VYPR

CVEs

38,021 total · page 197 of 761

  • CVE-2025-60269CriOct 10, 2025
    risk 0.61cvss 9.4epss 0.00

    JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework/web/cgreport/controller/excel/CgExportExcelController.java file.

  • CVE-2025-60307CriOct 10, 2025
    risk 0.64cvss 9.8epss 0.00

    code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.

  • CVE-2025-61928CriOct 9, 2025
    risk 0.55cvss —epss 0.18

    Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `api/auth/api-key/create` route. `session?.user ??…

  • CVE-2025-59286CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59272CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.

  • CVE-2025-59252CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.

  • CVE-2025-59246CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.08

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2025-59218CriOct 9, 2025
    risk 0.62cvss 9.6epss 0.01

    Azure Entra ID Elevation of Privilege Vulnerability

  • CVE-2025-55321CriOct 9, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthorized attacker to perform spoofing over a network.

  • CVE-2025-35051CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. According to the recommended architecture,…

  • CVE-2025-35050CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, unauthenticated attacker to execute arbitrary code with 'NT AUTHORITY\NetworkService' privileges. The vulnerable endpoint is used by Newforma Project Center…

  • CVE-2025-60316CriOct 9, 2025
    risk 0.61cvss 9.4epss 0.00

    SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.

  • CVE-2025-59978CriOct 9, 2025
    risk 0.59cvss 9.0epss 0.01

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to store script tags directly in web pages that, when viewed by another user, enable the attacker to execute commands with the…

  • CVE-2017-20203CriOct 9, 2025
    risk 0.61cvss —epss 0.01

    NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322, Xftp 5.0 Build 1218, and Xlpd 5.0 Build 1220 contain a malicious nssock2.dll that implements a multi-stage, DNS-based backdoor. The dormant library contacts a C2 DNS server via a…

  • CVE-2025-10284CriOct 9, 2025
    risk 0.55cvss 9.6epss 0.01

    BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arbitrary file write, resulting in remote code execution.

  • CVE-2025-10283CriOct 9, 2025
    risk 0.55cvss 9.6epss 0.00

    BBOT's gitdumper module could be abused to execute commands through a malicious git repository.

  • CVE-2025-56683CriOct 9, 2025
    risk 0.55cvss 9.6epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to execute arbitrary code via injecting arbitrary Javascript into a crafted README.md file.

  • CVE-2025-11539CriOct 9, 2025
    risk 0.57cvss 9.9epss 0.01

    Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due to the fact that the /render/csv endpoint lacked validation of the filePath parameter that allowed an attacker to save a shared object to an arbitrary…

  • CVE-2025-11522CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeover in all versions up to, and including, 2.7. This is due to insufficient user validation in the search_and_go_elated_check_facebook_user() function This…

  • CVE-2025-7634CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.6.7 via the mode parameter. This makes it possible for unauthenticated attackers to include and execute…

  • CVE-2025-7526CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file deletion (via renaming) due to insufficient file path validation in the set_user_profile_image function in all versions up to, and including, 6.6.7. This…

  • CVE-2025-10586CriOct 9, 2025
    risk 0.64cvss 9.8epss 0.01

    The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. …

  • CVE-2025-61913CriOct 8, 2025
    risk 0.58cvss 9.9epss 0.13

    Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write…

  • CVE-2017-20202CriOct 8, 2025
    risk 0.60cvss —epss 0.01

    Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and fetched a remote script. The fetched script conditionally loaded follow-on modules that performed extensive ad substitution and malvertising, displayed fake “repair” alerts that…

  • CVE-2017-20201CriOct 8, 2025
    risk 0.60cvss —epss 0.01

    CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loader. That loader decodes an embedded blob into shellcode, allocates executable heap memory, resolves…

  • CVE-2025-10353CriOct 8, 2025
    risk 0.54cvss —epss 0.03

    File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm'…

  • CVE-2025-10352CriOct 8, 2025
    risk 0.53cvss —epss 0.00

    Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthenticated attacker to create an administrator account via a request to '/melis/MelisCore/ToolUser/addNewUser'.

  • CVE-2025-10351CriOct 8, 2025
    risk 0.53cvss —epss 0.00

    SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates'…

  • CVE-2025-10587CriOct 8, 2025
    risk 0.64cvss 9.8epss 0.00

    The Community Events plugin for WordPress is vulnerable to SQL Injection via the event_category parameter in all versions up to, and including, 1.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This…

  • CVE-2025-11423CriOct 8, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was found in Tenda CH22 1.0.0.1. This affects the function formSafeEmailFilter of the file /goform/SafeEmailFilter. Performing a manipulation of the argument page results in memory corruption. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2025-11418CriOct 8, 2025
    risk 0.64cvss 9.8epss 0.07

    A security vulnerability has been detected in Tenda CH22 up to 1.0.0.1. This issue affects the function formWrlsafeset of the file /goform/AdvSetWrlsafeset of the component HTTP Request Handler. The manipulation of the argument mit_ssid_index leads to stack-based buffer…

  • CVE-2025-44823CriOct 7, 2025
    risk 0.66cvss 9.9epss 0.16

    Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagioslogserver/index.php/api/system/get_users call. This is GL:NLS#475.

  • CVE-2025-3450CriOct 7, 2025
    risk 0.65cvss 10.0epss 0.00

    An Improper Resource Locking vulnerability in the SDM component of B&R Automation Runtime versions before 6.3 and before Q4.93 may allow an unauthenticated network-based attacker to delete data causing denial of service conditions.

  • CVE-2025-52021CriOct 7, 2025
    risk 0.64cvss 9.8epss 0.00

    A SQL Injection vulnerability exists in the edit_product.php file of PuneethReddyHC Online Shopping System Advanced 1.0. The product_id GET parameter is unsafely passed to a SQL query without proper validation or parameterization.

  • CVE-2023-53629CriOct 7, 2025
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: fs: dlm: fix use after free in midcomms commit While working on processing dlm message in softirq context I experienced the following KASAN use-after-free warning: [ 151.760477]…

  • CVE-2025-0603CriOct 7, 2025
    risk 0.64cvss 9.8epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0.

  • CVE-2025-61774CriOct 6, 2025
    risk 0.60cvss —epss 0.01

    PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code use`--extra-index-url`. But when `--extra-index-url`…

  • CVE-2025-57515CriOct 6, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability has been identified in Uniclare Student Portal v2. This flaw allows remote attackers to inject arbitrary SQL commands via vulnerable input fields, enabling the execution of time-delay functions to infer database responses.

  • CVE-2025-61778CriOct 6, 2025
    risk 0.53cvss —epss 0.00

    Akka.NET is a .NET port of the Akka project from the Scala / Java community. In all versions of Akka.Remote from v1.2.0 to v1.5.51, TLS could be enabled via our `akka.remote.dot-netty.tcp` transport and this would correctly enforce private key validation on the server-side of…

  • CVE-2025-61777CriOct 6, 2025
    risk 0.00cvss 9.4epss 0.00

    Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/api/admin/badge-templates/create` (POST) endpoints previously allowed access without authentication or authorization. This could…

  • CVE-2025-60965CriOct 6, 2025
    risk 0.59cvss 9.1epss 0.01

    OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and possibly other unspecified…

  • CVE-2025-60964CriOct 6, 2025
    risk 0.59cvss 9.1epss 0.01

    OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive information, and possibly other unspecified…

  • CVE-2025-60957CriOct 6, 2025
    risk 0.64cvss 9.9epss 0.01

    OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive information.

  • CVE-2025-57247CriOct 6, 2025
    risk 0.59cvss 9.1epss 0.00

    The BATBToken smart contract (address 0xfbf1388408670c02f0dbbb74251d8ded1d63b7a2, Compiler Version v0.8.26+commit.8a97fa7a) contains incorrect access control implementation in whitelist management functions. The setColdWhiteList() and setSpecialAddress() functions in the base…

  • CVE-2025-36356CriOct 6, 2025
    risk 0.60cvss 9.3epss 0.00

    IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required.

  • CVE-2025-10363CriOct 6, 2025
    risk 0.65cvss —epss 0.01

    Deserialization of Untrusted Data vulnerability in Topal Solutions AG Topal Finanzbuchhaltung on Windows allows Remote Code Execution.This issue affects at least Topal Finanzbuchhaltung: 10.1.5.20 and is fixed in version 11.2.12.00

  • CVE-2025-59159CriOct 6, 2025
    risk 0.55cvss 9.6epss 0.00

    SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. In versions prior to 1.13.4, the web user interface for SillyTavern is susceptible to DNS…

  • CVE-2025-52472CriOct 6, 2025
    risk 0.54cvss —epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 4.3-milestone-1 and prior to versions 16.10.9, 17.4.2, and 17.5.0, the REST search URL is vulnerable to HQL injection via the `orderField` parameter. The…

  • CVE-2025-49594CriOct 6, 2025
    risk 0.53cvss —epss 0.00

    XWiki OIDC has various tools to manipulate OpenID Connect protocol in XWiki. Starting in version 2.17.1 and prior to version 2.18.2, anyone with VIEW access to a user profile can create a token for that user. If that XWiki instance is configured to allow token authentication, it…

  • CVE-2023-49886CriOct 6, 2025
    risk 0.64cvss 9.8epss 0.01

    IBM Standards Processing Engine 10.0.1.10 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe java deserialization. By sending specially crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.