VYPR

CVEs

38,012 total · page 189 of 761

  • CVE-2025-63217CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The Itel DAB MUX (IDMUX build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same…

  • CVE-2025-63216CriNov 18, 2025
    risk 0.65cvss 10.0epss 0.01

    The Itel DAB Gateway (IDGat build c041640a) is vulnerable to Authentication Bypass due to improper JWT validation across devices. Attackers can reuse a valid JWT token obtained from one device to authenticate and gain administrative access to any other device running the same…

  • CVE-2025-63228CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unauthenticated file upload vulnerability in the /upload_file.php endpoint. An attacker can exploit this by sending a crafted POST request with a malicious file (e.g., a PHP webshell) to…

  • CVE-2025-63225CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The Eurolab ELTS100_UBX device (firmware version ELTS100v1.UBX) is vulnerable to Broken Access Control due to missing authentication on critical administrative endpoints. Attackers can directly access and modify sensitive system and network configurations, upload firmware, and…

  • CVE-2025-54321CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the reset password function, leading to an email bombing vulnerability. An authenticated attacker can exploit this by automating reset password requests.

  • CVE-2025-63695CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    DzzOffice v2.3.7 and before is vulnerable to Arbitrary File Upload in /dzz/system/ueditor/php/controller.php.

  • CVE-2025-63694CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    DzzOffice v2.3.7 and before is vulnerable to SQL Injection in explorer/groupmanage.

  • CVE-2025-56643CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.00

    Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, previously issued tokens remain valid and can be reused to access the system, even after logout. This behavior affects session integrity and may allow…

  • CVE-2025-9312CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the…

  • CVE-2025-41348CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in WinPlus v24.11.27 by Informática del Este. This vulnerability allows an attacker recover, create, update an delete databases by sendng a POST request using the parameters 'val1' and 'cont in '/WinplusPortal/ws/sWinplus.svc/json/getacumper_post'.

  • CVE-2025-41734CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices.

  • CVE-2025-41733CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.01

    The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthenticated remote attacker can construct POST requests to set root credentials.

  • CVE-2025-41347CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerability allows an attacker to upload a 'webshell' by sending a POST request to '/WinplusPortal/ws/sWinplus.svc/json/uploadfile'.

  • CVE-2025-41346CriNov 18, 2025
    risk 0.64cvss 9.8epss 0.00

    Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impersonated simply by knowing their 'numerical ID', meaning that an attacker could compromise another user's account, thereby affecting the confidentiality,…

  • CVE-2025-40549CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to admin privileges the ability to execute code on a directory. This issue requires administrative privileges to abuse. On Windows systems, this scored as medium…

  • CVE-2025-40548CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because services…

  • CVE-2025-40547CriNov 18, 2025
    risk 0.59cvss 9.1epss 0.01

    A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privileges the ability to execute code. This issue requires administrative privileges to abuse. On Windows deployments, the risk is scored as a medium because…

  • CVE-2024-44659CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.00

    PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.

  • CVE-2025-63747CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.00

    QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immediate login via the web application login page. Because the account provides administrative privileges in the default configuration, an attacker who can reach the…

  • CVE-2025-9501CriNov 17, 2025
    risk 0.60cvss 9.0epss 0.23

    The W3 Total Cache WordPress plugin before 2.8.13 is vulnerable to command injection via the _parse_dynamic_mfunc function, allowing unauthenticated users to execute PHP commands by submitting a comment with a malicious payload to a post.

  • CVE-2025-13284CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.02

    ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2025-10460CriNov 17, 2025
    risk 0.61cvss —epss 0.00

    A SQL Injection vulnerability on an endpoint in BEIMS Contractor Web, a legacy product that is no longer maintained or patched by the vendor, allows an unauthorised user to retrieve sensitive database contents via unsanitized parameter input. This vulnerability occurs due to…

  • CVE-2025-58083CriNov 15, 2025
    risk 0.65cvss 10.0epss 0.01

    General Industrial Controls Lynx+ Gateway  is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.

  • CVE-2025-13188CriNov 14, 2025
    risk 0.64cvss 9.8epss 0.02

    A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authenticationcgi_main of the file /authentication.cgi. Performing manipulation of the argument Password results in stack-based buffer overflow. Remote exploitation of…

  • CVE-2021-4470CriNov 14, 2025
    risk 0.61cvss —epss 0.01

    TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply…

  • CVE-2025-54343CriNov 14, 2025
    risk 0.62cvss 9.6epss 0.00

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

  • CVE-2025-54339CriNov 14, 2025
    risk 0.65cvss 10.0epss 0.00

    An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 exploitable remotely for Escalation of Privileges.

  • CVE-2025-64446CriKEVNov 14, 2025
    risk 0.86cvss 9.8epss 0.92

    A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands on the system via…

  • CVE-2025-36251CriNov 13, 2025
    risk 0.62cvss 9.6epss 0.01

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in…

  • CVE-2025-36250CriNov 13, 2025
    risk 0.65cvss 10.0epss 0.01

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls.  This addresses additional attack vectors for a vulnerability that was…

  • CVE-2025-36096CriNov 13, 2025
    risk 0.59cvss 9.0epss 0.00

    IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.

  • CVE-2025-64709CriNov 13, 2025
    risk 0.62cvss 9.6epss 0.00

    Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) functionality allows authenticated users to make arbitrary HTTP requests from the server, including…

  • CVE-2025-64717CriNov 13, 2025
    risk 0.57cvss 9.8epss 0.00

    ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4, and 4.6.6, a vulnerability in ZITADEL's federation process allowed auto-linking users from external identity providers to existing users in ZITADEL even if…

  • CVE-2025-12762CriNov 13, 2025
    risk 0.53cvss 9.1epss 0.13

    pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in server mode and performing restores from PLAIN-format dump files. This issue allows attackers to inject and execute arbitrary commands on the server hosting…

  • CVE-2025-59367CriNov 13, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to gain unauthorized access into the affected system. Refer to the 'Security Update for DSL Series Router' section on the ASUS Security Advisory for more…

  • CVE-2021-4464CriNov 12, 2025
    risk 0.61cvss —epss 0.02

    FiberHome AN5506-04-FA firmware versions up to and including RP2631 and HG6245D prior to RP2602 contain a stack-based buffer overflow, as the HTTP service ('webs') fails to enforce maximum lengths for Cookie header values. When a cookie longer than 511 bytes is processed, a…

  • CVE-2025-46608CriNov 12, 2025
    risk 0.59cvss 9.1epss 0.00

    Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. This vulnerability is considered Critical, as it…

  • CVE-2025-56385CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarmony.asp' endpoint. User-supplied input to the 'TXTUSERID' parameter is not properly sanitized before being incorporated into a SQL query. Successful…

  • CVE-2025-64281CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials.

  • CVE-2025-64280CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.

  • CVE-2025-63353CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-shared key) to be predicted from the SSID. The device generates default passwords using a deterministic algorithm that derives the router passphrase from the…

  • CVE-2025-63289CriNov 12, 2025
    risk 0.59cvss 9.1epss 0.00

    Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryption keys in the encryption_helper.dart file

  • CVE-2025-11367CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization

  • CVE-2025-11366CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    N-central < 2025.4 is vulnerable to authentication bypass via path traversal

  • CVE-2025-63666CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.00

    Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and uses a short, low-entropy suffix as the session identifier. An attacker with network access or the ability to run JS in a victim browser can steal the cookie…

  • CVE-2025-40176CriNov 12, 2025
    risk 0.57cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp_msg_hold fails Async decryption calls tls_strp_msg_hold to create a clone of the input skb to hold references to the memory it uses. If we fail to allocate…

  • CVE-2025-12871CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the system with elevated privileges.

  • CVE-2025-12870CriNov 12, 2025
    risk 0.64cvss 9.8epss 0.01

    The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens and use them to access the system with elevated privileges.

  • CVE-2025-60724CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.06

    Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.

  • CVE-2025-13032CriNov 11, 2025
    risk 0.64cvss 9.9epss 0.00

    Double fetch in sandbox kernel driver in Avast/AVG Antivirus <25.3  on windows allows local attacker to escalate privelages via pool overflow.