VYPR

CVEs

378,385 total · page 97 of 7,568

  • CVE-2026-81648CriSep 13, 2026
    risk 0.65cvss 10.0epss 0.00

    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server, overwriting the payment…

  • CVE-2026-74933HigSep 13, 2026
    risk 0.57cvss 8.8epss 0.00

    The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and inject arbitrary web scripts that…

  • CVE-2026-49030Sep 13, 2026
    risk 0.00cvss epss

    Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

  • CVE-2026-38332LowSep 13, 2026
    risk 0.12cvss 2.9epss 0.00

    TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser::Fetch methods reachable via a crafted SubjectArea length.

  • CVE-2026-37008HigSep 13, 2026
    risk 0.46cvss 8.1epss 0.00

    CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete object graph. For example, calling…

  • CVE-2026-36989MedSep 13, 2026
    risk 0.38cvss 5.8epss 0.00

    A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php.

  • CVE-2026-36453HigSep 13, 2026
    risk 0.41cvss 7.4epss 0.00

    Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra variables.

  • CVE-2026-90583MedSep 13, 2026
    risk 0.21cvss 4.3epss 0.00

    A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected element is the function index of the file app/sw.py of the component Query String Rendering. Performing a manipulation of the argument qs results in cross site…

  • CVE-2026-90582MedSep 13, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file src/index.js of the component API Todo Endpoint. Such manipulation of the argument event.body leads to resource consumption. The attack can be executed…

  • CVE-2026-90581MedSep 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdate of the file /adminPage/main/autoUpdate. This manipulation of the argument url causes code injection. Remote exploitation of the attack is possible. The…

  • CVE-2026-90580MedSep 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the file packages/server/src/controllers/evaluations/index.ts of the component Evaluations Endpoint. The manipulation of the argument Host/X-Forwarded-Proto results…

  • CVE-2026-29812MedSep 13, 2026
    risk 0.21cvss 4.3epss 0.00

    CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

  • CVE-2026-29811HigSep 13, 2026
    risk 0.43cvss 7.7epss 0.00

    CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

  • CVE-2026-29810MedSep 13, 2026
    risk 0.21cvss 4.3epss 0.00

    CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

  • CVE-2025-70820LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    Zettlab D6 Ultra before 1.7.0 allows absolute path traversal to reach folders other than the personal folder.

  • CVE-2026-90579HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http_key of the file core/cat/factory/custom_auth_handler.py. The manipulation of the argument user_id leads to missing authentication. The attack may be initiated…

  • CVE-2026-90578MedSep 13, 2026
    risk 0.27cvss 5.3epss 0.00

    A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published…

  • CVE-2026-90577MedSep 13, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of the file scenegraph/base_scenegraph.c of the component MP4Box. Performing a manipulation results in heap-based buffer overflow. The attack is only possible…

  • CVE-2026-90576LowSep 13, 2026
    risk 0.14cvss 3.3epss 0.00

    A security vulnerability has been detected in GPAC up to f1219cde. Affected is the function gf_node_list_add_child of the file scenegraph/base_scenegraph.c of the component MP4Box. Such manipulation leads to null pointer dereference. The attack can only be performed from a local…

  • CVE-2025-70819MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    Zettlab D6 Ultra before 1.7.0 allows mounting /etc/passwd and /etc/shadow in a container via ".." manipulations such as volumes: - ../../../../../../../etc:/h_etc:rw in a compose file.

  • CVE-2025-64059LowSep 13, 2026
    risk 0.05cvss 1.8epss 0.00

    Grav 1.7.50.2 allows admins to enter JavaScript via the Home Page editor. NOTE: the relevance of this for stored XSS is disputed because admins are allowed to modify templates, install plugins, and upload other executable content.

  • CVE-2025-45480LowSep 13, 2026
    risk 0.20cvss 3.0epss 0.00

    Floodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.

  • CVE-2020-15875MedSep 13, 2026
    risk 0.26cvss 5.0epss 0.00

    An issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can extract all the information from the LibreNMS database via a SQL injection in the searchPhrase parameter in the /ajax_table.php API endpoint. This affects as-selection.inc.php,…

  • CVE-2026-90575LowSep 13, 2026
    risk 0.24cvss 3.7epss 0.00

    A weakness has been identified in PHPGurukul Small CRM 4.0. This impacts the function unserialize of the file /crm/login.php of the component Login Success Handler. This manipulation of the argument geopluginURL causes deserialization. It is possible to initiate the attack…

  • CVE-2026-90574MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/emp_transac.php?action=add. The manipulation of the argument firstname results in sql injection. The attack may be performed from remote. The…

  • CVE-2026-90573LowSep 13, 2026
    risk 0.14cvss 3.3epss 0.00

    A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_sg_mfurl_del of the file scenegraph/vrml_tools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The…

  • CVE-2026-90572MedSep 13, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient::opUpload of the file src/core/s7_micro_client.cpp. Executing a manipulation of the argument DataLen can lead to memory corruption. The attack can be executed…

  • CVE-2026-90571MedSep 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown function of the file xmall-manager-web/src/main/webapp/WEB-INF/jsp/order-print.jsp of the component Order Printing. Performing a manipulation results in cross site…

  • CVE-2026-90570LowSep 13, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdminGoodsService.validate of the file litemall-vue/src/views/items/detail/index.vue of the component Product Detail. Such manipulation of the argument detail…

  • CVE-2026-90569LowSep 13, 2026
    risk 0.16cvss 2.4epss 0.00

    A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of the component Admin Topic Handler. This manipulation causes cross site…

  • CVE-2026-90568LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort Endpoint. The manipulation of the argument sortName results in cross…

  • CVE-2026-90567LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function highlightKeyword of the file blog-web/src/components/Search/index.vue of the component Search. The manipulation of the argument title/summary leads to cross…

  • CVE-2026-90566HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the…

  • CVE-2026-90565MedSep 13, 2026
    risk 0.34cvss 5.3epss 0.01

    A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected is an unknown function of the file dashboard.php. Performing a manipulation of the argument userid results in improper access controls. It is…

  • CVE-2026-90564LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMsgList of the file blog-web/src/views/chat/index.vue of the component chat sendMsg Endpoint. Such manipulation of the argument chat_msg leads to cross site…

  • CVE-2026-90563LowSep 13, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the file ArticleController.java. This manipulation causes cross site scripting. The attack is possible to be carried out remotely.

  • CVE-2026-90529LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip of the file core/core-frontend/src/views/chart/components/js/panel/charts/map/symbolic-map.ts of the component Symbolic Map. Such manipulation of the argument…

  • CVE-2026-90528LowSep 13, 2026
    risk 0.23cvss 3.5epss 0.00

    A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality of the file tduck-front/src/views/form/write/index.vue of the component Form Write View. This manipulation of the argument submitShowCustomPageContent causes…

  • CVE-2026-90527MedSep 13, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admin/src/views/message/message/index.vue of the component Add Message API. The manipulation of the argument body.content results in cross site scripting. The…

  • CVE-2026-90526HigSep 13, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/save_class.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is…

  • CVE-2026-90525MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the file /pages/cust_pos_trans.php. Executing a manipulation of the argument firstname can lead to sql injection. The attack may be launched remotely. The exploit…

  • CVE-2026-90524HigSep 13, 2026
    risk 0.41cvss 7.3epss 0.01

    A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The impacted element is an unknown function of the component Update Endpoint. Performing a manipulation results in missing authentication. The attack…

  • CVE-2026-90523HigSep 13, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint.…

  • CVE-2026-90783HigSep 13, 2026
    risk 0.44cvss 7.8epss 0.00

    MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to integer wraparound in 32-bit arithmetic. Attackers can craft a malicious AVI file with oversized entry counts that cause an undersized heap allocation, allowing…

  • CVE-2026-90782MedSep 13, 2026
    risk 0.27cvss 5.3epss 0.00

    S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items() where a failed allocation for DataChangeNotification is overwritten by a successful allocation for EventNotificationList. Attackers can trigger heap…

  • CVE-2026-90781MedSep 13, 2026
    risk 0.22cvss 4.4epss 0.00

    alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through…

  • CVE-2026-90522HigSep 13, 2026
    risk 0.40cvss 7.3epss 0.01

    A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Password Recovery. This manipulation causes weak password recovery. The…

  • CVE-2026-90521MedSep 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of the component CRUD. The manipulation of the argument ID results in…

  • CVE-2026-90520MedSep 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the component Authorization Interceptor. The manipulation leads to…

  • CVE-2026-90519MedSep 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes unrestricted upload. Remote exploitation of the attack is possible.…