VYPR

CVEs

28,801 total · page 129 of 577

  • CVE-2020-37048HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Iskysoft Application Framework Service 2.4.3.241 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious…

  • CVE-2020-37047HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Deep Instinct Windows Agent 1.2.29.0 contains an unquoted service path vulnerability in the DeepMgmtService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files\HP Sure Sense\DeepMgmtService.exe…

  • CVE-2020-37045HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject…

  • CVE-2020-37037HigFeb 1, 2026
    risk 0.51cvss 7.8epss 0.00

    Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with…

  • CVE-2021-47909HigFeb 1, 2026
    risk 0.53cvss 8.1epss 0.00

    Mult-E-Cart Ultimate 2.4 contains multiple SQL injection vulnerabilities in inventory, customer, vendor, and order modules. Remote attackers with privileged vendor or admin roles can exploit the 'id' parameter to execute malicious SQL commands and compromise the database…

  • CVE-2025-14554HigJan 31, 2026
    risk 0.40cvss 7.2epss 0.00

    The Sell BTC - Cryptocurrency Selling Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'orderform_data' AJAX action in all versions up to, and including, 1.5 due to insufficient input sanitization and output escaping. This makes it possible…

  • CVE-2020-37049HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Frigate 3.36.0.9 contains a local buffer overflow vulnerability in the Command Line input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload to overflow the buffer, bypass DEP, and execute commands like launching calc.exe through a…

  • CVE-2020-37042HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the 'Find Computer' feature that allows attackers to execute arbitrary code by overflowing the computer name input field. Attackers can craft a malicious payload that triggers a buffer overflow,…

  • CVE-2020-37040HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field…

  • CVE-2020-37039HigJan 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Frigate 2.02 contains a denial of service vulnerability that allows attackers to crash the application by sending oversized input to the command line interface. Attackers can generate a payload of 8000 repeated characters and paste it into the application's command line field to…

  • CVE-2020-37038HigJan 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Code Blocks 20.03 contains a denial of service vulnerability that allows attackers to crash the application by manipulating input in the FSymbols search field. Attackers can paste a large payload of 5000 repeated characters into the search field to trigger an application crash.

  • CVE-2020-37036HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    RM Downloader 2.50.60 contains a local buffer overflow vulnerability in the 'Load' parameter that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious payload with an egg hunter technique to bypass memory protections and execute…

  • CVE-2020-37035HigJan 30, 2026
    risk 0.53cvss 8.2epss 0.00

    e-Learning PHP Script 0.1.0 contains a SQL injection vulnerability in the search functionality that allows attackers to manipulate database queries through unvalidated user input. Attackers can inject malicious SQL code in the 'search' parameter to potentially extract, modify,…

  • CVE-2020-37034HigJan 30, 2026
    risk 0.49cvss 7.5epss 0.00

    HelloWeb 2.0 contains an arbitrary file download vulnerability that allows remote attackers to download system files by manipulating filepath and filename parameters. Attackers can send crafted GET requests to download.asp with directory traversal to access sensitive…

  • CVE-2020-37033HigJan 30, 2026
    risk 0.53cvss 8.2epss 0.00

    Infor Storefront B2B 1.0 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'usr_name' parameter in login requests. Attackers can exploit the vulnerability by injecting malicious SQL code into the 'usr_name' parameter to…

  • CVE-2020-37031HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory through the 'File' input parameter. Attackers can craft a malicious payload with 268 bytes to trigger code execution, bypassing DEP…

  • CVE-2020-37029HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    FTPDummy 4.80 contains a local buffer overflow vulnerability in its preference file handling that allows attackers to execute arbitrary code. Attackers can craft a malicious preference file with carefully constructed shellcode to trigger a structured exception handler overwrite…

  • CVE-2020-37028HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Socusoft Photo to Video Converter Professional 8.07 contains a local buffer overflow vulnerability in the 'Output Folder' input field that allows attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the output folder field to trigger a…

  • CVE-2020-37025HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Port Forwarding Wizard 4.8.0 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code through a long request in the Register feature. Attackers can craft a malicious payload with an egg tag and overwrite SEH handlers to potentially execute…

  • CVE-2020-37024HigJan 30, 2026
    risk 0.55cvss 8.4epss 0.00

    Nidesoft DVD Ripper 5.2.18 contains a local buffer overflow vulnerability in the License Code registration parameter that allows attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the License Code field to trigger a stack-based buffer…

  • CVE-2020-37023HigJan 30, 2026
    risk 0.57cvss 8.8epss 0.00

    Koken CMS 0.22.24 contains a file upload vulnerability that allows authenticated attackers to bypass file extension restrictions by renaming malicious PHP files. Attackers can upload PHP files with system command execution capabilities by manipulating the file upload request…

  • CVE-2025-11175HigJan 30, 2026
    risk 0.57cvss epss 0.00

    Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in The Wikimedia Foundation Mediawiki - DiscussionTools Extension allows Regular Expression Exponential Blowup.This issue affects Mediawiki -…

  • CVE-2025-69662HigJan 30, 2026
    risk 0.49cvss 8.6epss 0.00

    SQL injection vulnerability in geopandas before v.1.1.2 allows an attacker to obtain sensitive information via the to_postgis()` function being used to write GeoDataFrames to a PostgreSQL database.

  • CVE-2025-62348HigJan 30, 2026
    risk 0.44cvss 7.8epss 0.00

    Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.

  • CVE-2026-1701HigJan 30, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in itsourcecode School Management System 1.0. This issue affects some unknown processing of the file /enrollment/index.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-1689HigJan 30, 2026
    risk 0.48cvss 7.3epss 0.05

    A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function checkUserFromLanOrWan of the file /boaform/admin/formLogin of the component Login Interface. The manipulation of the argument Host results in command injection.…

  • CVE-2020-37060HigJan 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe'…

  • CVE-2020-37059HigJan 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Popcorn Time 6.2.1.14 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can insert malicious executables in Program Files (x86) or system root directories to be executed…

  • CVE-2020-37058HigJan 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.

  • CVE-2020-37030HigJan 30, 2026
    risk 0.51cvss 7.8epss 0.00

    Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in C:\Program Files (x86)\Outline to inject malicious code that…

  • CVE-2026-1688HigJan 30, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in itsourcecode Directory Management System 1.0. The affected element is an unknown function of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The…

  • CVE-2026-1687HigJan 30, 2026
    risk 0.48cvss 7.3epss 0.06

    A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the file /boaform/formSamba of the component Boa Webserver. Executing a manipulation of the argument serverString can lead to command injection. It is possible to…

  • CVE-2025-4686HigJan 30, 2026
    risk 0.56cvss 8.6epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry and Trade Ltd. Co. Online Exam and Assessment allows SQL Injection.This issue affects Online Exam and Assessment:…

  • CVE-2024-4027HigJan 30, 2026
    risk 0.42cvss 7.5epss 0.00

    A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote…

  • CVE-2026-1498HigJan 30, 2026
    risk 0.46cvss epss 0.00

    An LDAP Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated attacker to retrieve sensitive information from a connected LDAP authentication server through an exposed authentication or management web interface. This vulnerability may also allow a…

  • CVE-2025-13176HigJan 30, 2026
    risk 0.55cvss epss 0.00

    Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.

  • CVE-2026-22623HigJan 30, 2026
    risk 0.47cvss 7.2epss 0.00

    Due to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary commands on the device by crafting specific messages.

  • CVE-2026-0709HigJan 30, 2026
    risk 0.47cvss 7.2epss 0.00

    Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary…

  • CVE-2025-1395HigJan 30, 2026
    risk 0.53cvss 8.2epss 0.00

    Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping.This issue affects HeyGarson: through 30012026. NOTE: The vendor was contacted several times to…

  • CVE-2026-24714HigJan 30, 2026
    risk 0.49cvss 7.5epss 0.00

    Some end of service NETGEAR products provide "TelnetEnable" functionality, which allows a magic packet to activate telnet service on the box.

  • CVE-2026-25117HigJan 29, 2026
    risk 0.54cvss epss 0.00

    pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit e33da14449a5abcff507e554f66e2141d6683b0a, missing sandboxing on `/workspace/*` routes allows challenge authors to inject arbitrary javascript which runs on the same origin as…

  • CVE-2026-24905HigJan 29, 2026
    risk 0.44cvss 7.8epss 0.00

    Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. The `ig` binary provides a subcommand for image building, used to generate custom gadget OCI images. A part of this functionality is…

  • CVE-2026-23896HigJan 29, 2026
    risk 0.47cvss 7.2epss 0.00

    immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, allowing a low-privilege API key to grant itself full administrative access to the system. Version…

  • CVE-2026-1595HigJan 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in itsourcecode Society Management System 1.0. This affects an unknown part of the file /admin/edit_student_query.php. The manipulation of the argument student_id results in sql injection. The attack can be executed remotely. The exploit is now…

  • CVE-2025-13905HigJan 29, 2026
    risk 0.46cvss epss 0.00

    CWE-276: Incorrect Default Permissions vulnerability exists that could cause privilege escalation through the reverse shell when one or more executable service binaries are modified in the installation folder by a local user with normal privilege upon service restart.

  • CVE-2026-1594HigJan 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in itsourcecode Society Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/add_expenses.php. The manipulation of the argument detail leads to sql injection. Remote exploitation of the attack…

  • CVE-2026-1593HigJan 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in itsourcecode Society Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/edit_expenses_query.php. Executing a manipulation of the argument detail can lead to sql injection. The attack may be…

  • CVE-2026-1590HigJan 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was identified in itsourcecode School Management System 1.0. This impacts an unknown function of the file /ramonsys/faculty/index.php. Such manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit is publicly…

  • CVE-2026-1589HigJan 29, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in itsourcecode School Management System 1.0. This affects an unknown function of the file /ramonsys/inquiry/index.php. This manipulation of the argument txtsearch causes sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2020-37021HigJan 29, 2026
    risk 0.51cvss 7.8epss 0.00

    10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during…