VYPR

CVEs

38,009 total · page 175 of 761

  • CVE-2025-29329CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.01

    Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote attacker to execute arbitrary code by sending a crafted HTTP request.

  • CVE-2025-12420CriJan 12, 2026
    risk 0.67cvss 9.8epss 0.53

    A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the impersonated user is entitled to perform. ServiceNow has addressed this vulnerability by deploying a…

  • CVE-2025-67147CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', and 'comment' parameters in (1) submit_contact.php, the 'username' and 'pass_key' parameters in (2) secure_login.php, and the 'login_id', 'pwfield', and…

  • CVE-2025-66802CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receives a reverse shell (php) into imagem of the user enabling RCE.

  • CVE-2025-51567CriJan 12, 2026
    risk 0.59cvss 9.1epss 0.00

    A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP…

  • CVE-2026-22785CriJan 12, 2026
    risk 0.57cvss 9.8epss 0.01

    orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation logic relies on string manipulation that incorporates the summary field from the OpenAPI specification without proper validation or…

  • CVE-2026-22783CriJan 12, 2026
    risk 0.00cvss 9.6epss 0.00

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior to 2.4.24, the DFIR-IRIS datastore file management system has a vulnerability where mass assignment of the file_local_name field combined with path trust in…

  • CVE-2026-22781CriJan 12, 2026
    risk 0.00cvss 9.8epss 0.02

    TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line arguments to the CGI executable via Windows…

  • CVE-2026-22252CriJan 12, 2026
    risk 0.00cvss 9.1epss 0.04

    LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This…

  • CVE-2025-63314CriJan 12, 2026
    risk 0.65cvss 10.0epss 0.00

    A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to arbitrarily reset the user password and execute a full account takeover via a replay attack.

  • CVE-2025-46070CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component

  • CVE-2025-46066CriJan 12, 2026
    risk 0.64cvss 9.9epss 0.00

    An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges

  • CVE-2025-65552CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication channel. The system does not implement rolling codes, message authentication, or anti-replay protection, allowing an attacker within RF range to record valid…

  • CVE-2025-41006CriJan 12, 2026
    risk 0.60cvss —epss 0.00

    Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.

  • CVE-2025-69270CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.00

    Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows Session Hijacking.This issue affects DX NetOps Spectrum: 24.3.8 and earlier.

  • CVE-2025-69269CriJan 12, 2026
    risk 0.64cvss 9.8epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier.

  • CVE-2025-52694CriJan 12, 2026
    risk 0.68cvss 10.0epss 0.40

    Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arbitrary SQL commands on the vulnerable service when it is exposed to the Internet, potentially affecting data confidentiality, integrity, and availability.…

  • CVE-2026-22688CriJan 10, 2026
    risk 0.58cvss 9.9epss 0.02

    WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_config.command/args into MCP stdio settings, causing the server…

  • CVE-2025-65091CriJan 10, 2026
    risk 0.58cvss 10.0epss 0.00

    XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right to view the Calendar.JSONService page (including guest users) can exploit a SQL injection vulnerability by accessing database info or starting a DoS attack.…

  • CVE-2025-61686CriJan 10, 2026
    risk 0.53cvss 9.1epss 0.17

    React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version 2.17.2, and @remix-run/node prior to version 2.17.2, if createFileSessionStorage() is being used from @react-router/node (or @remix-run/node/@remix-run/deno…

  • CVE-2026-22600CriJan 10, 2026
    risk 0.59cvss 9.1epss 0.00

    OpenProject is an open-source, web-based project management software. A Local File Read (LFR) vulnerability exists in the work package PDF export functionality of OpenProject prior to version 16.6.4. By uploading a specially crafted SVG file (disguised as a PNG) as a work…

  • CVE-2025-15501CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.07

    A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote…

  • CVE-2026-22584CriJan 9, 2026
    risk 0.57cvss 9.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Salesforce Uni2TS on MacOS, Windows, Linux allows Leverage Executable Code in Non-Executable Files.This issue affects Uni2TS: through 1.2.0.

  • CVE-2025-15500CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.06

    A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Handler. The manipulation of the argument sessionPath results…

  • CVE-2025-70161CriJan 9, 2026
    risk 0.66cvss 9.8epss 0.27

    EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit this by injecting malicious commands into the pppUserName…

  • CVE-2025-69542CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.10

    A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly concatenated into a system command without proper…

  • CVE-2025-69426CriJan 9, 2026
    risk 0.65cvss —epss 0.00

    The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables…

  • CVE-2025-69425CriJan 9, 2026
    risk 0.65cvss —epss 0.01

    The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static…

  • CVE-2020-36875CriJan 9, 2026
    risk 0.61cvss —epss 0.01

    AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of…

  • CVE-2025-14598CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.01

    BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites. The vulnerability enables arbitrary SQL commands to be executed on the backend database.

  • CVE-2025-7072CriJan 9, 2026
    risk 0.60cvss —epss 0.01

    The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all routers of this model) that an unauthenticated remote attacker could use to execute commands with root privileges. This vulnerability has been fixed in firmware…

  • CVE-2025-66050CriJan 9, 2026
    risk 0.64cvss 9.8epss 0.00

    Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as an administrator. While it is possible to set up such a password, a user is not informed about such a need. The vendor has not replied to the CNA. Possibly all…

  • CVE-2025-64093CriJan 9, 2026
    risk 0.65cvss 10.0epss 0.01

    Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device.

  • CVE-2025-64090CriJan 9, 2026
    risk 0.65cvss 10.0epss 0.00

    This vulnerability allows authenticated attackers to execute commands via the hostname of the device.

  • CVE-2025-14741CriJan 9, 2026
    risk 0.59cvss 9.1epss 0.00

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modification and deletion due to a missing capability check on the 'delete_object' function in all versions up to, and including, 3.28.25. This makes it possible for…

  • CVE-2025-70974CriJan 9, 2026
    risk 0.58cvss 10.0epss 0.01

    Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection…

  • CVE-2025-14736CriJan 9, 2026
    risk 0.57cvss 9.8epss 0.01

    The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_update_value', and 'get_fields_display'…

  • CVE-2025-68717CriJan 8, 2026
    risk 0.61cvss 9.4epss 0.01

    KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is logged in, endpoints such as /cgi-bin/system-tool accept unauthenticated requests with empty or invalid session values. This design flaw lets attackers…

  • CVE-2025-68715CriJan 8, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/goform/setWan, /goform/setLan, /goform/wirelessBasic) that do not enforce authentication. A remote unauthenticated attacker can modify WAN, LAN, and wireless…

  • CVE-2025-66916CriJan 8, 2026
    risk 0.61cvss 9.4epss 0.01

    The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpress expressions, but it does not filter user input, allowing attackers to use the File class to perform arbitrary file reading and writing.

  • CVE-2025-66913CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.01

    JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The application passes the attacker-supplied JDBC URL directly to the H2 driver, allowing the use of certain directives to execute arbitrary Java code. A different…

  • CVE-2025-67325CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

  • CVE-2026-22234CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.00

    OPEXUS eCasePortal before version 9.0.45.0 allows an unauthenticated attacker to navigate to the 'Attachments.aspx' endpoint, iterate through predictable values of 'formid', and download or delete all user-uploaded files, or upload new files.

  • CVE-2025-61548CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.01

    SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without…

  • CVE-2025-61546CriJan 8, 2026
    risk 0.59cvss 9.1epss 0.01

    There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69) that enables remote attacker to create financial discrepancies by purchasing items with a negative quantity. This…

  • CVE-2025-61246CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.00

    indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId parameter.

  • CVE-2025-59470CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.02

    This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter.

  • CVE-2025-59469CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.01

    This vulnerability allows a Backup or Tape Operator to write files as root.

  • CVE-2025-59468CriJan 8, 2026
    risk 0.59cvss 9.0epss 0.01

    This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a malicious password parameter.

  • CVE-2025-56425CriJan 8, 2026
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 11.10.0.183 and earlier of enaio 11.10. The vulnerability…