VYPR

CVEs

387,028 total · page 756 of 7,741

  • CVE-2026-59249MedJul 16, 2026
    risk 0.00cvss —epss 0.01

    Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled connection, enabling response-queue poisoning against…

  • CVE-2026-35149HigJul 16, 2026
    risk 0.00cvss 8.2epss 0.00

    HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized…

  • CVE-2026-35148MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without…

  • CVE-2026-35147HigJul 16, 2026
    risk 0.00cvss 8.2epss 0.00

    HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform…

  • CVE-2026-35146MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    HCL DFXServer is affected by an Unencrypted Communication vulnerability. The application permits users to establish connections over unencrypted channels via the HTTP protocol, which could allow a remote attacker to intercept network traffic and expose sensitive data transmitted…

  • CVE-2023-49900CriJul 16, 2026
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

  • CVE-2023-49899CriJul 16, 2026
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channel.

  • CVE-2026-22752CriJul 16, 2026
    risk 0.62cvss 9.6epss 0.00

    Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0 through 1.4.9, from 1.3.0 through 1.3.10.

  • CVE-2026-7543HigJul 16, 2026
    risk 0.00cvss 7.2epss 0.00

    The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2026-6424MedJul 16, 2026
    risk 0.00cvss —epss 0.00

    Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system

  • CVE-2026-6423HigJul 16, 2026
    risk 0.00cvss —epss 0.00

    A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.

  • CVE-2026-58078HigJul 16, 2026
    risk 0.00cvss —epss 0.00

    Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to an unauthenticated SQL injection.

  • CVE-2026-15727MedJul 16, 2026
    risk 0.00cvss 4.9epss 0.01

    The WP Bulk Delete plugin for WordPress is vulnerable to generic SQL Injection via the 'delete_user_roles' parameter in all versions up to, and including, 1.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL…

  • CVE-2026-15651MedJul 16, 2026
    risk 0.00cvss 4.9epss 0.00

    The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via the 'filtersource' parameter in all versions up to, and including, 14.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing…

  • CVE-2026-15610MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-15407MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.7.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2026-15350MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    The The Cache Purger plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with…

  • CVE-2026-15324MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    The SysBasics Customize My Account for WooCommerce – Live My Account Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'row_type' parameter in all versions up to, and including, 4.4.14 due to insufficient input sanitization and output…

  • CVE-2026-15106MedJul 16, 2026
    risk 0.00cvss 5.3epss 0.00

    The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 8.5.6. This is due to the plugin not properly verifying that a user is authorized to perform an action. This…

  • CVE-2026-15103HigJul 16, 2026
    risk 0.00cvss 8.8epss 0.01

    The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitrary option update in all versions up to, and including, 3.12.8. This is due to the `update_settings()` REST callback failing to…

  • CVE-2026-15099MedJul 16, 2026
    risk 0.00cvss 6.4epss 0.00

    The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and including, 1.10.2. This is due to insufficient input sanitization and output escaping in the wrap_direction_text() function, which…

  • CVE-2026-15022MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.01

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient…

  • CVE-2026-15021MedJul 16, 2026
    risk 0.00cvss 6.4epss 0.00

    The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…

  • CVE-2026-15008HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.01

    The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it…

  • CVE-2026-15005HigJul 16, 2026
    risk 0.00cvss 8.8epss 0.00

    The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute…

  • CVE-2026-13767MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.00

    The Quiz Master Next plugin for WordPress is vulnerable to SQL Injection via stored quiz page data in versions up to, and including, 11.2.0. This is due to insufficient escaping on the user-supplied 'pages' parameter persisted by the qsm_ajax_save_pages() AJAX handler…

  • CVE-2026-13755MedJul 16, 2026
    risk 0.00cvss 6.4epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute in all versions up to, and including, 3.6.0.0 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2026-13754MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.00

    The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, 3.6.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…

  • CVE-2026-13741HigJul 16, 2026
    risk 0.00cvss 8.8epss 0.00

    The Digits: WordPress Mobile Number Signup and Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 9.1.0.5. This is due to missing authorization and role validation in the `dig_update_wpwc_custom_fields()` function. This makes…

  • CVE-2026-15925CriJul 16, 2026
    risk 0.53cvss —epss 0.00

    Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacker to bypass certificate hostname validation on HTTPS connections made by the connector. An attacker with on-path network access…

  • CVE-2026-12979MedJul 16, 2026
    risk 0.00cvss 5.5epss 0.00

    The FunnelKit WordPress plugin before 3.15.0.6 does not validate a user-supplied path before deleting a file during a template-import operation, allowing users with administrator privileges to delete arbitrary .json files outside the intended directory through path traversal,…

  • CVE-2026-12978HigJul 16, 2026
    risk 0.00cvss 7.1epss 0.00

    The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who…

  • CVE-2026-12907LowJul 16, 2026
    risk 0.00cvss 2.7epss 0.00

    The RTMKit WordPress plugin before 2.0.9 does not perform a proper capability check on one of its -builder AJAX actions, allowing users with at least the Author role to create and activate a site-wide template that overrides the header, footer or other global areas displayed to…

  • CVE-2026-12906LowJul 16, 2026
    risk 0.00cvss 2.7epss 0.00

    The RTMKit WordPress plugin before 2.0.9 does not perform a capability check in one of its AJAX actions and resolves a request-supplied post identifier directly, allowing users with at least the Contributor role to read the titles of other users' private, draft, pending,…

  • CVE-2026-12869MedJul 16, 2026
    risk 0.00cvss 6.1epss 0.00

    The Header Footer Builder for Elementor WordPress plugin before 1.2.1 does not require an administrative capability for its dashboard template-import action (it allows any edit_posts user), so a Contributor can import a template containing an Elementor HTML widget configured to…

  • CVE-2026-12684MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.00

    The Customer Reviews for WooCommerce WordPress plugin before 5.113.0 does not perform authentication, capability, or nonce checks on one of its media upload AJAX actions when the review media attachment feature is enabled, allowing unauthenticated users to upload media files…

  • CVE-2026-12585HigJul 16, 2026
    risk 0.00cvss 8.1epss 0.00

    The Abandoned Cart Lite for WooCommerce WordPress plugin before 6.8.2 does not protect the integrity of its cart-recovery tokens or bind them to the requesting account, allowing unauthenticated attackers to forge a recovery link that logs them in as another user when the…

  • CVE-2026-12525HigJul 16, 2026
    risk 0.00cvss 8.8epss 0.00

    The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating…

  • CVE-2026-12510MedJul 16, 2026
    risk 0.00cvss 5.9epss 0.00

    The AI Engine WordPress plugin before 3.5.5 does not verify that a user owns the chatbot conversation referenced by a client-supplied identifier, allowing users with subscriber-level access to read other users' private conversations and take over their conversation records when…

  • CVE-2026-12492CriJul 16, 2026
    risk 0.00cvss 9.8epss 0.01

    The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authenticating a user based on a supplied identifier, allowing unauthenticated attackers to log in as any existing user, including…

  • CVE-2026-12395MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.00

    The WP Job Portal WordPress plugin before 2.5.5 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authenticated users with a subscriber-level (self-registerable) account to perform SQL injection attacks.

  • CVE-2026-11866MedJul 16, 2026
    risk 0.00cvss 5.4epss 0.00

    The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher, allowing attackers to perform privileged actions, such as overwriting the booking-form configuration or…

  • CVE-2026-11371MedJul 16, 2026
    risk 0.00cvss 6.1epss 0.00

    The BetterDocs WordPress plugin before 4.5.5 does not sanitise an AI-generated documentation summary before storing and outputting it, and the feature that generates it is exposed to unauthenticated users, allowing them to store a malicious payload via prompt injection that…

  • CVE-2026-53366HigJul 16, 2026
    risk 0.44cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; …

  • CVE-2026-15458MedJul 16, 2026
    risk 0.00cvss 4.9epss 0.00

    The SEO Booster plugin for WordPress is vulnerable to generic SQL Injection via the 'sort_field' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2026-15445MedJul 16, 2026
    risk 0.00cvss 4.9epss 0.00

    The SEO Booster plugin for WordPress is vulnerable to time-based SQL Injection via the 'orderby' parameter in all versions up to, and including, 7.3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2026-15306MedJul 16, 2026
    risk 0.00cvss 6.1epss 0.00

    The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping.…

  • CVE-2026-15013CriJul 16, 2026
    risk 0.64cvss 9.8epss 0.01

    The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the…

  • CVE-2026-13042HigJul 16, 2026
    risk 0.00cvss 7.2epss 0.00

    The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject…

  • CVE-2026-21729HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.00

    Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.