VYPR

CVEs

113,590 total · page 1 of 2,272

  • CVE-2026-15142HigAug 15, 2026
    risk 0.49cvss 7.5epss

    The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID…

  • CVE-2026-14279HigAug 15, 2026
    risk 0.57cvss 8.8epss

    The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.2.2 via the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce (which is exposed to any authenticated…

  • CVE-2026-16007HigAug 15, 2026
    risk 0.46cvss epss

    AppFlowy's qcuiknote feature is affected by a SQL injection vulnerability. Authenticated users with access to the feature can inject arbitrary SQL to exfiltrate data in the underlying SQL database.

  • CVE-2026-16145HigAug 15, 2026
    risk 0.40cvss 7.2epss

    The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 5.1 due to insufficient input sanitization and output escaping. This makes…

  • CVE-2026-13360HigAug 15, 2026
    risk 0.40cvss 7.2epss

    The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'regionArray' parameter in all versions up to, and including, 4.3.5 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-15965HigAug 15, 2026
    risk 0.57cvss 8.8epss

    The MaxUpload – Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.4.0 via the handle_upload function. This is due to a filename-validation mismatch in the handle_upload…

  • CVE-2026-15312HigAug 15, 2026
    risk 0.57cvss 8.8epss

    The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an…

  • CVE-2026-15162HigAug 15, 2026
    risk 0.49cvss 7.5epss

    The Object Sync for Salesforce plugin is vulnerable to unauthenticated SQL Injection via the wordpress_object_type parameter of its /wp-json/object-sync-for-salesforce/push/ REST route. The route's permission callback (can_process()) checks only the HTTP method for the push…

  • CVE-2026-15001HigAug 15, 2026
    risk 0.57cvss 8.8epss

    The bLoyal: Loyalty & Promotions by bLoyal plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.611.78. This is due to the AJAX actions `save_bloyal_configuration_data` and `save_bloyal_accesskeyverification_data` being registered…

  • CVE-2026-14433HigAug 15, 2026
    risk 0.47cvss 7.2epss

    The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'business_id' parameter in all versions up to, and including, 4.6.0 due to insufficient input sanitization and output escaping. This makes it…

  • CVE-2026-73683HigAug 14, 2026
    risk 0.46cvss 8.1epss

    Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC id_tokens by exploiting the missing nonce claim validation in the getUserByOIDCToken() function within FacebookProvider.php.…

  • CVE-2026-69414HigAug 14, 2026
    risk 0.51cvss 7.8epss

    Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide…

  • CVE-2026-55157higAug 14, 2026
    risk 0.38cvss epss

    ### Summary `token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool. The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`: ```ts getent passwd…

  • CVE-2026-73682HigAug 14, 2026
    risk 0.50cvss 8.8epss

    Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows authenticated users holding the Manager or Owner role on any project to achieve remote code execution on the Semaphore server…

  • CVE-2026-50523HigAug 14, 2026
    risk 0.51cvss 7.8epss

    Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute code locally.

  • CVE-2026-73680HigAug 14, 2026
    risk 0.50cvss 8.8epss

    Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the assets/upload permission to execute arbitrary commands by uploading a video file with a shell metacharacter-laden filename. The…

  • CVE-2026-71571HigAug 14, 2026
    risk 0.56cvss epss

    Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permissions to access iCagenda could inject SQL.

  • CVE-2026-64887HigAug 14, 2026
    risk 0.45cvss epss

    Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1.

  • CVE-2026-34492HigAug 14, 2026
    risk 0.45cvss epss

    External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1.

  • CVE-2026-19910HigAug 14, 2026
    risk 0.49cvss 7.5epss

    PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit…

  • CVE-2026-19909HigAug 14, 2026
    risk 0.49cvss 7.5epss

    PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. …

  • CVE-2026-19908HigAug 14, 2026
    risk 0.46cvss 7.1epss

    PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information and modify configuration on affected installations of PAX Technology Q80. Authentication is not required to exploit this…

  • CVE-2026-18554HigAug 14, 2026
    risk 0.49cvss 7.5epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-17179HigAug 14, 2026
    risk 0.55cvss 8.5epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.

  • CVE-2026-17177HigAug 14, 2026
    risk 0.49cvss 7.5epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

  • CVE-2026-17175HigAug 14, 2026
    risk 0.49cvss 7.5epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement.

  • CVE-2026-17081HigAug 14, 2026
    risk 0.53cvss 8.2epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricted directory.

  • CVE-2026-16915HigAug 14, 2026
    risk 0.49cvss 7.5epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper input validation.

  • CVE-2026-16879HigAug 14, 2026
    risk 0.57cvss 8.8epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper authorization using user-supplied input.

  • CVE-2026-16708HigAug 14, 2026
    risk 0.54cvss 8.3epss

    IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to obtain sensitive information due to external control of system configuration.

  • CVE-2026-53660higAug 14, 2026
    risk 0.45cvss epss

    ## Summary **Description** An Insecure Default Initialization of Resource (CWE-1188) issue in the OpenAM default configuration ships the `iPlanetDirectoryPro` SSO cookie with `HttpOnly=false`. Also, the `iPlanetDirectoryPro` SSO cookie is used as a CSRF token in OAuth/OIDC…

  • CVE-2026-35219higAug 14, 2026
    risk 0.38cvss epss

    ## Summary Budibase automation steps (outgoing webhook, Zapier, n8n, Slack, Discord, Make.com) make server-side HTTP requests to user-provided URLs using `node-fetch` directly, completely bypassing the IP blacklist protection that exists in the REST API integration.…

  • CVE-2026-73679HigAug 14, 2026
    risk 0.47cvss 7.2epss

    ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded…

  • CVE-2026-45699HigAug 14, 2026
    risk 0.42cvss 7.5epss

    Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow exists in the copydir() function of Netatalk's afpd daemon due to an integer underflow in the calculation of the remaining…

  • CVE-2026-73850HigAug 14, 2026
    risk 0.56cvss epss

    Emlog is an open source website building system. In 2.6.20 and earlier, there is a SQL injection vulnerability in the queryDatabase function in ai.php.

  • CVE-2026-72970HigAug 14, 2026
    risk 0.54cvss 8.3epss

    Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

  • CVE-2026-63361HigAug 14, 2026
    risk 0.48cvss epss

    LimeSurvey Community Edition 7.0.5 contains an authenticated reflected cross-site scripting vulnerability in the HTML editor popup endpoint. The text and name query parameters are passed through a blacklist sanitizer and then rendered without context-appropriate output encoding.

  • CVE-2026-19847HigAug 14, 2026
    risk 0.57cvss 8.8epss

    A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component wps.so. The manipulation of the argument pin results in stack-based buffer overflow. The attack can be…

  • CVE-2026-19846HigAug 14, 2026
    risk 0.57cvss 8.8epss

    A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setUrlFilterRules of the file /cgi-bin/cstecgi.cgi of the component firewall.so. The manipulation of the argument url leads to stack-based buffer overflow. The attack can be…

  • CVE-2026-19680HigAug 14, 2026
    risk 0.46cvss 7.1epss

    A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database.

  • CVE-2026-19679HigAug 14, 2026
    risk 0.57cvss 8.8epss

    An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue.

  • CVE-2026-19635HigAug 14, 2026
    risk 0.57cvss 8.8epss

    A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction.

  • CVE-2026-19629HigAug 14, 2026
    risk 0.53cvss 8.1epss

    A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables…

  • CVE-2026-12366HigAug 14, 2026
    risk 0.50cvss 8.8epss

    Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its reference count reaches zero, after running a per-object-type cleanup. The cleanup switch handled only K_OBJ_MSGQ and K_OBJ_STACK;…

  • CVE-2026-12364HigAug 14, 2026
    risk 0.48cvss 8.4epss

    The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-supplied source, desc, package, and data arguments directly to the kernel-mode implementation z_impl_z_log_msg_static_create()…

  • CVE-2026-49989HigAug 14, 2026
    risk 0.39cvss epss

    CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they know, and can plant new blobs unconditionally, in any blob table, regardless of `GRANT`s. CrateDB has two ways to access blob…

  • CVE-2026-49986HigAug 14, 2026
    risk 0.46cvss epss

    The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer…

  • CVE-2026-46603HigAug 14, 2026
    risk 0.42cvss 7.5epss

    VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffman tree groups. This allows a remote attacker to cause a denial of service via memory exhaustion.

  • CVE-2026-46439HigAug 14, 2026
    risk 0.44cvss 7.8epss 0.00

    compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an…

  • CVE-2026-19845HigAug 14, 2026
    risk 0.57cvss 8.8epss

    A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi of the component lan.so. Executing a manipulation of the argument Comment can lead to stack-based buffer overflow. It is…