VYPR

CVEs

35,144 total · page 9 of 703

  • CVE-2026-65572CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

  • CVE-2026-65571CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

  • CVE-2026-65556CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

  • CVE-2026-65553CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.00

    Unauthenticated Remote Code Execution (RCE) in Spider Analyser – WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

  • CVE-2026-65552CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

  • CVE-2026-65548CriAug 6, 2026
    risk 0.64cvss 9.9epss 0.00

    Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

  • CVE-2026-65546CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

  • CVE-2026-65520CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

  • CVE-2026-65508CriAug 6, 2026
    risk 0.60cvss 9.3epss 0.00

    Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

  • CVE-2026-65507CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.

  • CVE-2026-54489CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session…

  • CVE-2026-53976CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.02

    OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an…

  • CVE-2026-53975CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any…

  • CVE-2026-34191CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3

  • CVE-2026-32327CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.

  • CVE-2026-28139CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

  • CVE-2026-28005CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

  • CVE-2026-5134CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. CMS allows SQL Injection. This issue affects CMS: through 06082026. NOTE: The vendor was contacted early about this disclosure…

  • CVE-2026-12605CriAug 6, 2026
    risk 0.62cvss 9.6epss 0.00

    In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled host if the victim is authenticated into the Admin Console -\> full unauthenticated takeover of Eclipse GlassFish domain until the…

  • CVE-2026-68079CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization code MUST NOT be…

  • CVE-2026-65583CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/time and sub_jwk binding), enabling authentication bypass with crafted tokens. However, note that self-issued ID tokens are not…

  • CVE-2026-63687CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can…

  • CVE-2026-61466CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning…

  • CVE-2026-66909CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to…

  • CVE-2026-64597CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_close_init() fails before the next send, cleanup retains the…

  • CVE-2026-5430CriAug 6, 2026
    risk 0.65cvss 10.0epss 0.00

    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. Successful…

  • CVE-2026-1728CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitation of this vulnerability allows a low-privileged user to invoke the Admin REST APIs of WSO2 products, potentially leading to full…

  • CVE-2025-15039CriAug 6, 2026
    risk 0.61cvss 9.4epss 0.00

    The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate…

  • CVE-2026-16054CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce that is the only control gating its file-deletion routine, allowing anonymous attackers to delete files staged in its upload…

  • CVE-2026-12713CriAug 6, 2026
    risk 0.59cvss 9.1epss 0.00

    The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by…

  • CVE-2026-67873CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encode() validates only the standalone segment length via FileSegment_GetMaxDataSize() and does not verify the residual capacity of the…

  • CVE-2026-67870CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.01

    In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remote attacker can send a crafted AddReferencesRequest with an empty targetServerUri and a non-zero targetNodeId.serverIndex, causing…

  • CVE-2026-67531CriAug 6, 2026
    risk 0.53cvss epss 0.00

    FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances to the script via getTool(), and because Zod v4 defines _zod as a non-configurable, non-writable own…

  • CVE-2026-52466CriAug 6, 2026
    risk 0.64cvss 9.8epss 0.00

    Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming request in VuFind\Controller\AbstractBase::validateAccessPermission after it has found that controller level access permissions do not…

  • CVE-2026-71319CriAug 5, 2026
    risk 0.55cvss 9.6epss 0.00

    Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the nuxt:devtools:rpc plugin. On affected versions the channel has no authentication: any client…

  • CVE-2025-63823CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentication and gain unauthorized access to user accounts via predictable OTP values.

  • CVE-2026-70615CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission to inject arbitrary lines into the server account's SSH authorized_keys file by supplying a percent-encoded newline character in…

  • CVE-2026-48168CriAug 5, 2026
    risk 0.00cvss 10.0epss 0.01

    PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation.…

  • CVE-2026-70426CriAug 5, 2026
    risk 0.59cvss 9.0epss 0.00

    In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing…

  • CVE-2026-20310CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…

  • CVE-2026-20304CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered…

  • CVE-2026-20303CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…

  • CVE-2026-20272CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…

  • CVE-2026-20267CriAug 5, 2026
    risk 0.59cvss 9.0epss 0.00

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…

  • CVE-2026-9195CriAug 5, 2026
    risk 0.00cvss 9.3epss 0.00

    A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a crafted URL to execute arbitrary JavaScript in the administrator's browser session, capture…

  • CVE-2026-9193CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop role to escalate privileges and execute privileged operations against the Security database.

  • CVE-2026-9192CriAug 5, 2026
    risk 0.64cvss 9.8epss 0.00

    An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password verification and execute queries with the privileges of any named user known to the server, including…

  • CVE-2026-9190CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and authorization checks, hijack a legitimate user's session, or capture credentials. The vulnerability occurs…

  • CVE-2026-8709CriAug 5, 2026
    risk 0.64cvss 9.9epss 0.00

    An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges and execute privileged operations against the…

  • CVE-2026-7557CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.00

    An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass authentication and impersonate any user, including administrators. This…