VYPR

CVEs

28,315 total · page 12 of 567

  • CVE-2010-20007HigAug 21, 2025
    risk 0.60cvss epss 0.16

    Seagull FTP Client <= v3.3 Build 409 contains a stack-based buffer overflow vulnerability in its FTP directory listing parser. When the client connects to an FTP server and receives a crafted response to a LIST command containing an excessively long filename, the application fails to properly validate input length, resulting in a buffer overflow that overwrites the Structured Exception Handler (SEH). This may allow remote attackers to execute arbitrary code on the client system. This product line was discontinued and users were advised to use BlueZone Secure FTP instead, at the time of disclosure.

  • CVE-2011-10014HigAug 13, 2025
    risk 0.60cvss epss 0.02

    GTA San Andreas Multiplayer (SA-MP) server version 0.3.1.1 is vulnerable to a stack-based buffer overflow triggered by parsing a malformed server.cfg configuration file. The vulnerability allows local attackers to execute arbitrary code when the server binary (samp-server.exe) processes a crafted echo directive containing excessive input. The original 'sa-mp.com' site is defunct, but the community maintains mirrors and forks that may be vulnerable.

  • CVE-2025-7769HigAug 6, 2025
    risk 0.60cvss epss 0.04

    Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE_PING command is called, allowing remote code execution due to improper handling of user input. When used with default credentials, this enables attackers to execute arbitrary commands on the device that could cause potential unauthorized access, service disruption, and data exposure.

  • CVE-2025-7771HigAug 6, 2025
    risk 0.60cvss epss 0.00

    ThrottleStop.sys, a legitimate driver, exposes two IOCTL interfaces that allow arbitrary read and write access to physical memory via the MmMapIoSpace function. This insecure implementation can be exploited by a malicious user-mode application to patch the running Windows kernel and invoke arbitrary kernel functions with ring-0 privileges. The vulnerability enables local attackers to execute arbitrary code in kernel context, resulting in privilege escalation and potential follow-on attacks, such as disabling security software or bypassing kernel-level protections. ThrottleStop.sys version 3.0.0.0 and possibly others are affected. Apply updates per vendor instructions.

  • CVE-2025-49484HigJul 18, 2025
    risk 0.60cvss epss 0.01

    A SQL injection vulnerability in the JS Jobs plugin versions 1.0.0-1.4.1 for Joomla allows low-privilege users to execute arbitrary SQL commands via the 'cvid' parameter in the employee application feature.

  • CVE-2025-34124HigJul 16, 2025
    risk 0.60cvss epss 0.27

    A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object name causes a buffer overflow, potentially allowing arbitrary code execution. Exploitation requires the victim to open a malicious map file within the game.

  • CVE-2024-56901HigFeb 3, 2025
    risk 0.60cvss 8.8epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability in Geovision GV-ASWeb application with the version 6.1.1.0 or less that allows attackers to arbitrarily create Administrator accounts via a crafted GET request method. This vulnerability is used in chain with CVE-2024-56903 for a successful CSRF attack.

  • CVE-2024-51442HigJan 8, 2025
    risk 0.60cvss 8.8epss 0.33

    Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.

  • CVE-2024-55587HigDec 12, 2024
    risk 0.60cvss 8.8epss 0.37

    python-libarchive through 4.2.1 allows directory traversal (to create files) in extract in zip.py for ZipFile.extractall and ZipFile.extract.

  • CVE-2024-10516HigDec 6, 2024
    risk 0.60cvss 8.1epss 0.88

    The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

  • CVE-2024-10674HigNov 9, 2024
    risk 0.60cvss 8.8epss 0.41

    The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install arbitrary plugins which can be leveraged to exploit other vulnerabilities and achieve remote code execution and privilege escalation.

  • CVE-2024-6387HigJul 1, 2024
    risk 0.60cvss 8.1epss 0.48

    A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.

  • CVE-2024-4351HigMay 16, 2024
    risk 0.60cvss 8.8epss 0.31

    The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized access of data, modification of data, loss of data due to a missing capability check on the 'authenticate' function in all versions up to, and including, 2.7.0. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to gain control of an existing administrator account.

  • CVE-2024-30491HigMar 29, 2024
    risk 0.60cvss 8.5epss 0.55

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

  • CVE-2024-1751HigMar 13, 2024
    risk 0.60cvss 8.8epss 0.35

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the question_id parameter in all versions up to, and including, 2.6.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with subscriber/student access or higher, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

  • CVE-2023-6700HigFeb 5, 2024
    risk 0.60cvss 8.8epss 0.29

    The Cookie Information | Free GDPR Consent Solution plugin for WordPress is vulnerable to arbitrary option updates due to a missing capability check on its AJAX request handler in versions up to, and including, 2.0.22. This makes it possible for authenticated attackers, with subscriber-level access or higher, to edit arbitrary site options which can be used to create administrator accounts.

  • CVE-2023-6634HigJan 11, 2024
    risk 0.60cvss 8.1epss 0.91

    The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This makes it possible for unauthenticated attackers to execute any public function with one parameter, which could result in remote code execution.

  • CVE-2017-17874HigDec 27, 2017
    risk 0.60cvss 8.8epss 0.02

    Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product preview" action, which can make a .php file accessible under a uploads/ URI.

  • CVE-2017-16995HigDec 27, 2017
    risk 0.60cvss 7.8epss 0.83

    The check_alu_op function in kernel/bpf/verifier.c in the Linux kernel through 4.4 allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging incorrect sign extension.

  • CVE-2017-5264HigDec 14, 2017
    risk 0.60cvss 8.8epss 0.00

    Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.

  • CVE-2017-17615HigDec 13, 2017
    risk 0.60cvss 8.8epss 0.00

    Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.

  • CVE-2017-11319HigDec 11, 2017
    risk 0.60cvss 8.8epss 0.02

    Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.

  • CVE-2017-7851HigNov 15, 2017
    risk 0.60cvss 8.8epss 0.00

    D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.

  • CVE-2017-16570HigNov 6, 2017
    risk 0.60cvss 8.8epss 0.00

    KeystoneJS before 4.0.0-beta.7 allows application-wide CSRF bypass by removing the CSRF parameter and value, aka SecureLayer7 issue number SL7_KEYJS_03. In other words, it fails to reject requests that lack an x-csrf-token header.

  • CVE-2017-16542HigNov 5, 2017
    risk 0.60cvss 8.8epss 0.01

    Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name parameter in a manageApplications.do?method=insert request.

  • CVE-2017-15957HigOct 29, 2017
    risk 0.60cvss 8.8epss 0.03

    my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.

  • CVE-2015-2878HigOct 23, 2017
    risk 0.60cvss 8.8epss 0.00

    Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/json; turn off the (2) Url matching, (3) DNS Inject, or (4) IP Redirect Sensor in a request to interface/rest/dpi/setEnabled/1; or (5) perform whitelisting of malware MD5 hash IDs via the id parameter to interface/rest/md5-threats/whitelist.

  • CVE-2017-15808HigOct 23, 2017
    risk 0.60cvss 8.8epss 0.00

    In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.

  • CVE-2017-7092HigOct 23, 2017
    risk 0.60cvss 8.8epss 0.30

    An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

  • CVE-2017-15735HigOct 22, 2017
    risk 0.60cvss 8.8epss 0.00

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) for modifying a glossary.

  • CVE-2017-15734HigOct 22, 2017
    risk 0.60cvss 8.8epss 0.00

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.main.php.

  • CVE-2017-15730HigOct 22, 2017
    risk 0.60cvss 8.8epss 0.00

    In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.

  • CVE-2017-15645HigOct 19, 2017
    risk 0.60cvss 8.8epss 0.01

    CSRF exists in Webmin 1.850. By sending a GET request to at/create_job.cgi containing dir=/&cmd= in the URI, an attacker to execute arbitrary commands.

  • CVE-2017-15644HigOct 19, 2017
    risk 0.60cvss 8.6epss 0.13

    SSRF exists in Webmin 1.850 via the PATH_INFO to tunnel/link.cgi, as demonstrated by a GET request for tunnel/link.cgi/http://INTRANET-IP:8000.

  • CVE-2017-10955HigOct 19, 2017
    risk 0.60cvss 8.8epss 0.33

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of EMC Data Protection Advisor 6.3.0. Authentication is required to exploit this vulnerability. The specific flaw exists within the EMC DPA Application service, which listens on TCP port 9002 by default. When parsing the preScript parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute arbitrary code under the context of SYSTEM. Was ZDI-CAN-4697. NOTE: Dell EMC disputes that this is a vulnerability

  • CVE-2015-7715HigOct 18, 2017
    risk 0.60cvss 8.8epss 0.00

    Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.

  • CVE-2017-15595HigOct 18, 2017
    risk 0.60cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.9.x allowing x86 PV guest OS users to cause a denial of service (unbounded recursion, stack consumption, and hypervisor crash) or possibly gain privileges via crafted page-table stacking.

  • CVE-2017-15578HigOct 18, 2017
    risk 0.60cvss 8.8epss 0.00

    In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.

  • CVE-2017-15276HigOct 13, 2017
    risk 0.60cvss 8.8epss 0.03

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batches (TAR archives). When unpacking TAR archives, Content Server fails to verify the contents of an archive, which causes a path traversal vulnerability via symlinks. Because some files on the Content Server filesystem are security-sensitive, this leads to privilege escalation.

  • CVE-2017-15013HigOct 13, 2017
    risk 0.60cvss 8.8epss 0.03

    OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server stores information about uploaded files in dmr_content objects, which are queryable and "editable" (before release 7.2P02, any authenticated user was able to edit dmr_content objects; now any authenticated user may delete a dmr_content object and then create a new one with the old identifier) by authenticated users; this allows any authenticated user to replace the content of security-sensitive dmr_content objects (for example, dmr_content related to dm_method objects) and gain superuser privileges.

  • CVE-2017-11763HigOct 13, 2017
    risk 0.60cvss 8.8epss 0.41

    The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.

  • CVE-2017-11762HigOct 13, 2017
    risk 0.60cvss 8.8epss 0.41

    The Microsoft Graphics Component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a remote code execution vulnerability in the way it handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability". This CVE ID is unique from CVE-2017-11763.

  • CVE-2015-2143HigOct 6, 2017
    risk 0.60cvss 8.8epss 0.00

    Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecified impact via unknown parameters.

  • CVE-2017-14848HigOct 3, 2017
    risk 0.60cvss 8.8epss 0.01

    WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.

  • CVE-2017-14758HigOct 3, 2017
    risk 0.60cvss 8.8epss 0.00

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

  • CVE-2017-14757HigOct 3, 2017
    risk 0.60cvss 8.8epss 0.00

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

  • CVE-2017-14847HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.01

    Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14846HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.01

    Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14845HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.01

    Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.

  • CVE-2017-14844HigSep 28, 2017
    risk 0.60cvss 8.8epss 0.01

    Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.