VYPR

CVEs

37,387 total · page 8 of 748

  • CVE-2026-14349CriSep 16, 2026
    risk 0.64cvss 9.8epss 0.00

    The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…

  • CVE-2026-12793CriSep 16, 2026
    risk 0.57cvss 9.8epss 0.00

    The JetFormBuilder — Dynamic Blocks Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.6.2. This is due to the plugin not validating that a submitted form ID belongs to a JetFormBuilder form before parsing the…

  • CVE-2026-15640CriSep 16, 2026
    risk 0.62cvss —epss 0.00

    Under certain conditions a valid SAML IdP response may be used to impersonate another Secret Server user.

  • CVE-2026-15639CriSep 16, 2026
    risk 0.60cvss —epss 0.00

    An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

  • CVE-2026-15638CriSep 16, 2026
    risk 0.59cvss —epss 0.00

    An unauthenticated user with access to Secret Server could leverage a padding oracle to decrypt or encrypt data using one of the server's cryptographic keys. The key itself is not exposed.

  • CVE-2026-81855CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing framework component of Wärtsilä FOS-Onboard.

  • CVE-2026-78225CriSep 15, 2026
    risk 0.59cvss 9.0epss 0.00

    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller component of Wärtsilä FOS-Onboard.

  • CVE-2026-73807CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions.

  • CVE-2026-73437CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP) relay configured, an unauthenticated attacker with network access could send a crafted DHCP reply packet from an IP address that is not configured as a helper address, and the relay agent…

  • CVE-2026-61560CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version 2.1.27, the SSE transport mode (`SSE=true`) exposes all MCP tools without any authentication. The `upload_markdown` tool reads arbitrary files from the server's local filesystem via an…

  • CVE-2026-91939CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.01

    Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without allowed_classes restriction, allowing unauthenticated attackers to instantiate arbitrary PHP classes with attacker-controlled properties. Attackers can exploit PHP object injection through crafted…

  • CVE-2026-91749CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Workers in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

  • CVE-2026-91738CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Improper input validation in ANGLE in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-91729CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in DigitalCredentials in Google Chrome prior to 153.0.8010.47 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-91728CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-91718CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-91716CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in Auth in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-91710CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Use after free in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

  • CVE-2026-68491CriSep 15, 2026
    risk 0.61cvss —epss 0.00

    An insufficient check allowed for the overwrite of arbitrary files via a symlink.

  • CVE-2026-66890CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.

  • CVE-2026-66887CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    The affected products are missing authorization on state-changing CGIs and session checks are not performed.

  • CVE-2026-61568CriSep 15, 2026
    risk 0.55cvss 9.6epss 0.00

    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to 2.1.30 expose the Streamable HTTP MCP endpoint without an effective Host or Origin allowlist. A malicious web page can use DNS rebinding to route browser requests to a victim's local MCP…

  • CVE-2026-61559CriSep 15, 2026
    risk 0.55cvss 9.6epss 0.00

    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version 0.0.1 and prior to version 2.1.27, when the environment variable `ENABLE_DYNAMIC_API_URL=true` is set, the server reads the `X-GitLab-API-URL` HTTP request header and uses it as the base…

  • CVE-2026-54337CriSep 15, 2026
    risk 0.57cvss 9.8epss 0.00

    Fireshare facilitates self-hosted media and link sharing. Prior to version 1.6.14, an argument Injection in the video upload function allows unauthenticated attacker to write/overwrite system files. Version 1.6.14 fixes the issue.

  • CVE-2026-92240CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    A malicious or compromised IMAP server can trigger an out-of-bounds read in the IMAP response parser by sending an untagged '* ID' response, crashing Thunderbird. The affected parsing path is reachable before authentication. This vulnerability was fixed in Thunderbird 156,…

  • CVE-2026-92238CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    A maliciously constructed mail header could lead to multiple fields being parsed as one, or potential memory safety violations. This vulnerability was fixed in Thunderbird 156, Thunderbird 140.16, and Thunderbird 153.3.

  • CVE-2026-89040CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.01

    Tencent Mass Service Engine in Cluster (MSEC) allows a remote, unauthenticated attacker to send a crafted POST request including ../ and gain root access on the target device. An attacker who uploads a webshell can execute arbitrary code as root.

  • CVE-2026-87230CriSep 15, 2026
    risk 0.65cvss 10.0epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-87223CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-87217CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-87214CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise…

  • CVE-2026-87189CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to…

  • CVE-2026-87188CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-87186CriSep 15, 2026
    risk 0.62cvss 9.6epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication…

  • CVE-2026-87184CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise…

  • CVE-2026-87176CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise…

  • CVE-2026-87175CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise…

  • CVE-2026-87173CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise…

  • CVE-2026-87172CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…

  • CVE-2026-87170CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise…

  • CVE-2026-87129CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-87128CriSep 15, 2026
    risk 0.59cvss 9.1epss 0.00

    Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-83462CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to…

  • CVE-2026-83452CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access…

  • CVE-2026-83355CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-83339CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via…

  • CVE-2026-83327CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to…

  • CVE-2026-83283CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…

  • CVE-2026-83282CriSep 15, 2026
    risk 0.64cvss 9.9epss 0.00

    Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP…

  • CVE-2026-83269CriSep 15, 2026
    risk 0.64cvss 9.8epss 0.00

    Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and 26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP…