VYPR

CVEs

1,665 total · page 5 of 34

  • CVE-2025-49704HigKEVJul 8, 2025
    risk 0.86cvss 8.8epss 1.00

    Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

  • CVE-2025-6554HigKEVJun 30, 2025
    risk 0.65cvss 8.1epss 0.13

    Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-32463CriKEVJun 30, 2025
    risk 0.72cvss 9.3epss 0.56

    Sudo before 1.9.17p1 allows local users to obtain root access because /etc/nsswitch.conf from a user-controlled directory is used with the --chroot option.

  • CVE-2025-20281CriKEVJun 25, 2025
    risk 0.85cvss 10.0epss 0.97

    A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to exploit this vulnerability. This…

  • CVE-2025-6543CriKEVJun 25, 2025
    risk 0.76cvss 9.8epss 0.10

    Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  • CVE-2025-32975CriKEVJun 24, 2025
    risk 0.77cvss 10.0epss 0.02

    Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate…

  • CVE-2025-48700MedKEVJun 23, 2025
    risk 0.45cvss 6.1epss 0.02

    An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0 and 10.0 and 10.1. A Cross-Site Scripting (XSS) vulnerability in the Zimbra Classic UI allows attackers to execute arbitrary JavaScript within the user's session, potentially leading to unauthorized access to…

  • CVE-2025-6218HigKEVJun 21, 2025
    risk 0.70cvss 7.8epss 0.89

    RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a…

  • CVE-2025-5777HigKEVJun 17, 2025
    risk 0.78cvss 7.5epss 1.00

    Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

  • CVE-2025-43200MedKEVJun 16, 2025
    risk 0.39cvss 4.2epss 0.01

    This issue was addressed with improved checks. This issue is fixed in iOS 15.8.4 and iPadOS 15.8.4, iOS 16.7.11 and iPadOS 16.7.11, iOS 18.3.1 and iPadOS 18.3.1, iPadOS 17.7.5, macOS Sequoia 15.3.1, macOS Sonoma 14.7.4, macOS Ventura 13.7.4, visionOS 2.3.1, watchOS 11.3.1. A…

  • CVE-2025-33073HigKEVJun 10, 2025
    risk 0.77cvss 8.8epss 0.80

    Improper access control in Windows SMB allows an authorized attacker to elevate privileges over a network.

  • CVE-2025-33053HigKEVJun 10, 2025
    risk 0.79cvss 8.8epss 0.85

    External control of file name or path in Internet Shortcut Files allows an unauthorized attacker to execute code over a network.

  • CVE-2025-47827MedKEVJun 5, 2025
    risk 0.42cvss 4.6epss 0.04

    In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image.

  • CVE-2025-21479HigKEVJun 3, 2025
    risk 0.68cvss 8.6epss 0.01

    Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

  • CVE-2025-27038HigKEVJun 3, 2025
    risk 0.61cvss 7.5epss 0.01

    Memory corruption while rendering graphics using Adreno GPU drivers in Chrome.

  • CVE-2025-21480HigKEVJun 3, 2025
    risk 0.68cvss 8.6epss 0.00

    Memory corruption due to unauthorized command execution in GPU micronode while executing specific sequence of commands.

  • CVE-2025-5419HigKEVJun 3, 2025
    risk 0.70cvss 8.8epss 0.06

    Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2025-5086CriKEVJun 2, 2025
    risk 0.78cvss 9.0epss 0.90

    A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could lead to a remote code execution.

  • CVE-2025-49113CriKEVJun 2, 2025
    risk 0.80cvss 9.9epss 0.98

    Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization.

  • CVE-2025-48928MedKEVMay 28, 2025
    risk 0.38cvss 4.0epss 0.00

    The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap content is roughly equivalent to a "core dump" in which a password previously sent over HTTP would be included in this dump, as exploited in the wild in May 2025.

  • CVE-2025-48927MedKEVMay 28, 2025
    risk 0.47cvss 5.3epss 0.09

    The TeleMessage service through 2025-05-05 configures Spring Boot Actuator with an exposed heap dump endpoint at a /heapdump URI, as exploited in the wild in May 2025.

  • CVE-2025-34026HigKEVMay 21, 2025
    risk 0.67cvss 7.5epss 0.83

    The Versa Concerto SD-WAN orchestration platform is vulnerable to an authentication bypass in the Traefik reverse proxy configuration, allowing at attacker to access administrative endpoints. The internal Actuator endpoint can be leveraged for access to heap dumps and trace…

  • CVE-2025-4008HigKEVMay 21, 2025
    risk 0.77cvss 8.8epss 0.94

    The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer their meteobridge system through a web application written in CGI shell scripts and C. This web interface exposes an endpoint that is vulnerable to command…

  • CVE-2025-32709HigKEVMay 13, 2025
    risk 0.63cvss 7.8epss 0.02

    Null pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32706HigKEVMay 13, 2025
    risk 0.63cvss 7.8epss 0.02

    Improper input validation in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-32701HigKEVMay 13, 2025
    risk 0.63cvss 7.8epss 0.01

    Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

  • CVE-2025-30400HigKEVMay 13, 2025
    risk 0.63cvss 7.8epss 0.02

    Use after free in Windows DWM allows an authorized attacker to elevate privileges locally.

  • CVE-2025-30397HigKEVMay 13, 2025
    risk 0.65cvss 7.5epss 0.21

    Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network.

  • CVE-2025-4428HigKEVMay 13, 2025
    risk 0.68cvss 7.2epss 0.85

    Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

  • CVE-2025-4427MedKEVMay 13, 2025
    risk 0.57cvss 5.3epss 1.00

    An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

  • CVE-2025-32756CriKEVMay 13, 2025
    risk 0.78cvss 9.8epss 0.33

    A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail…

  • CVE-2025-4632CriKEVMay 13, 2025
    risk 0.78cvss 9.8epss 0.24

    Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write arbitrary file as system authority.

  • CVE-2025-42999CriKEVMay 13, 2025
    risk 0.78cvss 9.1epss 0.11

    SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

  • CVE-2025-47729LowKEVMay 8, 2025
    risk 0.24cvss 1.9epss 0.00

    The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive"…

  • CVE-2025-35939MedKEVMay 7, 2025
    risk 0.40cvss 5.3epss 0.01

    Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session…

  • CVE-2025-2776CriKEVMay 7, 2025
    risk 0.78cvss 9.3epss 0.64

    SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

  • CVE-2025-2775CriKEVMay 7, 2025
    risk 0.77cvss 9.3epss 0.43

    SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

  • CVE-2025-27920HigKEVMay 5, 2025
    risk 0.59cvss 7.2epss 0.02

    Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By using ../ sequences in parameters, attackers could access sensitive files outside the intended directory, potentially leading to configuration leakage or…

  • CVE-2025-3935HigKEVApr 25, 2025
    risk 0.65cvss 8.1epss 0.03

    ScreenConnect versions 25.2.3 and earlier versions may be susceptible to a ViewState code injection attack. ASP.NET Web Forms use ViewState to preserve page and control state, with data encoded using Base64 protected by machine keys.  It is important to note that to obtain…

  • CVE-2025-3928HigKEVApr 25, 2025
    risk 0.69cvss 8.8epss 0.02

    Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89,…

  • CVE-2025-32432CriKEVApr 25, 2025
    risk 0.81cvss 10.0epss 1.00

    Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a…

  • CVE-2025-31324CriKEVApr 24, 2025
    risk 0.91cvss 10.0epss 1.00

    SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality,…

  • CVE-2025-1976MedKEVApr 24, 2025
    risk 0.56cvss 6.7epss 0.01

    Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.

  • CVE-2025-34028CriKEVApr 22, 2025
    risk 0.85cvss 10.0epss 0.98

    The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vulnerable to path traversal vulnerability that can result in Remote Code Execution via malicious…

  • CVE-2025-42599CriKEVApr 18, 2025
    risk 0.76cvss 9.8epss 0.03

    Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

  • CVE-2025-32433CriKEVApr 16, 2025
    risk 0.23cvss 10.0epss 0.99

    Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling,…

  • CVE-2025-31201CriKEVApr 16, 2025
    risk 0.77cvss 9.8epss 0.15

    This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication. Apple is aware of…

  • CVE-2025-31200CriKEVApr 16, 2025
    risk 0.77cvss 9.8epss 0.20

    A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4.1, macOS Sequoia 15.4.1, tvOS 18.4.1, visionOS 2.4.1, watchOS 11.5. Processing an audio stream in a maliciously crafted media file may result in code…

  • CVE-2024-58136CriKEVApr 10, 2025
    risk 0.70cvss 9.0epss 0.85

    Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.

  • CVE-2025-29824HigKEVApr 8, 2025
    risk 0.70cvss 7.8epss 0.14

    Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.