VYPR

CVEs

28,801 total · page 126 of 577

  • CVE-2026-2113HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in yuan1994 tpadmin up to 1.3.12. This affects an unknown part in the library /public/static/admin/lib/webuploader/0.1.5/server/preview.php of the component WebUploader. The manipulation leads to deserialization. The attack is possible…

  • CVE-2026-2090HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in SourceCodester Online Class Record System 1.0. This issue affects some unknown processing of the file /admin/message/search.php. Executing a manipulation of the argument term can lead to sql injection. The attack can be executed remotely. The…

  • CVE-2026-2089HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible.…

  • CVE-2026-2088HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. This affects an unknown part of the file /admin/accepted-appointment.php. Such manipulation of the argument delid leads to sql injection. The attack may be launched remotely. The exploit has been…

  • CVE-2026-2087HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in SourceCodester Online Class Record System 1.0. Affected by this issue is some unknown functionality of the file /admin/login.php. This manipulation of the argument user_email causes sql injection. The attack may be initiated remotely. The exploit has…

  • CVE-2026-2083HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file /delete_post.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has…

  • CVE-2026-2073HigFeb 7, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/user/index.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has…

  • CVE-2020-37163HigFeb 7, 2026
    risk 0.53cvss 8.2epss 0.00

    QuickDate 1.3.2 contains a SQL injection vulnerability that allows remote attackers to manipulate database queries through the '_located' parameter in the find_matches endpoint. Attackers can inject UNION-based SQL statements to extract database information including user…

  • CVE-2020-37157HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    DBPower C300 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive credentials through an unprotected configuration backup endpoint. Attackers can download the configuration file and extract hardcoded username and…

  • CVE-2020-37155HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without…

  • CVE-2020-37154HigFeb 7, 2026
    risk 0.46cvss 7.1epss 0.00

    eLection 2.0 contains an authenticated SQL injection vulnerability in the candidate management endpoint that allows attackers to manipulate database queries through the 'id' parameter. Attackers can leverage SQLMap to exploit the vulnerability, potentially gaining remote code…

  • CVE-2020-37147HigFeb 7, 2026
    risk 0.46cvss 7.1epss 0.00

    ATutor 2.2.4 contains a SQL injection vulnerability in the admin user deletion page that allows authenticated attackers to manipulate database queries through the 'id' parameter. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'id' parameter of…

  • CVE-2020-37146HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint,…

  • CVE-2020-37141HigFeb 7, 2026
    risk 0.53cvss 8.2epss 0.00

    AMSS++ version 4.31 contains a SQL injection vulnerability in the mail module's maildetail.php script through the 'id' parameter. Attackers can manipulate the 'id' parameter in /modules/mail/main/maildetail.php to inject malicious SQL queries and potentially access or modify…

  • CVE-2020-37135HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    AMSS++ 4.7 contains an authentication bypass vulnerability that allows attackers to access administrative accounts using hardcoded credentials. Attackers can log in with the default admin username and password '1234' to gain unauthorized administrative access to the system.

  • CVE-2020-37122HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    SpotFTP-FTP Password Recover 2.4.8 contains a denial of service vulnerability that allows attackers to crash the application by generating a large buffer overflow. Attackers can create a text file with 1000 'Z' characters and input it as a registration code to trigger the…

  • CVE-2020-37109HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Subject title field with a large buffer. Attackers can generate a 1000-character buffer and paste it into the Subject title to trigger an…

  • CVE-2020-37107HigFeb 7, 2026
    risk 0.49cvss 7.5epss 0.00

    Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the account field with a large buffer. Attackers can create a text file with 20,000 repeated characters and paste it into the account field to cause the…

  • CVE-2026-2060HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Simple Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /simpleblooddonor/editcampaignform.php. Performing a manipulation of the argument ID results in sql injection. It is…

  • CVE-2026-2059HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in SourceCodester Medical Center Portal Management System 1.0. Affected is an unknown function of the file /emp_edit1.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been…

  • CVE-2026-2058HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql…

  • CVE-2019-25305HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    JumpStart 0.6.0.0 contains an unquoted service path vulnerability in the jswpbapi service running with LocalSystem privileges. Attackers can exploit the unquoted path containing spaces to inject and execute malicious code with elevated system permissions.

  • CVE-2019-25304HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    SecurOS Enterprise 10.2 contains an unquoted service path vulnerability in the SecurosCtrlService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\ISS\SecurOS\ to insert malicious code…

  • CVE-2019-25303HigFeb 6, 2026
    risk 0.46cvss 7.1epss 0.00

    TheJshen ContentManagementSystem 1.04 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to extract or manipulate…

  • CVE-2019-25302HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Acer Launch Manager 6.1.7600.16385 contains an unquoted service path vulnerability in the DsiWMIService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Launch Manager\dsiwmis.exe to…

  • CVE-2019-25300HigFeb 6, 2026
    risk 0.46cvss 7.1epss 0.00

    thejshen Globitek CMS 1.4 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'id' GET parameter. Attackers can exploit boolean-based, time-based, and UNION-based SQL injection techniques to potentially extract or modify…

  • CVE-2019-25299HigFeb 6, 2026
    risk 0.46cvss 7.1epss 0.00

    RimbaLinux AhadPOS 1.11 contains a SQL injection vulnerability in the 'alamatCustomer' parameter that allows attackers to manipulate database queries through crafted POST requests. Attackers can exploit time-based and boolean-based blind SQL injection techniques to extract…

  • CVE-2019-25293HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files…

  • CVE-2019-25292HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Alps HID Monitor Service 8.1.0.10 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\Apoint2K\HidMonitorSvc.exe to inject…

  • CVE-2019-25266HigFeb 6, 2026
    risk 0.51cvss 7.8epss 0.00

    Wondershare Application Framework Service 2.4.3.231 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted service path by placing malicious executables in…

  • CVE-2026-2057HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in SourceCodester Medical Center Portal Management System 1.0. This affects an unknown function of the file /login.php. The manipulation of the argument User results in sql injection. The attack can be executed remotely. The exploit is now public and…

  • CVE-2026-2018HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in itsourcecode School Management System 1.0. This affects an unknown part of the file /ramonsys/settings/controller.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been…

  • CVE-2026-2014HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /ramonsys/billing/index.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The…

  • CVE-2026-2013HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in itsourcecode Student Management System 1.0. This affects an unknown function of the file /ramonsys/soa/index.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly available…

  • CVE-2026-2012HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /ramonsys/facultyloading/index.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit…

  • CVE-2026-2011HigFeb 6, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /ramonsys/enrollment/controller.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit…

  • CVE-2026-1499HigFeb 6, 2026
    risk 0.57cvss 8.8epss 0.00

    The WP Duplicate plugin for WordPress is vulnerable to Missing Authorization leading to Arbitrary File Upload in all versions up to and including 1.1.8. This is due to a missing capability check on the `process_add_site()` AJAX action combined with path traversal in the file…

  • CVE-2025-15566HigFeb 6, 2026
    risk 0.57cvss 8.8epss 0.00

    A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and…

  • CVE-2026-24302HigFeb 5, 2026
    risk 0.56cvss 8.6epss 0.00

    Improper access control in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2020-37143HigFeb 5, 2026
    risk 0.49cvss 7.5epss 0.00

    ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and…

  • CVE-2020-37142HigFeb 5, 2026
    risk 0.55cvss 8.4epss 0.00

    10-Strike Network Inventory Explorer 8.54 contains a structured exception handler buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting SEH records. Attackers can craft a malicious payload targeting the 'Computer' parameter during the 'Add'…

  • CVE-2020-37139HigFeb 5, 2026
    risk 0.55cvss 8.4epss 0.00

    Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the application by manipulating site information fields. Attackers can generate a buffer overflow by pasting 108 bytes of repeated characters into connection fields,…

  • CVE-2020-37136HigFeb 5, 2026
    risk 0.49cvss 7.5epss 0.00

    ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the application to become unresponsive when…

  • CVE-2020-37134HigFeb 5, 2026
    risk 0.49cvss 7.5epss 0.00

    UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application…

  • CVE-2020-37130HigFeb 5, 2026
    risk 0.49cvss 7.5epss 0.00

    Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the…

  • CVE-2026-1523HigFeb 5, 2026
    risk 0.57cvss epss 0.00

    Path Traversal vulnerability in Digitek ADT1100 and Digitek DT950 from PRIMION DIGITEK, S.L.U (Azkoyen Group). This vulnerability allows an attacker to access arbitrary files in the server's file system, thet is, 'http:///..%2F..% 2F..%2F..%2F..%2F..%2F..%2F..%2F..%2Fetc%2F…

  • CVE-2026-23572HigFeb 5, 2026
    risk 0.47cvss 7.2epss 0.00

    Improper access control in the TeamViewer Full and Host clients (Windows, macOS, Linux) prior version 15.74.5 allows an authenticated user to bypass additional access controls with “Allow after confirmation” configuration in a remote…

  • CVE-2026-1294HigFeb 5, 2026
    risk 0.40cvss 7.2epss 0.00

    The All In One Image Viewer Block plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.2 due to missing authorization and URL validation on the image-proxy REST API endpoint. This makes it possible for unauthenticated…

  • CVE-2026-1953HigFeb 5, 2026
    risk 0.53cvss epss 0.00

    Nukegraphic CMS v3.1.2 contains a stored cross-site scripting (XSS) vulnerability in the user profile edit functionality at /ngc-cms/user-edit-profile.php. The application fails to properly sanitize user input in the name field before storing it in the database and rendering it…

  • CVE-2025-15080HigFeb 5, 2026
    risk 0.57cvss epss 0.00

    Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric MELSEC iQ-R Series R08PCPU, R16PCPU, R32PCPU, and R120PCPU allows an unauthenticated attacker to read device data or part of a control program from the affected product, write device data in…