VYPR

CVEs

38,011 total · page 186 of 761

  • CVE-2025-65896CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via crafted dict keys.

  • CVE-2025-60736CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

  • CVE-2025-60854CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during a password change request in the web administrator page, it is possible to trigger a command injection in httpd.

  • CVE-2025-58386CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper server-side authorization checks. A Power User can intercept and modify this parameter to assign the Administrator role to other existing lower-privileged…

  • CVE-2025-65656CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.

  • CVE-2025-65358CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.

  • CVE-2025-13828CriDec 2, 2025
    risk 0.59cvss —epss 0.00

    SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even if the flag in update settings for enable composer based update is unticked. ImpactA low-privileged user of the platform can install malicious code to obtain…

  • CVE-2025-59703CriDec 2, 2025
    risk 0.59cvss 9.1epss 0.00

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a Physically Proximate Attacker to access the internal components of the appliance, without leaving tamper evidence. To exploit this, the attacker…

  • CVE-2025-59695CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a user with OS root access to alter firmware on the Chassis Management Board (without Authentication). This is called F04.

  • CVE-2025-59693CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allows a physically proximate attacker to obtain debug access and escalate privileges by bypassing the tamper label and…

  • CVE-2025-41013CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a GET request using the 'idmant' parameter in '/PC/frmEPIS.aspx'.

  • CVE-2025-11788CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Heap-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowSupervisorParameters()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input,…

  • CVE-2025-11786CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'SetUserPassword()' function, the 'newPassword' parameter is directly embedded in a shell command string using 'sprintf()' without any sanitisation or validation, and then executed using…

  • CVE-2025-11785CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterPasswords()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which…

  • CVE-2025-11784CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'ShowMeterDatabase()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which…

  • CVE-2025-11783CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The vulnerability is found in the 'AddEvent()' function when copying the user-controlled username input to a fixed-size buffer (48 bytes) without boundary checking. This can lead to memory…

  • CVE-2025-11782CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'ShowDownload()' function uses “sprintf()” to format a string that includes the user-controlled input of 'GetParameter(meter)' in the fixed-size buffer 'acStack_4c' (64 bytes) without…

  • CVE-2025-11780CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. In the 'showMeterReport()' function, there is an unlimited user input that is copied to a fixed-size buffer via 'sprintf()'. The 'GetParameter(meter)' function retrieves the user input, which is…

  • CVE-2025-11779CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow vulnerability in CircutorSGE-PLC1000/SGE-PLC50 v9.0.2. The 'SetLan' function is invoked when a new configuration is applied. This new configuration function is activated by a management web request, which can be invoked by a user when making changes…

  • CVE-2025-11778CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Stack-based buffer overflow in Circutor SGE-PLC1000/SGE-PLC50 v0.9.2. This vulnerability allows an attacker to remotely exploit memory corruption through the 'read_packet()' function of the TACACSPLUS implementation.

  • CVE-2025-41744CriDec 2, 2025
    risk 0.59cvss 9.1epss 0.00

    Sprecher Automations SPRECON-E series uses default cryptographic keys that allow an unprivileged remote attacker to access all encrypted communications, thereby compromising confidentiality and integrity.

  • CVE-2025-41742CriDec 2, 2025
    risk 0.64cvss 9.8epss 0.00

    Sprecher Automations SPRECON-E-C,  SPRECON-E-P, SPRECON-E-T3 is vulnerable to attack by an unauthorized remote attacker via default cryptographic keys. The use of these keys allows the attacker to read, modify, and write projects and data, or to access any device via remote…

  • CVE-2025-13872CriDec 2, 2025
    risk 0.59cvss 9.1epss 0.00

    Blind Server-Side Request Forgery (SSRF) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on Web-based platforms allows an attacker to force the server to perform HTTP GET requests via crafted import requests to an arbitrary destination.

  • CVE-2025-66410CriDec 1, 2025
    risk 0.52cvss 9.1epss 0.01

    Gin-vue-admin is a backstage management system based on vue and gin. In 2.8.6 and earlier, attackers can delete any file on the server at will, causing damage or unavailability of server resources. Attackers can control the 'FileMd5' parameter to delete any file and folder.

  • CVE-2025-66405CriDec 1, 2025
    risk 0.57cvss 9.8epss 0.00

    Portkey.ai Gateway is a blazing fast AI Gateway with integrated guardrails. Prior to 1.14.0, the gateway determined the destination baseURL by prioritizing the value in the x-portkey-custom-host request header. The proxy route then appends the client-specified path to perform an…

  • CVE-2025-66401CriDec 1, 2025
    risk 0.57cvss 9.8epss 0.02

    MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPScanner class contains a critical Command Injection vulnerability in the cloneRepo method. The application passes the user-supplied githubUrl argument directly to…

  • CVE-2025-66301CriDec 1, 2025
    risk 0.59cvss 9.6epss 0.01

    Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now able to change the functioning…

  • CVE-2025-65836CriDec 1, 2025
    risk 0.59cvss 9.1epss 0.00

    PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

  • CVE-2025-51683CriDec 1, 2025
    risk 0.64cvss 9.8epss 0.02

    A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL statements via a crafted POST request to the /Default.aspx/update_profile_Server endpoint .

  • CVE-2025-51682CriDec 1, 2025
    risk 0.64cvss 9.8epss 0.02

    mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to administrative features. Additionally, they can craft requests based on the client-side code to call these administrative functions directly.

  • CVE-2025-63535CriDec 1, 2025
    risk 0.62cvss 9.6epss 0.00

    A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the abs.php component. The application fails to properly sanitize usersupplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an…

  • CVE-2025-63532CriDec 1, 2025
    risk 0.62cvss 9.6epss 0.00

    A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the cancel.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the search field, an…

  • CVE-2025-3500CriDec 1, 2025
    risk 0.59cvss 9.0epss 0.00

    Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This issue affects Antivirus: from 25.1.981.6 before 25.3.

  • CVE-2025-63531CriDec 1, 2025
    risk 0.65cvss 10.0epss 0.01

    A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The application fails to properly sanitize user-supplied input in SQL queries, allowing an attacker to inject arbitrary SQL code. By manipulating the remail and…

  • CVE-2025-63525CriDec 1, 2025
    risk 0.62cvss 9.6epss 0.00

    An issue was discovered in Blood Bank Management System 1.0 allowing authenticated attackers to perform actions with escalated privileges via crafted request to delete.php.

  • CVE-2025-12106CriDec 1, 2025
    risk 0.59cvss 9.1epss 0.01

    Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

  • CVE-2025-35028CriNov 30, 2025
    risk 0.60cvss 9.1epss 0.05

    By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecutor class of the HexStrike AI MCP server, the resultant composed command is executed directly in the context of the MCP server’s normal privilege; typically,…

  • CVE-2025-13615CriNov 30, 2025
    risk 0.64cvss 9.8epss 0.00

    The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 4.78. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it…

  • CVE-2025-66216CriNov 29, 2025
    risk 0.64cvss 9.8epss 0.01

    AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been identified in the AIS::Message class of AIS-catcher. This vulnerability allows an attacker to write approximately 1KB of arbitrary data into a 128-byte buffer. This…

  • CVE-2025-66219CriNov 29, 2025
    risk 0.64cvss 9.8epss 0.03

    willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a command Injection vulnerability in willitmerge. The vulnerability manifests in this package due to the use of insecure child process execution API (exec) to which…

  • CVE-2025-65112CriNov 29, 2025
    risk 0.61cvss 9.4epss 0.00

    PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubNet allows unauthenticated users to upload packages as any user by providing arbitrary author-id values. This enables identity spoofing, privilege escalation,…

  • CVE-2025-66385CriNov 28, 2025
    risk 0.61cvss —epss 0.00

    UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges (e.g., obtain a higher role such as admin) via the user-edit endpoint by supplying or modifying role_id or organisation_id fields in the edit request.

  • CVE-2025-64314CriNov 28, 2025
    risk 0.60cvss 9.3epss 0.00

    Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability may affect confidentiality.

  • CVE-2025-12421CriNov 27, 2025
    risk 0.57cvss 9.9epss 0.00

    Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a…

  • CVE-2025-12419CriNov 27, 2025
    risk 0.57cvss 9.9epss 0.00

    Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via…

  • CVE-2025-8890CriNov 27, 2025
    risk 0.61cvss —epss 0.01

    Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell command injection attacks. In order to exploit this vulnerability, an attacker has to log in to the router's administrative portal, which by default is reachable…

  • CVE-2025-12140CriNov 27, 2025
    risk 0.60cvss —epss 0.00

    The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlParameter' parameter. The application interprets the entered string of characters as a Java expression, allowing an unauthenticated attacer to perform arbitrary…

  • CVE-2025-13675CriNov 27, 2025
    risk 0.64cvss 9.8epss 0.00

    The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply…

  • CVE-2025-13540CriNov 27, 2025
    risk 0.64cvss 9.8epss 0.00

    The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_membership_init_rest_api_register' function not restricting what user roles a user can register with. This makes it possible for…

  • CVE-2025-13539CriNov 27, 2025
    risk 0.64cvss 9.8epss 0.00

    The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'findall_membership_check_facebook_user'…