VYPR

CVEs

387,028 total · page 757 of 7,741

  • CVE-2026-15652MedJul 16, 2026
    risk 0.00cvss 6.4epss 0.00

    The Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'align' Block Attribute in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-15336MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    The Catch Themes Demo Import plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.3. This is due to the catch_themes_demo_import_activate_plugin() function, hooked on admin_init when the activate_plugin GET parameter is present, calling…

  • CVE-2026-14987MedJul 16, 2026
    risk 0.00cvss 6.4epss 0.00

    The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting in all versions up to, and including, 4.16.3 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-13005MedJul 16, 2026
    risk 0.00cvss 4.4epss 0.00

    The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-12941MedJul 16, 2026
    risk 0.00cvss 6.5epss 0.00

    The MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions plugin for WordPress is vulnerable to generic SQL Injection via the 'order_by' parameter in all versions up to, and including, 5.0.9 due to insufficient escaping on the user supplied parameter and lack…

  • CVE-2026-12753HigJul 16, 2026
    risk 0.00cvss 7.5epss 0.01

    The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of…

  • CVE-2026-12434MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    The List category posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 0.95.0 via the sanitize_status. This makes it possible for authenticated attackers, with contributor-level access and above, to extract titles, full…

  • CVE-2026-12409MedJul 16, 2026
    risk 0.00cvss 4.3epss 0.00

    The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.3.6. This is due to missing or incorrect nonce validation on the…

  • CVE-2026-48863HigJul 16, 2026
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI…

  • CVE-2026-3842HigJul 16, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful…

  • CVE-2026-23538HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server…

  • CVE-2026-1609HigJul 16, 2026
    risk 0.53cvss 8.1epss 0.01

    A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can…

  • CVE-2026-15909MedJul 16, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected is an unknown function of the file proses/add.php. The manipulation of the argument kd_cs leads to authorization bypass. The attack is possible to be carried out…

  • CVE-2026-15907HigJul 16, 2026
    risk 0.00cvss 7.3epss 0.00

    A flaw has been found in H3C SecPath F1000-C8300 up to 20260522. This impacts an unknown function of the file /webui/?g=log_fw_nbc_mail_jsondata. Executing a manipulation of the argument subject can lead to sql injection. The attack can be executed remotely. The exploit has been…

  • CVE-2026-63175HigJul 15, 2026
    risk 0.00cvss —epss 0.00

    PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture objects running within the same Python process could share state, including HTTP headers, cookies,…

  • CVE-2026-62314MedJul 15, 2026
    risk 0.31cvss 5.8epss 0.00

    Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scraper bots. From 1.22.0 until 1.26.0-pre1, lib/policy/checker.go PathChecker.Check() trusted the client-controlled X-Original-URI header before matching…

  • CVE-2026-55652CriJul 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLoginAuth.js to trust the client-supplied X-Forwarded-For header before the real socket address, allowing an unauthenticated attacker…

  • CVE-2026-55576HigJul 15, 2026
    risk 0.57cvss —epss 0.00

    MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a run: shell command during the pull_request opened, reopened, and…

  • CVE-2026-55445CriJul 15, 2026
    risk 0.54cvss —epss 0.01

    Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in back/loaders/express.ts checks /api/user/init but not /open/user/init, while rewrite('/open/*', '/api/$1') rewrites the whitelisted…

  • CVE-2026-55234HigJul 15, 2026
    risk 0.48cvss 8.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.js, server/permissions/lists.js, and server/permissions/swimlanes.js authorize against the stored source boardId and do not validate a new boardId in the update…

  • CVE-2026-54458CriJul 15, 2026
    risk 0.55cvss 9.6epss 0.01

    WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin of every administrator currently…

  • CVE-2026-53447MedJul 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.35, the Wekan cloneBoard Meteor method in models/import.js uses caller-supplied sourceBoardId to build a board export through models/exporter.js without invoking canExport() or checking source-board membership. Any…

  • CVE-2026-53446MedJul 15, 2026
    risk 0.33cvss —epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan webhook integration URLs in models/integrations.js are stored from user input and later fetched by server/notifications/outgoing.js without applying the existing validateAttachmentUrl() private-network checks…

  • CVE-2026-53445HigJul 15, 2026
    risk 0.39cvss —epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan copyBoard Meteor DDP method in server/publications/boards.js copies a board by caller-supplied board ID without checking this.userId, membership, or admin access. Any authenticated user can copy a private…

  • CVE-2026-53444HigJul 15, 2026
    risk 0.42cvss —epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan OIDC-related Meteor methods in packages/wekan-oidc/oidc_server.js, server/models/org.js, and server/models/team.js are globally callable without the admin authorization checks used by their non-OIDC…

  • CVE-2026-52893CriJul 15, 2026
    risk 0.00cvss —epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into existing accounts when the OIDC email or username matches an existing Wekan user, without verifying ownership or checking…

  • CVE-2026-52892MedJul 15, 2026
    risk 0.35cvss 6.5epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.32, Wekan REST handlers in server/models/customFields.js use read-level Authentication.checkBoardAccess instead of write-level Authentication.checkBoardWriteAccess for mutating custom-field routes. A read-only board…

  • CVE-2026-52891CriJul 15, 2026
    risk 0.57cvss 9.9epss 0.01

    Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec() for MIME-type detection. Because models/avatars.js and models/fileValidation.js used a shell command…

  • CVE-2026-52890HigJul 15, 2026
    risk 0.39cvss 7.1epss 0.00

    Wekan is open source kanban built with Meteor. Prior to 9.31, Wekan allows a logged-in board member to insert an attachment document through the /attachments/insert DDP method with attacker-controlled versions.original.path and versions.original.storage fields. The…

  • CVE-2026-50183MedJul 15, 2026
    risk 0.24cvss 4.7epss 0.00

    WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data API into the homepage gallery markup with no HTML encoding.…

  • CVE-2026-50182MedJul 15, 2026
    risk 0.33cvss 6.1epss 0.00

    WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenated directly into the href attribute of two pagination links…

  • CVE-2026-49279HigJul 15, 2026
    risk 0.43cvss —epss 0.01

    WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg'], but…

  • CVE-2026-48795HigJul 15, 2026
    risk 0.49cvss 8.6epss 0.01

    AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via…

  • CVE-2026-45313HigJul 15, 2026
    risk 0.43cvss 7.7epss 0.00

    Sandboxie-Plus is an open source sandbox-based isolation software for Windows. Prior to 1.17.6, GuiServer::WndHookRegisterSlave in Sandboxie/core/svc/GuiServer.cpp stores attacker-supplied hthread and hproc fields from a GUI_WND_HOOK_REGISTER request without validating that the…

  • CVE-2026-38974MedJul 15, 2026
    risk 0.50cvss 5.3epss 0.00

    Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.

  • CVE-2026-38755LowJul 15, 2026
    risk 0.19cvss 2.9epss 0.00

    A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • CVE-2026-38754MedJul 15, 2026
    risk 0.33cvss 5.1epss 0.00

    A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

  • CVE-2026-38752LowJul 15, 2026
    risk 0.19cvss 2.9epss 0.00

    A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

  • CVE-2026-36590HigJul 15, 2026
    risk 0.00cvss 7.5epss 0.01

    An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component

  • CVE-2026-30623CriJul 15, 2026
    risk 0.64cvss 9.8epss 0.05

    LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without…

  • CVE-2026-30618CriJul 15, 2026
    risk 0.00cvss 9.8epss 0.01

    xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and…

  • CVE-2026-26719MedJul 15, 2026
    risk 0.00cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script

  • CVE-2026-26718CriJul 15, 2026
    risk 0.00cvss 9.1epss 0.00

    A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP…

  • CVE-2026-15921LowJul 15, 2026
    risk 0.13cvss 3.1epss 0.00

    Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm install --lts`) parse the node.js mirror's `index.tab` and…

  • CVE-2025-65720CriJul 15, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.

  • CVE-2026-62361MedJul 15, 2026
    risk 0.00cvss 5.5epss 0.00

    listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscribers/export endpoint injects the user-controlled query parameter into QuerySubscribersForExport in internal/core/subscribers.go without calling…

  • CVE-2026-62312HigJul 15, 2026
    risk 0.00cvss 8.8epss 0.01

    9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitrary code execution on the host operating system by combining a Host header bypass of localhost-only routes with unvalidated MCP plugin args passed to…

  • CVE-2026-59950HigJul 15, 2026
    risk 0.46cvss 8.1epss 0.00

    The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1, the deprecated mcp.server.websocket.websocket_server transport accepted WebSocket handshakes without applying Host or Origin header validation, leaving no…

  • CVE-2026-56679HigJul 15, 2026
    risk 0.50cvss —epss 0.01

    9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body to persistent settings without a field whitelist, allowing an authenticated user to set security-critical fields such as requireLogin and disable authentication…

  • CVE-2026-56678MedJul 15, 2026
    risk 0.35cvss 6.4epss 0.00

    9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key builds an upstream URL using a user-controlled region value, allowing an authenticated attacker to supply a crafted region such as kiro-canary.local:8443# and…