VYPR

CVEs

38,008 total · page 168 of 761

  • CVE-2019-25232CriJan 30, 2026
    risk 0.64cvss 9.8epss 0.01

    NetPCLinker 1.0.0.0 contains a buffer overflow vulnerability in the Clients Control Panel DNS/IP field that allows attackers to execute arbitrary shellcode. Attackers can craft a malicious payload in the DNS/IP input to overwrite SEH handlers and execute shellcode when adding a…

  • CVE-2026-25141CriJan 30, 2026
    risk 0.57cvss 9.8epss 0.01

    Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape function properly handles single quotes ('),…

  • CVE-2026-25130CriJan 30, 2026
    risk 0.55cvss 9.6epss 0.01

    Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in its function tools. User-controlled input is passed directly to shell commands via…

  • CVE-2026-1723CriJan 30, 2026
    risk 0.60cvss —epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X6000R allows OS Command Injection.This issue affects X6000R: through V9.4.0cu.1498_B20250826.

  • CVE-2025-51958CriJan 30, 2026
    risk 0.64cvss 9.8epss 0.01

    aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/plugins/runcommand/postaction.php.

  • CVE-2025-7964CriJan 30, 2026
    risk 0.60cvss —epss 0.00

    After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigbee router resulting in the Zigbee Router getting stuck in a non-rejoinable state. If a suitable parent is not available, the end devices will be unable to…

  • CVE-2025-26385CriJan 30, 2026
    risk 0.62cvss —epss 0.01

    Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects  * Metasys:…

  • CVE-2026-1699CriJan 30, 2026
    risk 0.65cvss 10.0epss 0.01

    In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI…

  • CVE-2026-0963CriJan 30, 2026
    risk 0.64cvss 9.9epss 0.01

    An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.

  • CVE-2026-24729CriJan 30, 2026
    risk 0.65cvss —epss 0.00

    An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a malicious class file.

  • CVE-2026-24728CriJan 30, 2026
    risk 0.60cvss —epss 0.01

    A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality without prior authentication.

  • CVE-2026-1340CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.99

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2026-1281CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.99

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2026-22806CriJan 29, 2026
    risk 0.59cvss 9.1epss 0.00

    vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to versions 4.6.0, 4.5.4, 4.4.2, and 4.3.10, when an access key is created with a limited scope, the scope can be bypassed to access resources outside of it.…

  • CVE-2025-69929CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.00

    An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the password hashing on the client side using the MD5 algorithm over a predictable string format

  • CVE-2026-1453CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.01

    A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product.

  • CVE-2026-24054CriJan 29, 2026
    risk 0.00cvss 10.0epss 0.01

    Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 3.26.0, when a container image is malformed or contains no layers, containerd falls back to bind-mounting an…

  • CVE-2020-37012CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.01

    Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary shell commands through the /api.php endpoint. Attackers can craft a malicious LaTeX payload with shell commands that are executed when processed by the…

  • CVE-2020-37010CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.00

    BearShare Lite 5.2.5 contains a buffer overflow vulnerability in the Advanced Search keywords input that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite the EIP register and execute shellcode by pasting malicious content…

  • CVE-2020-37002CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.01

    Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execute arbitrary commands after successful login. Attackers can leverage the /api/terminal/create endpoint to send a netcat reverse shell payload targeting a…

  • CVE-2020-37000CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.01

    Free MP3 CD Ripper 2.8 contains a stack buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting a malicious WAV file with oversized payload. Attackers can leverage a specially crafted exploit file with shellcode, SEH bypass, and egghunter…

  • CVE-2020-36997CriJan 29, 2026
    risk 0.64cvss 9.8epss 0.00

    BacklinkSpeed 2.4 contains a buffer overflow vulnerability that allows attackers to corrupt the Structured Exception Handler (SEH) chain through malicious file import. Attackers can craft a specially designed payload file to overwrite SEH addresses, potentially executing…

  • CVE-2026-1188CriJan 29, 2026
    risk 0.00cvss 9.8epss 0.00

    In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly…

  • CVE-2026-24897CriJan 28, 2026
    risk 0.03cvss 10.0epss 0.03

    Erugo is a self-hosted file-sharing platform. In versions up to and including 0.2.14, an authenticated low-privileged user can upload arbitrary files to any specified location due to insufficient validation of user‑supplied paths when creating shares. By specifying a writable…

  • CVE-2026-24857CriJan 28, 2026
    risk 0.64cvss 9.8epss 0.00

    `bulk_extractor` is a digital forensics exploitation tool. Starting in version 1.4, `bulk_extractor`’s embedded unrar code has a heap‑buffer‑overflow in the RAR PPM LZ decoding path. A crafted RAR inside a disk image causes an out‑of‑bounds write in…

  • CVE-2026-24769CriJan 28, 2026
    risk 0.52cvss 9.0epss 0.00

    NocoDB is software for building databases as spreadsheets. Prior to version 0.301.0, a stored cross-site scripting (XSS) vulnerability exists in NocoDB’s attachment handling mechanism. Authenticated users can upload malicious SVG files containing embedded JavaScript, which are…

  • CVE-2025-69602CriJan 28, 2026
    risk 0.59cvss 9.1epss 0.00

    A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate the session identifier after successful authentication. As a result, the same session cookie value is reused for users logging in from the same browser, allowing…

  • CVE-2025-57795CriJan 28, 2026
    risk 0.64cvss 9.9epss 0.01

    Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service component. In default configurations, this flaw can be leveraged to achieve remote code execution.

  • CVE-2025-57794CriJan 28, 2026
    risk 0.59cvss 9.1epss 0.01

    Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administrative interface. The application does not adequately restrict uploaded file types, allowing malicious files to be uploaded and executed by the server. This…

  • CVE-2025-57792CriJan 28, 2026
    risk 0.65cvss 10.0epss 0.00

    Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user input in a web application endpoint. An attacker can supply crafted input that is executed as part of backend database queries. The issue is exploitable…

  • CVE-2020-36967CriJan 28, 2026
    risk 0.64cvss 9.8epss 0.01

    Zortam Mp3 Media Studio 27.60 contains a buffer overflow vulnerability in the library creation file selection process that allows remote code execution. Attackers can craft a malicious text file with shellcode to trigger a structured exception handler (SEH) overwrite and execute…

  • CVE-2020-36964CriJan 28, 2026
    risk 0.64cvss 9.8epss 0.00

    YATinyWinFTP contains a denial of service vulnerability that allows attackers to crash the FTP service by sending a 272-byte buffer with a trailing space. Attackers can exploit the service by connecting and sending a malformed command that triggers a buffer overflow and service…

  • CVE-2020-36962CriJan 28, 2026
    risk 0.58cvss 9.8epss 0.12

    Tendenci 12.3.1 contains a CSV formula injection vulnerability in the contact form message field that allows attackers to inject malicious formulas during export. Attackers can submit crafted payloads like '=10+20+cmd|' /C calc'!A0' in the message field to trigger arbitrary…

  • CVE-2020-36961CriJan 28, 2026
    risk 0.64cvss 9.8epss 0.01

    10-Strike Network Inventory Explorer 8.65 contains a buffer overflow vulnerability in exception handling that allows remote attackers to execute arbitrary code. Attackers can craft a malicious file with 209 bytes of padding and a specially constructed Structured Exception…

  • CVE-2025-61140CriJan 28, 2026
    risk 0.57cvss 9.8epss 0.01

    The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.

  • CVE-2026-1056CriJan 28, 2026
    risk 0.58cvss 9.8epss 0.13

    The Snow Monkey Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'generate_user_dirpath' function in all versions up to, and including, 12.0.3. This makes it possible for unauthenticated attackers to delete…

  • CVE-2025-40554CriJan 28, 2026
    risk 0.68cvss 9.8epss 0.61

    SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could allow an attacker to invoke specific actions within Web Help Desk.

  • CVE-2025-40553CriJan 28, 2026
    risk 0.69cvss 9.8epss 0.68

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

  • CVE-2025-40552CriJan 28, 2026
    risk 0.68cvss 9.8epss 0.52

    SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would allow a malicious actor to execute actions and methods that should be protected by authentication.

  • CVE-2025-40551CriKEVJan 28, 2026
    risk 0.85cvss 9.8epss 0.84

    SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead to remote code execution, which would allow an attacker to run commands on the host machine. This could be exploited without authentication.

  • CVE-2026-24841CriJan 28, 2026
    risk 0.00cvss 9.9epss 0.03

    Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection vulnerability exists in Dokploy's WebSocket endpoint `/docker-container-terminal`. The `containerId` and `activeWay` parameters are directly interpolated into…

  • CVE-2026-24838CriJan 28, 2026
    risk 0.52cvss 9.1epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to versions 9.13.10 and 10.2.0, module title supports richtext which could include scripts that would execute in certain scenarios. Versions 9.13.10 and 10.2.0…

  • CVE-2026-24785CriJan 28, 2026
    risk 0.52cvss 9.1epss 0.00

    Clatter is a no_std compatible, pure Rust implementation of the Noise protocol framework with post-quantum support. Versiosn prior to2.2.0 have a protocol compliance vulnerability. The library allowed post-quantum handshake patterns that violated the PSK validity rule (Noise…

  • CVE-2026-23830CriJan 28, 2026
    risk 0.58cvss 10.0epss 0.01

    SandboxJS is a JavaScript sandboxing library. Versions prior to 0.8.26 have a sandbox escape vulnerability due to `AsyncFunction` not being isolated in `SandboxFunction`. The library attempts to sandbox code execution by replacing the global `Function` constructor with a safe,…

  • CVE-2026-24770CriJan 27, 2026
    risk 0.00cvss 9.8epss 0.01

    RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a "Zip Slip" vulnerability, allowing an attacker to overwrite arbitrary files on the server (leading to Remote Code Execution) via a…

  • CVE-2026-24740CriJan 27, 2026
    risk 0.57cvss 9.9epss 0.00

    Dozzle is a realtime log viewer for docker containers. Prior to version 9.0.3, a flaw in Dozzle’s agent-backed shell endpoints allows a user restricted by label filters (for example, `label=env=dev`) to obtain an interactive root shell in out‑of‑scope containers (for…

  • CVE-2026-24736CriJan 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Squidex is an open source headless content management system and content management hub. Versions of the application up to and including 7.21.0 allow users to define "Webhooks" as actions within the Rules engine. The url parameter in the webhook configuration does not appear to…

  • CVE-2025-21589CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.02

    An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may allows a network-based attacker to bypass authentication and take administrative control of the device. This issue affects Session Smart Router:  * from…

  • CVE-2026-24858CriKEVJan 27, 2026
    risk 0.83cvss 9.8epss 0.86

    An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through…

  • CVE-2025-14988CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.