VYPR

CVEs

38,008 total · page 166 of 761

  • CVE-2026-25722CriFeb 6, 2026
    risk 0.59cvss 9.1epss 0.01

    Claude Code is an agentic coding tool. Prior to version 2.0.57, Claude Code failed to properly validate directory changes when combined with write operations to protected folders. By using the cd command to navigate into sensitive directories like .claude, it was possible to…

  • CVE-2025-64111CriFeb 6, 2026
    risk 0.57cvss 9.8epss 0.01

    Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update files in the .git directory and achieve remote command execution. This issue has been patched in versions 0.13.4 and…

  • CVE-2019-25298CriFeb 6, 2026
    risk 0.59cvss 9.1epss 0.00

    html5_snmp 1.11 contains multiple SQL injection vulnerabilities that allow attackers to manipulate database queries through Router_ID and Router_IP parameters. Attackers can exploit error-based, time-based, and union-based injection techniques to potentially extract or modify…

  • CVE-2026-2017CriFeb 6, 2026
    risk 0.64cvss 9.8epss 0.05

    A vulnerability was detected in IP-COM W30AP up to 1.0.0.11(1340). Affected by this issue is the function R7WebsSecurityHandler of the file /goform/wx3auth of the component POST Request Handler. The manipulation of the argument data results in stack-based buffer overflow. The…

  • CVE-2026-21643CriKEVFeb 6, 2026
    risk 0.83cvss 9.8epss 0.94

    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

  • CVE-2026-24300CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Azure Front Door Elevation of Privilege Vulnerability

  • CVE-2026-0106CriFeb 5, 2026
    risk 0.60cvss 9.3epss 0.00

    In vpu_mmap of vpu_ioctl, there is a possible arbitrary address mmap due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-68121CriFeb 5, 2026
    risk 0.58cvss 10.0epss 0.01

    During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between the initial handshake and the resumed handshake, the resumed handshake may succeed when it should have failed. This may happen when a user calls Config.Clone and…

  • CVE-2025-68723CriFeb 5, 2026
    risk 0.59cvss 9.0epss 0.00

    Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin interface. Three instances exist: (1) the log file name parameter in the Local Services Log page, (2) certificate file content in the SSL Certificates View Usage…

  • CVE-2020-37138CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.01

    10-Strike Network Inventory Explorer 9.03 contains a buffer overflow vulnerability in the file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious text file with carefully constructed payload to trigger a stack-based…

  • CVE-2020-37129CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Memu Play 7.1.3 contains an insecure folder permissions vulnerability that allows low-privileged users to modify the MemuService.exe executable. Attackers can replace the service executable with a malicious file during system restart to gain SYSTEM-level privileges by exploiting…

  • CVE-2020-37126CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attackers to overwrite Structured Exception Handler (SEH) registers. Attackers can exploit the vulnerability by crafting a malicious Unicode input that triggers an…

  • CVE-2020-37125CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.07

    Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands through the /goform/mp endpoint. Attackers can exploit the vulnerability by sending crafted POST requests with command injection…

  • CVE-2020-37124CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.00

    B64dec 1.1.2 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) with crafted input. Attackers can leverage an egg hunter technique and carefully constructed payload to inject and execute…

  • CVE-2020-37123CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.03

    Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the ping and socket parameters. Attackers can exploit the unsanitized input in ping.php to write arbitrary PHP files and execute system commands by appending shell…

  • CVE-2020-37120CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Rubo DICOM Viewer 2.0 contains a buffer overflow vulnerability in the DICOM server name input field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious text file with carefully constructed payload to execute arbitrary code by…

  • CVE-2020-37119CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.01

    Nsauditor 3.0.28 and 3.2.1.0 contains a buffer overflow vulnerability in the DNS Lookup tool that allows attackers to execute arbitrary code by overwriting memory. Attackers can craft a malicious DNS query payload to trigger a three-byte overwrite, bypass ASLR, and execute…

  • CVE-2026-23796CriFeb 5, 2026
    risk 0.64cvss 9.8epss 0.00

    Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. The vendor was…

  • CVE-2025-62616CriFeb 4, 2026
    risk 0.64cvss 9.8epss 0.00

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.34, in SendDiscordFileBlock, the third-party library aiohttp.ClientSession().get is used directly…

  • CVE-2025-62615CriFeb 4, 2026
    risk 0.64cvss 9.8epss 0.00

    AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that automate complex workflows. Prior to autogpt-platform-beta-v0.6.34, in RSSFeedBlock, the third-party library urllib.request.urlopen is used directly to access the…

  • CVE-2026-25547CriFeb 4, 2026
    risk 0.53cvss —epss 0.01

    @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated…

  • CVE-2026-25539CriFeb 4, 2026
    risk 0.52cvss 9.1epss 0.01

    SiYuan is a personal knowledge management system. Prior to version 3.5.5, the /api/file/copyFile endpoint does not validate the dest parameter, allowing authenticated users to write files to arbitrary locations on the filesystem. This can lead to Remote Code Execution (RCE) by…

  • CVE-2026-25526CriFeb 4, 2026
    risk 0.57cvss 9.8epss 0.01

    JinJava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Prior to versions 2.7.6 and 2.8.3, JinJava is vulnerable to arbitrary Java execution via bypass through ForTag. This allows arbitrary Java class instantiation and file…

  • CVE-2025-13375CriFeb 4, 2026
    risk 0.64cvss 9.8epss 0.01

    IBM Common Cryptographic Architecture (CCA) 7.5.52 and 8.4.82 could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system.

  • CVE-2026-25505CriFeb 4, 2026
    risk 0.57cvss 9.8epss 0.01

    Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.

  • CVE-2026-25481CriFeb 4, 2026
    risk 0.55cvss 9.6epss 0.01

    Langroid is a framework for building large-language-model-powered applications. Prior to version 0.59.32, there is a bypass to the fix for CVE-2025-46724. TableChatAgent can call pandas_eval tool to evaluate the expression. There is a WAF in langroid/utils/pandas_utils.py…

  • CVE-2026-25160CriFeb 4, 2026
    risk 0.52cvss 9.1epss 0.00

    Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle…

  • CVE-2026-25139CriFeb 4, 2026
    risk 0.59cvss 9.1epss 0.01

    RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) devices and other embedded devices. In version 2025.10 and prior, multiple out-of-bounds read allow any unauthenticated user, with ability to send or…

  • CVE-2025-64712CriFeb 4, 2026
    risk 0.57cvss 9.8epss 0.01

    The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, and many more. Prior to version 0.18.18, a path traversal vulnerability in the partition_msg function allows an attacker to write…

  • CVE-2026-25115CriFeb 4, 2026
    risk 0.57cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. This issue has been patched in…

  • CVE-2026-25053CriFeb 4, 2026
    risk 0.57cvss 9.9epss 0.01

    n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or read arbitrary files on the n8n host. This…

  • CVE-2026-25052CriFeb 4, 2026
    risk 0.57cvss 9.9epss 0.00

    n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host system. This can be exploited…

  • CVE-2026-25049CriFeb 4, 2026
    risk 0.57cvss 9.9epss 0.02

    n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running…

  • CVE-2025-5329CriFeb 4, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection. This issue affects Delta Course Automation: through 04022026. NOTE: The vendor was contacted early about…

  • CVE-2025-59818CriFeb 4, 2026
    risk 0.65cvss 10.0epss 0.01

    This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

  • CVE-2026-1633CriFeb 4, 2026
    risk 0.65cvss 10.0epss 0.01

    The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.

  • CVE-2026-1632CriFeb 3, 2026
    risk 0.59cvss 9.1epss 0.01

    MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.

  • CVE-2026-25510CriFeb 3, 2026
    risk 0.57cvss 9.9epss 0.01

    CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.28.5.0, an authenticated user with file editor permissions can achieve Remote Code Execution (RCE) by leveraging the…

  • CVE-2026-25150CriFeb 3, 2026
    risk 0.54cvss 9.3epss 0.01

    Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create…

  • CVE-2026-1341CriFeb 3, 2026
    risk 0.60cvss —epss 0.01

    Avation Light Engine Pro exposes its configuration and control interface without any authentication or access control.

  • CVE-2020-37090CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

  • CVE-2020-37082CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the…

  • CVE-2020-37080CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on…

  • CVE-2020-37075CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) overwrite and execute…

  • CVE-2020-37074CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and…

  • CVE-2020-37071CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the…

  • CVE-2020-37070CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    CloudMe 1.11.2 contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code through crafted network packets. Attackers can exploit the vulnerability by sending a specially crafted payload to the CloudMe service running on port 8888, enabling…

  • CVE-2020-37069CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

  • CVE-2020-37068CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.01

    Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.

  • CVE-2020-37067CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP…