VYPR

CVEs

31,436 total · page 153 of 629

  • CVE-2026-27940HigMar 12, 2026
    risk 0.44cvss 7.8epss 0.00

    llama.cpp is an inference of several LLM models in C/C++. Prior to b8146, the gguf_init_from_file_impl() in gguf.cpp is vulnerable to an Integer overflow, leading to an undersized heap allocation. Using the subsequent fread() writes 528+ bytes of attacker-controlled data past…

  • CVE-2026-21672HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.

  • CVE-2026-4043HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A security vulnerability has been detected in Tenda i12 1.0.0.6(2204). The impacted element is the function formwrlSSIDget of the file /goform/wifiSSIDget. Such manipulation of the argument index leads to stack-based buffer overflow. The attack may be launched remotely. The…

  • CVE-2019-25537HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Netartmedia Event Portal 2.0 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with malicious SQL…

  • CVE-2019-25536HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL…

  • CVE-2019-25535HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Netartmedia PHP Dating Site contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with time-based SQL injection payloads…

  • CVE-2019-25534HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Netartmedia PHP Car Dealer contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can submit POST requests to index.php with crafted SQL payloads in…

  • CVE-2019-25533HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Netartmedia PHP Business Directory 4.2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to the loginaction.php endpoint with crafted…

  • CVE-2019-25532HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Netartmedia Jobs Portal 6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the Email parameter. Attackers can send POST requests to loginaction.php with crafted SQL payloads in the Email…

  • CVE-2019-25531HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Netartmedia Deals Portal contains an SQL injection vulnerability in the Email parameter of loginaction.php that allows unauthenticated attackers to manipulate database queries. Attackers can submit crafted SQL payloads through POST requests to extract sensitive information or…

  • CVE-2019-25530HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    uHotelBooking System contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the system_page GET parameter. Attackers can send crafted requests to index.php with malicious system_page values using…

  • CVE-2019-25529HigMar 12, 2026
    risk 0.46cvss 7.1epss 0.00

    Placeto CMS Alpha rv.4 contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'page' parameter. Attackers can send GET requests to the admin/edit.php endpoint with malicious 'page' values using…

  • CVE-2019-25509HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    XooDigital Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Attackers can send GET requests to results.php with malicious 'p' values to extract sensitive database…

  • CVE-2019-25481HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    iScripts ReserveLogic contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the jqSearchDestination parameter. Attackers can send POST requests to the search endpoint with crafted SQL payloads…

  • CVE-2019-25479HigMar 12, 2026
    risk 0.53cvss 8.2epss 0.00

    Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in…

  • CVE-2019-25473HigMar 12, 2026
    risk 0.46cvss 7.1epss 0.00

    Clinic Pro contains a SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the month parameter. Attackers can send POST requests to the monthly_expense_overview endpoint with crafted month values using…

  • CVE-2026-4042HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A weakness has been identified in Tenda i12 1.0.0.6(2204). The affected element is the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet. This manipulation of the argument index causes stack-based buffer overflow. The attack may be initiated remotely. The…

  • CVE-2026-4041HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A security flaw has been discovered in Tenda i12 1.0.0.6(2204). Impacted is the function vos_strcpy of the file /goform/exeCommand. The manipulation of the argument cmdinput results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been…

  • CVE-2026-21670HigMar 12, 2026
    risk 0.50cvss 7.7epss 0.00

    A vulnerability allowing a low-privileged user to extract saved SSH credentials.

  • CVE-2026-21668HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability allowing an authenticated domain user to bypass restrictions and manipulate arbitrary files on a Backup Repository.

  • CVE-2026-3989HigMar 12, 2026
    risk 0.44cvss 7.8epss 0.00

    SGLangs `replay_request_dump.py` contains an insecure pickle.load() without validation and proper deserialization. An attacker can take advantage of this by providing a malicious .pkl file, which will execute the attackers code on the device running the script.

  • CVE-2026-4014HigMar 12, 2026
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in itsourcecode Cafe Reservation System 1.0. This impacts an unknown function of the file /curvus2/signup.php of the component Registration. Performing a manipulation of the argument Username results in sql injection. Remote exploitation of…

  • CVE-2026-4008HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw has been found in Tenda W3 1.0.0.3(2204). This issue affects some unknown processing of the file /goform/wifiSSIDset of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is possible to…

  • CVE-2026-4007HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was detected in Tenda W3 1.0.0.3(2204). This vulnerability affects unknown code of the file /goform/wifiSSIDget of the component POST Parameter Handler. Performing a manipulation of the argument index results in stack-based buffer overflow. It is possible to…

  • CVE-2026-3981HigMar 12, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit…

  • CVE-2026-3980HigMar 12, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_action.php. Such manipulation of the argument patient_id leads to sql injection. The attack may be launched remotely. The exploit has…

  • CVE-2026-3976HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A weakness has been identified in Tenda W3 1.0.0.3(2204). Impacted is the function formWifiMacFilterSet of the file /goform/WifiMacFilterSet of the component POST Parameter Handler. Executing a manipulation of the argument index/GO can lead to stack-based buffer overflow. It is…

  • CVE-2026-3975HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A security flaw has been discovered in Tenda W3 1.0.0.3(2204). This issue affects the function formWifiMacFilterGet of the file /goform/WifiMacFilterGet of the component POST Parameter Handler. Performing a manipulation of the argument wl_radio results in stack-based buffer…

  • CVE-2026-3974HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was identified in Tenda W3 1.0.0.3(2204). This vulnerability affects the function formexeCommand of the file /goform/exeCommand of the component HTTP Handler. Such manipulation of the argument cmdinput leads to stack-based buffer overflow. The attack may be…

  • CVE-2026-3657HigMar 12, 2026
    risk 0.49cvss 7.5epss 0.00

    The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action in all versions up to, and including, 2.8.6. This is due to the handler using attacker-controlled POST parameter names directly as SQL column identifiers in…

  • CVE-2026-3973HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was determined in Tenda W3 1.0.0.3(2204). This affects the function formSetAutoPing of the file /goform/setAutoPing of the component POST Parameter Handler. This manipulation of the argument ping1/ping2 causes stack-based buffer overflow. The attack is possible…

  • CVE-2026-3972HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability was found in Tenda W3 1.0.0.3(2204). Affected by this issue is the function formSetCfm of the file /goform/setcfm of the component HTTP Handler. The manipulation of the argument funcpara1 results in stack-based buffer overflow. The attack can only be performed…

  • CVE-2026-3971HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A vulnerability has been found in Tenda i3 1.0.0.6(2204). Affected by this vulnerability is the function formwrlSSIDset of the file /goform/wifiSSIDset. The manipulation of the argument index/GO leads to stack-based buffer overflow. Remote exploitation of the attack is possible.…

  • CVE-2026-3970HigMar 12, 2026
    risk 0.57cvss 8.8epss 0.00

    A flaw has been found in Tenda i3 1.0.0.6(2204). Affected is the function formwrlSSIDget of the file /goform/wifiSSIDget. Executing a manipulation of the argument index can lead to stack-based buffer overflow. The attack may be launched remotely. The exploit has been published…

  • CVE-2026-3969HigMar 12, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in FeMiner wms up to 1.0. This impacts an unknown function of the file /wms-master/src/basic/depart/depart_add_bg.php of the component Basic Organizational Structure Module. Performing a manipulation of the argument Name results in sql injection. The…

  • CVE-2026-31958HigMar 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsing occurs synchronously on the main thread, this…

  • CVE-2019-25486HigMar 11, 2026
    risk 0.53cvss 8.2epss 0.00

    Varient 1.6.1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_id parameter. Attackers can submit POST requests with crafted SQL payloads in the user_id field to bypass…

  • CVE-2019-25483HigMar 11, 2026
    risk 0.55cvss 8.4epss 0.00

    Comtrend AR-5310 GE31-412SSG-C01_R10.A2pG039u.d24k contains a restricted shell escape vulnerability that allows local users to bypass command restrictions by using the command substitution operator $( ). Attackers can inject arbitrary commands through the $( ) syntax when passed…

  • CVE-2019-25480HigMar 11, 2026
    risk 0.49cvss 7.5epss 0.00

    ARMBot contains an unrestricted file upload vulnerability in upload.php that allows unauthenticated attackers to upload arbitrary files by manipulating the file parameter with path traversal sequences. Attackers can upload PHP files with traversal payloads ../public_html/ to…

  • CVE-2019-25478HigMar 11, 2026
    risk 0.49cvss 7.5epss 0.00

    GetGo Download Manager 6.2.2.3300 contains a buffer overflow vulnerability that allows remote attackers to cause denial of service by sending HTTP responses with excessively long headers. Attackers can craft malicious HTTP responses with oversized header values to crash the…

  • CVE-2019-25470HigMar 11, 2026
    risk 0.49cvss 7.5epss 0.00

    eWON Firmware versions 12.2 to 13.0 contain an authentication bypass vulnerability that allows attackers with minimal privileges to retrieve sensitive user data by exploiting the wsdReadForm endpoint. Attackers can send POST requests to /wrcgi.bin/wsdReadForm with base64-encoded…

  • CVE-2019-25467HigMar 11, 2026
    risk 0.55cvss 8.4epss 0.00

    Verypdf docPrint Pro 8.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized alphanumeric encoded payload in the User Password or Master Password fields. Attackers can craft a…

  • CVE-2019-25466HigMar 11, 2026
    risk 0.55cvss 8.4epss 0.00

    Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding…

  • CVE-2019-25465HigMar 11, 2026
    risk 0.49cvss 7.5epss 0.00

    Hisilicon HiIpcam V100R003 contains a directory traversal vulnerability that allows unauthenticated attackers to access sensitive configuration files by exploiting directory listing in the cgi-bin directory. Attackers can request the getadslattr.cgi endpoint to retrieve ADSL…

  • CVE-2026-1497HigMar 11, 2026
    risk 0.47cvss 7.2epss 0.00

    Incorrect resolving of namespaces in composite databases in Neo4j Enterprise edition prior to versions 2026.02 and 5.26.22 can lead to the following scenario:  an admin that intends to give a user an access to a remote database constituent "namespace.name" will inadvertently…

  • CVE-2025-12690HigMar 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, through 7.1.10.

  • CVE-2026-3013HigMar 11, 2026
    risk 0.57cvss epss 0.01

    Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue…

  • CVE-2026-30902HigMar 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Privilege Management in certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2026-30901HigMar 11, 2026
    risk 0.46cvss 7.0epss 0.00

    Improper Input Validation in Zoom Rooms for Windows before 6.6.5 in Kiosk Mode may allow an authenticated user to conduct an escalation of privilege via local access.

  • CVE-2026-30900HigMar 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Check of minimum version in update functionality of certain Zoom Clients for Windows may allow an authenticated user to conduct an escalation of privilege via local access.