VYPR

CVEs

38,012 total · page 187 of 761

  • CVE-2025-13539CriNov 27, 2025
    risk 0.64cvss 9.8epss 0.00

    The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.4. This is due to the plugin not properly logging in a user with the data that was previously verified through the 'findall_membership_check_facebook_user'…

  • CVE-2025-13538CriNov 27, 2025
    risk 0.64cvss 9.8epss 0.00

    The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findall_listing_user_registration_additional_params' function not restricting what user roles a user can register with. This makes it…

  • CVE-2024-5539CriNov 27, 2025
    risk 0.60cvss —epss 0.00

    The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.

  • CVE-2025-40934CriNov 26, 2025
    risk 0.00cvss 9.3epss 0.00

    XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can remove the signature from the XML document to make it pass the verification check. XML-Sig is a Perl module to validate signatures on XML files.  An unsigned…

  • CVE-2025-65276CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/henzljw/hashtech) 1.0 thru commit 5919decaff2681dc250e934814fc3a35f6093ee5 (2021-07-02). Due to missing authentication checks on /admin_index.php, an attacker…

  • CVE-2025-50433CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted password reset to take over arbitrary user accounts.

  • CVE-2025-65669CriNov 26, 2025
    risk 0.59cvss 9.1epss 0.00

    An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without any authorization or authentication checks, bypassing the expected admin-only deletion restriction.

  • CVE-2025-26155CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

  • CVE-2025-64130CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to execute arbitrary JavaScript on the victim's browser.

  • CVE-2025-64128CriNov 26, 2025
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauthenticated attacker to inject arbitrary…

  • CVE-2025-64127CriNov 26, 2025
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute …

  • CVE-2025-64126CriNov 26, 2025
    risk 0.65cvss 10.0epss 0.02

    An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This could allow an unauthenticated attacker…

  • CVE-2025-55469CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator backend.

  • CVE-2025-65236CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID parameter in the /occontrolpanel/index.php endpoint.

  • CVE-2025-65235CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via the ID parameter in the getSubUsersByProvider function.

  • CVE-2025-62354CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those specified in the allowlist, resulting in arbitrary code execution.

  • CVE-2025-50402CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.

  • CVE-2025-50399CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.

  • CVE-2025-59390CriNov 26, 2025
    risk 0.57cvss 9.8epss 0.01

    Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-graphically secure…

  • CVE-2025-66022CriNov 26, 2025
    risk 0.00cvss 9.6epss 0.01

    FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution path in Faction’s extension framework permits untrusted extension code to execute arbitrary system commands on the server when a lifecycle hook is invoked,…

  • CVE-2025-66266CriNov 26, 2025
    risk 0.60cvss —epss 0.00

    The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control. A local attacker can replace the executable with a malicious binary to execute code with SYSTEM privileges or simply change the config path of the service to…

  • CVE-2025-66262CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Tar extraction with -C / allow arbitrary file overwrite…

  • CVE-2025-66261CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform URL-decoded name parameter passed to exec() allows remote…

  • CVE-2025-66259CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform in main_ok.php user supplied…

  • CVE-2025-66257CriNov 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletepatch parameter allows unauthenticated…

  • CVE-2025-66256CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Unrestricted file upload in patch_contents.php allows…

  • CVE-2025-66255CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Missing signature validation allows uploading malicious…

  • CVE-2025-66254CriNov 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deleteupgrade parameter allows unauthenticated…

  • CVE-2025-66253CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code…

  • CVE-2025-66251CriNov 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform The deletehidden parameter allows path traversal deletion…

  • CVE-2025-66250CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.00

    Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform Allows unauthenticated arbitrary file upload via…

  • CVE-2025-64657CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-64656CriNov 26, 2025
    risk 0.61cvss 9.4epss 0.01

    Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-13597CriNov 25, 2025
    risk 0.57cvss 9.8epss 0.01

    The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.0.11. This makes it possible for unauthenticated attackers to download arbitrary GitHub…

  • CVE-2025-13595CriNov 25, 2025
    risk 0.57cvss 9.8epss 0.01

    The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actualizador_git.php' file in all versions up to, and including, 1.10.8. This makes it possible for unauthenticated attackers to download arbitrary GitHub…

  • CVE-2025-51746CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-51745CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-51744CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-51743CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to fastjson deserialization attacks.

  • CVE-2025-66016CriNov 25, 2025
    risk 0.53cvss —epss 0.00

    CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiable abort, and a key refresh protocol. Prior to version 0.6.3, there is a missing check in the ZK proof that enables an attack in which single malicious signer…

  • CVE-2025-51742CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the search query parameter directly to parseObject(), introducing a Fastjson deserialization vulnerability that can lead to RCE via JDBC payloads.

  • CVE-2025-64063CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specifically, a standard user can exploit this flaw by sending direct HTTP requests to administrative endpoints, bypassing the UI restrictions. This allows the…

  • CVE-2025-61168CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

  • CVE-2025-65085CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code.

  • CVE-2025-65084CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code.

  • CVE-2025-33187CriNov 25, 2025
    risk 0.60cvss 9.3epss 0.00

    NVIDIA DGX Spark GB10 contains a vulnerability in SROOT, where an attacker could use privileged access to gain access to SoC protected areas. A successful exploit of this vulnerability might lead to code execution, information disclosure, data tampering, denial of service, or…

  • CVE-2025-63729CriNov 25, 2025
    risk 0.59cvss 9.0epss 0.00

    An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Private Key, CA Certificate, SSL Certificate, and Client Certificates in .pem format in firmware in etc folder.

  • CVE-2025-60739CriNov 25, 2025
    risk 0.62cvss 9.6epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logic Version v6.00 - 2025_07_21 allows a remote attacker to execute arbitrary code via the /bh_web_backend component

  • CVE-2025-64693CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Content-Length. Receiving a specially crafted request from a remote unauthenticated attacker could lead to arbitrary code execution with SYSTEM privilege.

  • CVE-2025-62691CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HTTP headers. Receiving a specially crafted request from a remote unauthenticated attacker could lead to arbitrary code execution with SYSTEM privilege.