VYPR

CVEs

28,801 total · page 128 of 577

  • CVE-2025-62599HigFeb 3, 2026
    risk 0.56cvss 8.6epss 0.00

    eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a…

  • CVE-2020-37108HigFeb 3, 2026
    risk 0.46cvss 7.1epss 0.00

    PhpIX 2012 Professional contains a SQL injection vulnerability in the 'id' parameter of product_detail.php that allows remote attackers to manipulate database queries. Attackers can inject malicious SQL code through the 'id' parameter to potentially extract or modify database…

  • CVE-2020-37105HigFeb 3, 2026
    risk 0.46cvss 7.1epss 0.00

    PMB 5.6 contains a SQL injection vulnerability in the administration download script that allows authenticated attackers to execute arbitrary SQL commands through the 'logid' parameter. Attackers can leverage this vulnerability by sending crafted requests to the…

  • CVE-2026-25027HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.7.1.

  • CVE-2026-25022HigFeb 3, 2026
    risk 0.55cvss 8.5epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16.

  • CVE-2026-24954HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    Deserialization of Untrusted Data vulnerability in magepeopleteam WpEvently mage-eventpress allows Object Injection.This issue affects WpEvently: from n/a through <= 5.0.8.

  • CVE-2020-37102HigFeb 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with…

  • CVE-2020-37101HigFeb 3, 2026
    risk 0.51cvss 7.8epss 0.00

    VPN Unlimited 6.1 contains an unquoted service path vulnerability that allows local attackers to inject malicious executables into the service binary path. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\VPN Unlimited\' to replace the service executable and…

  • CVE-2020-37099HigFeb 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Savvy Enterprise\bin\disksvs.exe' to…

  • CVE-2020-37098HigFeb 3, 2026
    risk 0.51cvss 7.8epss 0.00

    Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be…

  • CVE-2025-7760HigFeb 3, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ofisimo Web-Based Software Technologies Association Web Package Flora allows XSS Through HTTP Headers.This issue affects Association Web Package Flora: from v3.0 through…

  • CVE-2025-6397HigFeb 3, 2026
    risk 0.56cvss 8.6epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Ankara Hosting Website Design Website Software allows Reflected XSS.This issue affects Website Software: through 03022026.  NOTE: The vendor was contacted early about…

  • CVE-2025-59902HigFeb 3, 2026
    risk 0.46cvss epss 0.00

    HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML content in email transcripts by modifying the 'firstName' and 'lastName' parameters during a chat session. The injected HTML is included in the body of the email…

  • CVE-2025-8461HigFeb 3, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Seres Software syWEB allows Reflected XSS.This issue affects syWEB: through 03022026.  NOTE: The vendor was contacted early about this disclosure but did not respond in…

  • CVE-2025-8456HigFeb 3, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kod8 Software Technologies Trade Ltd. Co. Kod8 Individual and SME Website allows Reflected XSS.This issue affects Kod8 Individual and SME Website: through 03022026.  …

  • CVE-2026-1730HigFeb 3, 2026
    risk 0.50cvss 8.8epss 0.00

    The OS DataHub Maps plugin for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'OS_DataHub_Maps_Admin::add_file_and_ext' function in all versions up to, and including, 1.8.3. This makes it possible for authenticated attackers, with…

  • CVE-2026-1375HigFeb 3, 2026
    risk 0.46cvss 8.1epss 0.00

    The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Insecure Direct Object References (IDOR) in all versions up to, and including, 3.9.5. This is due to missing object-level authorization checks in the `course_list_bulk_action()`,…

  • CVE-2025-8590HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    Exposure of Sensitive Information to an Unauthorized Actor vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows Directory Indexing.This issue affects SKSPro: through 07012026.

  • CVE-2025-8589HigFeb 3, 2026
    risk 0.49cvss 7.6epss 0.00

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AKCE Software Technology R&D Industry and Trade Inc. SKSPro allows Reflected XSS.This issue affects SKSPro: through 07012026.

  • CVE-2026-22550HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.

  • CVE-2026-1065HigFeb 3, 2026
    risk 0.47cvss 7.2epss 0.00

    The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.35. This is due to the plugin's default file upload allowlist including SVG files combined with weak substring-based extension validation. This…

  • CVE-2026-1058HigFeb 3, 2026
    risk 0.46cvss 7.1epss 0.00

    The Form Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via hidden field values in all versions up to, and including, 1.15.35. This is due to insufficient output escaping when displaying hidden field values in the admin submissions list. The plugin uses…

  • CVE-2026-0617HigFeb 3, 2026
    risk 0.47cvss 7.2epss 0.00

    The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer profile fields in all versions up to, and including, 5.2.5 due to insufficient input sanitization and output escaping. This…

  • CVE-2026-24694HigFeb 3, 2026
    risk 0.51cvss 7.8epss 0.00

    The installer for Roland Cloud Manager ver.3.1.19 and prior insecurely loads Dynamic Link Libraries (DLLs), which could allow an attacker to execute arbitrary code with the privileges of the application.

  • CVE-2025-67478HigFeb 3, 2026
    risk 0.57cvss 8.8epss 0.00

    Vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files includes/Mail/UserMailer.Php. This issue affects CheckUser: from * before 1.39.14, 1.43.4, 1.44.1.

  • CVE-2026-1777HigFeb 2, 2026
    risk 0.40cvss 7.2epss 0.00

    The Amazon SageMaker Python SDK before v3.2.0 and v2.256.0 includes the ModelBuilder HMAC signing key in the cleartext response elements of the DescribeTrainingJob function. A third party with permissions to both call this API and permissions to modify objects in the Training…

  • CVE-2026-0924HigFeb 2, 2026
    risk 0.46cvss 7.0epss 0.00

    BuhoCleaner contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via insecure functions.This issue affects BuhoCleaner: 1.15.2.

  • CVE-2022-50978HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

  • CVE-2022-50977HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.00

    An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.

  • CVE-2022-50976HigFeb 2, 2026
    risk 0.50cvss 7.7epss 0.00

    A local attacker could cause a full device reset by resetting the device passwords using an invalid reset file via USB.

  • CVE-2022-50975HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the device if configuration via ethernet is enabled.

  • CVE-2026-24070HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    During the installation of the Native Access application, a privileged helper `com.native-instruments.NativeAccess.Helper2`, which is used by Native Access to trigger functions via XPC communication like copy-file, remove or set-permissions, is deployed as well. The…

  • CVE-2026-1761HigFeb 2, 2026
    risk 0.56cvss 8.6epss 0.01

    A flaw was found in libsoup. This stack-based buffer overflow vulnerability occurs during the parsing of multipart HTTP responses due to an incorrect length calculation. A remote attacker can exploit this by sending a specially crafted multipart HTTP response, which can lead to…

  • CVE-2026-1186HigFeb 2, 2026
    risk 0.56cvss epss 0.00

    EAP Legislator is vulnerable to Path Traversal in file extraction functionality. Attacker can prepare zipx archive (default file type used by the Legislator application) and choose arbitrary path outside the intended directory (e.x. system startup) where files will be extracted…

  • CVE-2026-0599HigFeb 2, 2026
    risk 0.42cvss 7.5epss 0.00

    A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a…

  • CVE-2025-10279HigFeb 2, 2026
    risk 0.39cvss 7.0epss 0.00

    In mlflow version 2.20.3, the temporary directory used for creating Python virtual environments is assigned insecure world-writable permissions (0o777). This vulnerability allows an attacker with write access to the `/tmp` directory to exploit a race condition and overwrite…

  • CVE-2026-1117HigFeb 2, 2026
    risk 0.46cvss 8.2epss 0.00

    A vulnerability in the `lollms_generation_events.py` component of parisneo/lollms version 5.9.0 allows unauthenticated access to sensitive Socket.IO events. The `add_events` function registers event handlers such as `generate_text`, `cancel_generation`, `generate_msg`, and…

  • CVE-2024-54263HigFeb 2, 2026
    risk 0.49cvss 7.5epss 0.00

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Talemy Spirit Framework allows PHP Local File Inclusion.This issue affects Spirit Framework: from n/a through 1.2.13.

  • CVE-2025-9974HigFeb 2, 2026
    risk 0.52cvss 8.0epss 0.00

    The unified WEBUI application of the ONT/Beacon device contains an input handling flaw that allows authenticated users to trigger unintended system-level command execution. Due to insufficient validation of user-supplied data, a low-privileged authenticated attacker may be able…

  • CVE-2025-15396HigFeb 2, 2026
    risk 0.46cvss 7.1epss 0.00

    The Library Viewer WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

  • CVE-2026-1531HigFeb 2, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic…

  • CVE-2026-1530HigFeb 2, 2026
    risk 0.46cvss 8.1epss 0.00

    A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications between Satellite and…

  • CVE-2026-24788HigFeb 2, 2026
    risk 0.50cvss 8.8epss 0.00

    RaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be executed by a user who can log in to the product.

  • CVE-2026-1740HigFeb 2, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in EFM ipTIME A8004T 14.18.2. This impacts the function httpcon_check_session_url of the file /cgi/timepro.cgi of the component Hidden Hiddenloginsetup Interface. The manipulation results in improper authentication. The attack may be performed from…

  • CVE-2025-13348HigFeb 2, 2026
    risk 0.55cvss epss 0.00

    An improper access control vulnerability exists in ASUS Secure Delete Driver of ASUS Business Manager. This vulnerability can be triggered by a local user sending a specially crafted request, potentially leading to the creation of arbitrary files in a specified path. Refer to…

  • CVE-2020-37064HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network…

  • CVE-2020-37063HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be…

  • CVE-2020-37062HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service…

  • CVE-2020-37061HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the…

  • CVE-2020-37055HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    SpyHunter 4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path by placing malicious executables in specific file system locations to gain…