to out-of-bounds read. The attack may be…

  • CVE-2026-16009MedJul 17, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php. The manipulation of the argument delid results in sql injection. The attack can be launched remotely. The exploit is now public…

  • CVE-2026-15943MedJul 17, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated administrator updates an OIDC identity provider using a masked client secret sentinel value. Due to improper validation, Keycloak…

  • CVE-2026-9602MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to crash the Mattermost Desktop App via changing the payload of a method to a malformed one. Mattermost…

  • CVE-2026-8075MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash another channel members Desktop App via posting a malicious link with an embedded image that misses one of…

  • CVE-2026-59695HigJul 17, 2026
    risk 0.00cvss —epss 0.01

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet in a single request by naming an arbitrarily high gas price. When the mpp Elixir library is configured as fee payer (fee_payer: true),…

  • CVE-2026-59694HigJul 17, 2026
    risk 0.00cvss —epss 0.01

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to inflate the fee-payer's gas cost per payment by a large multiplier, degrading the sponsor's operating margin. When the mpp Elixir library is configured as fee payer…

  • CVE-2026-59252HigJul 17, 2026
    risk 0.00cvss —epss 0.01

    Improper Validation of Specified Quantity in Input in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet, resulting in denial of service for legitimate clients. When the mpp Elixir library is configured as fee payer (fee_payer: true), the…

  • CVE-2026-16008MedJul 17, 2026
    risk 0.34cvss 6.3epss 0.00

    A security vulnerability has been detected in sagold json-schema-library 11.5.0/11.5.1. This impacts the function parsePropertyDependencies of the file src/keywords/propertyDependencies.ts. The manipulation leads to improperly controlled modification of object prototype…

  • CVE-2026-22104HigJul 17, 2026
    risk 0.00cvss —epss 0.00

    Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read all cracked hashes of a Hashtopolis server instance.

  • CVE-2026-62764MedJul 17, 2026
    risk 0.42cvss 6.5epss 0.01

    Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, manager, monitor,…

  • CVE-2026-9656MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.62 via the wp_localize_script() / window.leadinConfig JavaScript object. This makes it possible for…

  • CVE-2026-15380MedJul 17, 2026
    risk 0.00cvss —epss 0.00

    A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory corruption required (ITMS 8.7.3)

  • CVE-2026-15379MedJul 17, 2026
    risk 0.00cvss —epss 0.00

    The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the SYSTEM account, bypassing filesystem ACLs. No admin privileges required. The provider reverts to the LocalSystem context when…

  • CVE-2026-9810CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unauthenticated attackers who complete the public OAuth flow to execute privileged MCP tools as an…

  • CVE-2026-13402MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one of its REST endpoints, allowing unauthenticated users to retrieve the rendered HTML content of private or draft Elementor…

  • CVE-2026-12393MedJul 17, 2026
    risk 0.00cvss 5.4epss 0.00

    The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling it, allowing any authenticated user, such as a Subscriber or Customer, to cancel and void other customers' booking orders.

  • CVE-2026-11966MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete…

  • CVE-2026-11961HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated…

  • CVE-2026-11575HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used to validate the callback signature is empty on sites configured through the current setup flow, so the expected signature reduces…

  • CVE-2026-10525MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.00

    The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the admin dashboard, leading to a Stored Cross-Site Scripting vulnerability which could allow unauthenticated users to perform Stored…

  • CVE-2019-25764HigJul 17, 2026
    risk 0.47cvss —epss 0.00

    **UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update…

  • CVE-2026-15982CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.8.4. This is due to due to a missing capability check on the 'aiomatic_call_google_ai_function'…

  • CVE-2026-15094MedJul 17, 2026
    risk 0.00cvss 6.1epss 0.01

    The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, and including, 2.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2026-60060MedJul 17, 2026
    risk 0.00cvss 6.3epss 0.00

    Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a…

  • CVE-2026-58317MedJul 17, 2026
    risk 0.00cvss 6.3epss 0.00

    Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents…

  • CVE-2026-41993MedJul 17, 2026
    risk 0.00cvss 4.4epss 0.00

    Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker…

  • CVE-2026-21770MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.00

    HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the application with malicious content.

  • CVE-2026-15759MedJul 17, 2026
    risk 0.00cvss 6.4epss 0.00

    The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input…

  • CVE-2026-15457MedJul 17, 2026
    risk 0.00cvss 4.9epss 0.01

    The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and…

  • CVE-2026-15349MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes…

  • CVE-2026-15161MedJul 17, 2026
    risk 0.00cvss 6.4epss 0.00

    The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() AJAX handler storing the raw $_POST['filter'] array into a WordPress option via update_option() without any…

  • CVE-2026-14503MedJul 17, 2026
    risk 0.00cvss 6.5epss 0.01

    The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_inner. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract…

  • CVE-2026-13765HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.01

    The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.1 via the check_answer. This makes it possible for unauthenticated attackers to extract the…

  • CVE-2026-13352HigJul 17, 2026
    risk 0.00cvss 8.8epss 0.01

    The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 4.16.18 via the allowed_mime_types function. This is due…

  • CVE-2026-8616MedJul 17, 2026
    risk 0.00cvss 5.3epss 0.00

    The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the fense_bpvt_save_settings() function in versions up to, and including, 3.0.1. The callback is registered to…

  • CVE-2026-15395HigJul 17, 2026
    risk 0.00cvss 7.2epss 0.00

    The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field Value in all versions up to, and including, 2.4.18 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-15160MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.01

    The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to…

  • CVE-2026-15159MedJul 17, 2026
    risk 0.00cvss 4.3epss 0.00

    The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_form_id' parameter due to missing validation on a user controlled key. This makes it possible for…

  • CVE-2026-11324MedJul 17, 2026
    risk 0.33cvss 6.1epss 0.00

    The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in versions up to, and including, 3.2.2 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-62387HigJul 17, 2026
    risk 0.00cvss 7.1epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all responses, including authenticated endpoints and preflight (OPTIONS) responses. Because the plugin accepts credentials via the…

  • CVE-2026-62386HigJul 17, 2026
    risk 0.00cvss 7.5epss 0.00

    The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route (JwtAuthenticator::extractBearerToken fallback). Because tokens are embedded in URLs, they are logged verbatim in web server…