VYPR

CVEs

38,009 total · page 169 of 761

  • CVE-2025-14988CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.

  • CVE-2026-22039CriJan 27, 2026
    risk 0.57cvss 9.9epss 0.01

    Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have a critical authorization boundary bypass in namespaced Kyverno Policy apiCall. The resolved `urlPath` is executed using the Kyverno admission controller…

  • CVE-2025-69564CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters.

  • CVE-2025-69563CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.

  • CVE-2025-69562CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter.

  • CVE-2025-69559CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.

  • CVE-2026-24874CriJan 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in themrdemonized xray-monolith.This issue affects xray-monolith: before 2025.12.30.

  • CVE-2026-24872CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.00

    improper pointer arithmetic vulnerability in ProjectSkyfire SkyFire_548.This issue affects SkyFire_548: before 5.4.8-stable5.

  • CVE-2026-24871CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in pilgrimage233 Minecraft-Rcon-Manage.This issue affects Minecraft-Rcon-Manage: before 3.0.

  • CVE-2026-24832CriJan 27, 2026
    risk 0.00cvss 9.8epss 0.00

    Out-of-bounds Write vulnerability in ixray-team ixray-1.6-stcop.This issue affects ixray-1.6-stcop: before 1.3.

  • CVE-2025-69565CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.00

    code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.

  • CVE-2025-68670CriJan 27, 2026
    risk 0.00cvss 9.1epss 0.01

    xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability…

  • CVE-2021-47901CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Dirsearch 0.4.1 contains a CSV injection vulnerability when using the --csv-report flag that allows attackers to inject formulas through redirected endpoints. Attackers can craft malicious server redirects with comma-separated paths containing Excel formulas to manipulate the…

  • CVE-2021-47900CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Gila CMS versions prior to 2.0.0 contain a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through manipulated HTTP headers. Attackers can inject PHP code in the User-Agent header with shell_exec() to run system…

  • CVE-2020-36948CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    VestaCP 0.9.8-26 contains a session token vulnerability in the LoginAs module that allows remote attackers to manipulate authentication tokens. Attackers can exploit insufficient token validation to access user accounts and perform unauthorized login requests without proper…

  • CVE-2020-36941CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    Knockpy 4.1.1 contains a CSV injection vulnerability that allows attackers to inject malicious formulas into CSV reports through unfiltered server headers. Attackers can manipulate server response headers to include spreadsheet formulas that will execute when the CSV is opened…

  • CVE-2020-36940CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Easy CD & DVD Cover Creator 4.13 contains a buffer overflow vulnerability in the serial number input field that allows attackers to crash the application. Attackers can generate a 6000-byte payload and paste it into the serial number field to trigger an application crash.

  • CVE-2026-1470CriJan 27, 2026
    risk 0.59cvss 9.9epss 0.21

    n8n contains a critical Remote Code Execution (RCE) vulnerability in its workflow Expression evaluation system. Expressions supplied by authenticated users during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the…

  • CVE-2026-24830CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.00

    Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.

  • CVE-2026-24826CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Out-of-bounds Write, Divide By Zero, NULL Pointer Dereference, Use of Uninitialized Resource, Out-of-bounds Read, Reachable Assertion vulnerability in cadaver turso3d.This issue affects .

  • CVE-2026-24346CriJan 27, 2026
    risk 0.59cvss 9.1epss 0.00

    Use of well-known default credentials in Admin UI of EZCast Pro II version 1.17478.146 allows attackers to access protected areas in the web application

  • CVE-2026-24823CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in FASTSHIFT X-TRACK (Software/X-Track/USER/App/Utils/lv_img_png/PNGdec/src modules). This vulnerability is associated with program files inflate.C. This issue affects…

  • CVE-2026-24822CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Out-of-bounds Write, Heap-based Buffer Overflow vulnerability in ttttupup wxhelper (src modules). This vulnerability is associated with program files mongoose.C. This issue affects wxhelper: through 3.9.10.19-v1.

  • CVE-2026-24821CriJan 27, 2026
    risk 0.60cvss —epss 0.00

    Out-of-bounds Read vulnerability in turanszkij WickedEngine (WickedEngine/LUA modules). This vulnerability is associated with program files lparser.C. This issue affects WickedEngine: through 0.71.727.

  • CVE-2026-24816CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in datavane tis (tis-console/src/main/java/com/qlangtech/tis/runtime/module/action modules). This vulnerability is associated with program files ChangeDomainAction.Java. This issue affects tis: before v4.3.0.

  • CVE-2026-24815CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before…

  • CVE-2026-24814CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Integer Overflow or Wraparound vulnerability in swoole swoole-src (thirdparty/hiredis modules). This vulnerability is associated with program files sds.C. This issue affects swoole-src: before 6.0.2.

  • CVE-2026-24812CriJan 27, 2026
    risk 0.60cvss —epss 0.00

    Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root: through 6.36.00-rc1.

  • CVE-2026-24811CriJan 27, 2026
    risk 0.00cvss 9.8epss 0.00

    Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C. This issue affects root.

  • CVE-2026-24810CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb (src/cjson modules). This vulnerability is associated with program files cJSON.Cc. This issue affects rethinkdb: through v2.4.4.

  • CVE-2026-24804CriJan 27, 2026
    risk 0.60cvss —epss 0.00

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7603e/src/mt7603_wifi/common modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.

  • CVE-2026-24803CriJan 27, 2026
    risk 0.60cvss —epss 0.00

    Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7615d/src/mt_wifi/embedded/security modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.

  • CVE-2026-24800CriJan 27, 2026
    risk 0.65cvss —epss 0.00

    Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules). This vulnerability is associated with program files inflate.C.

  • CVE-2026-24798CriJan 27, 2026
    risk 0.60cvss —epss 0.00

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GaijinEntertainment DagorEngine (prog/3rdPartyLibs/miniupnpc modules). This vulnerability is associated with program files upnpreplyparse.C. This issue affects DagorEngine: through…

  • CVE-2026-24794CriJan 27, 2026
    risk 0.60cvss —epss 0.00

    Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in CardboardPowered cardboard (src/main/java/org/cardboardpowered/impl/world modules). This vulnerability is associated with program files WorldImpl.Java. This issue affects cardboard: before…

  • CVE-2026-24793CriJan 27, 2026
    risk 0.00cvss 9.8epss 0.00

    Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in azerothcore azerothcore-wotlk (deps/zlib modules). This vulnerability is associated with program files inflate.C. This issue affects azerothcore-wotlk: through v4.0.0.

  • CVE-2026-24479CriJan 27, 2026
    risk 0.04cvss 9.8epss 0.08

    HUSTOF is an open source online judge based on PHP/C++/MySQL/Linux for ACM/ICPC and NOIP training. Prior to version 26.01.24, the problem_import_qduoj.php and problem_import_hoj.php modules fail to properly sanitize filenames within uploaded ZIP archives. Attackers can craft a…

  • CVE-2026-24400CriJan 26, 2026
    risk 0.52cvss 9.1epss 0.01

    AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.xml.XmlStringPrettyFormatter`: the `toXmlDocument(String)`…

  • CVE-2026-22709CriJan 26, 2026
    risk 0.57cvss 9.8epss 0.01

    vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitization can be bypassed. This allows attackers to escape the sandbox and run arbitrary code. In lib/setup-sandbox.js, the callback…

  • CVE-2026-22696CriJan 26, 2026
    risk 0.53cvss —epss 0.00

    dcap-qvl implements the quote verification logic for DCAP (Data Center Attestation Primitives). A vulnerability present in versions prior to 0.3.9 involves a critical gap in the cryptographic verification process within the dcap-qvl. The library fetches QE Identity collateral…

  • CVE-2026-24436CriJan 26, 2026
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) do not enforce rate limiting or account lockout mechanisms on authentication endpoints. This allows attackers to perform unrestricted brute-force attempts against administrative credentials.

  • CVE-2026-24429CriJan 26, 2026
    risk 0.64cvss 9.8epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) ship with a predefined default password for a built-in authentication account that is not required to be changed during initial configuration. An attacker can leverage these default credentials to…

  • CVE-2025-70982CriJan 26, 2026
    risk 0.64cvss 9.9epss 0.00

    Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to arbitrarily import sensitive user data.

  • CVE-2016-15057CriJan 26, 2026
    risk 0.68cvss 9.9epss 0.04

    ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke…

  • CVE-2025-59108CriJan 26, 2026
    risk 0.60cvss —epss 0.00

    By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the password was not enforced.

  • CVE-2025-59103CriJan 26, 2026
    risk 0.60cvss —epss 0.00

    The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revisions. In this new hardware revision it was noticed that an SSH service is exposed on port 22. By analyzing the firmware of the devices, it was noticed that…

  • CVE-2025-59097CriJan 26, 2026
    risk 0.60cvss —epss 0.01

    The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done in a graphical user interface on the dormakaba exos server. As soon as the save button is clicked in exos 9300, the whole configuration is sent to the…

  • CVE-2025-59091CriJan 26, 2026
    risk 0.61cvss —epss 0.01

    Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server running on port 1004 and 1005. This server is used for relaying status information from and to the Access Managers. This information, among other things, is used…

  • CVE-2025-59090CriJan 26, 2026
    risk 0.61cvss —epss 0.01

    On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sending requests. Therefore, network access to the exos server allows e.g. the creation of arbitrary access log events as well as querying the 2FA PINs associated…

  • CVE-2025-13374CriJan 24, 2026
    risk 0.64cvss 9.8epss 0.01

    The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the kalrav_upload_file AJAX action in all versions up to, and including, 2.3.3. This makes it possible for unauthenticated attackers to upload arbitrary files…