VYPR

CVEs

38,030 total · page 206 of 761

  • CVE-2024-58240CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling from async If we're not doing async, the handling is much simpler. There's no reference counting, we just need to wait for the completion to wake us up and…

  • CVE-2025-54762CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.01

    SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.

  • CVE-2025-53970CriAug 28, 2025
    risk 0.64cvss 9.8epss 0.01

    SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arbitrary files and execute OS commands with SYSTEM privileges.

  • CVE-2025-7955CriAug 28, 2025
    risk 0.57cvss 9.8epss 0.01

    The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user…

  • CVE-2025-34523CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data Protection (UDP). This flaw is reachable without authentication and results from improper bounds checking when processing attacker-controlled input. By…

  • CVE-2025-34522CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). This flaw can be triggered without authentication by sending specially crafted input to the target system. Improper bounds checking allows an attacker to…

  • CVE-2025-34520CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.00

    An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gain unauthorized access to protected functionality or user accounts. By manipulating specific request parameters or exploiting a logic flaw, an attacker can…

  • CVE-2025-34163CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce proper file type validation and access control. An attacker can upload arbitrary files, including executable scripts such as .ashx, via a crafted…

  • CVE-2025-34162CriAug 27, 2025
    risk 0.61cvss —epss 0.01

    An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. The backend fails to properly sanitize…

  • CVE-2025-34160CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service accepts user-supplied input via POST and fails to sanitize command-like payloads. An attacker can inject…

  • CVE-2024-13985CriAug 27, 2025
    risk 0.66cvss —epss 0.15

    A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation in the captureCommand parameter, which is…

  • CVE-2024-13984CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    QiAnXin TianQing Management Center versions up to and including 6.7.0.4130 contain a path traversal vulnerability in the rptsvr component that allows unauthenticated attackers to upload files to arbitrary locations on the server. The /rptsvr/upload endpoint fails to sanitize the…

  • CVE-2024-13981CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    LiveBOS, an object-oriented business architecture middleware suite developed by Apex Software Co., Ltd., contains an arbitrary file upload vulnerability in its UploadFile.do;.js.jsp endpoint. This flaw affects the LiveBOS Server component and allows unauthenticated remote…

  • CVE-2024-13980CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    H3C Intelligent Management Center (IMC) versions up to and including E0632H07 contains a remote command execution vulnerability in the /byod/index.xhtml endpoint. Improper handling of JSF ViewState allows unauthenticated attackers to craft POST requests with forged…

  • CVE-2024-13979CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.03

    A SQL injection vulnerability exists in the St. Joe ERP system ("圣乔ERP系统") that allows unauthenticated remote attackers to execute arbitrary SQL commands via crafted HTTP POST requests to the login endpoint. The application fails to properly sanitize user-supplied input…

  • CVE-2023-7309CriAug 27, 2025
    risk 0.65cvss —epss 0.01

    A path traversal vulnerability exists in the Dahua Smart Park Integrated Management Platform (also referred to as the Dahua Smart Campus Integrated Management Platform), affecting the SOAP-based GIS bitmap upload interface. The flaw allows unauthenticated remote attackers to…

  • CVE-2018-25115CriAug 27, 2025
    risk 0.65cvss 9.8epss 0.10

    Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary system commands without authentication.…

  • CVE-2025-58050CriAug 27, 2025
    risk 0.00cvss 9.1epss 0.01

    The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-buffer-overflow read vulnerability exists in the PCRE2 regular expression matching engine, specifically within the handling of the (*scs:...) (Scan SubString)…

  • CVE-2025-50428CriAug 27, 2025
    risk 0.00cvss 9.8epss 0.02

    In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. The vulnerability is due to improper sanitizing of user input passed via the interface parameter.

  • CVE-2025-34157CriAug 27, 2025
    risk 0.59cvss 9.0epss 0.00

    Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project creation workflow. An authenticated user with low privileges can create a project with a maliciously crafted name containing embedded JavaScript. When an…

  • CVE-2025-52122CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.01

    Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).

  • CVE-2025-50989CriAug 27, 2025
    risk 0.60cvss 9.1epss 0.09

    OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (interfaces_bridge_edit.php). The span POST parameter is concatenated into a system-level command without proper sanitization or escaping, allowing an…

  • CVE-2025-50972CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via the tmpl_id parameter to index.php. Three techniques have been demonstrated: error-based injection using a crafted FLOOR-based payload, time-based blind…

  • CVE-2025-43728CriAug 27, 2025
    risk 0.62cvss 9.6epss 0.00

    Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

  • CVE-2025-9523CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the argument mac results in stack-based buffer overflow. It is possible to launch the attack remotely. The…

  • CVE-2025-30063CriAug 27, 2025
    risk 0.61cvss —epss 0.00

    The configuration file containing database logins and passwords is readable by any local user.

  • CVE-2025-30057CriAug 27, 2025
    risk 0.61cvss —epss 0.01

    In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() call in the ConvertToPDF function.

  • CVE-2025-30056CriAug 27, 2025
    risk 0.61cvss —epss 0.00

    The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker to execute arbitrary code on the system.

  • CVE-2025-30055CriAug 27, 2025
    risk 0.59cvss —epss 0.00

    The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible to execute arbitrary code provided as the "Module" parameter.

  • CVE-2025-30041CriAug 27, 2025
    risk 0.59cvss —epss 0.00

    The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/CliniNET.prd/utils/dblogstat.pl" expose data containing session IDs.

  • CVE-2025-30040CriAug 27, 2025
    risk 0.59cvss —epss 0.00

    The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "/cgi-bin/CliniNET.prd/utils/userlogxls.pl" endpoint.

  • CVE-2025-30039CriAug 27, 2025
    risk 0.59cvss —epss 0.00

    Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session logged into the system, including users with admin privileges.

  • CVE-2025-2313CriAug 27, 2025
    risk 0.61cvss —epss 0.00

    In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.

  • CVE-2025-22408CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-22403CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In sdp_snd_service_search_req of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-0075CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In process_service_search_attr_req of sdp_server.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-0074CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.00

    In process_service_attr_rsp of sdp_discovery.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2025-55443CriAug 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Telpo MDM 1.4.6 thru 1.4.9 for Android contains sensitive administrator credentials and MQTT server connection details (IP/port) that are stored in plaintext within log files on the device's external storage. This allows attackers with access to these logs to: 1. Authenticate to…

  • CVE-2025-52353CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files containing embedded PHP code via the file-upload endpoint, bypassing content-type validation. When such a file is accessed via its URL, the server…

  • CVE-2024-39335CriAug 26, 2025
    risk 0.59cvss 9.1epss 0.00

    Supported versions of Mahara 24.04 before 24.04.1 and 23.04 before 23.04.6 are vulnerable to information being disclosed to an institution administrator under certain conditions via the 'Current submissions' page: Administration -> Groups -> Submissions.

  • CVE-2025-55526CriAug 26, 2025
    risk 0.59cvss 9.1epss 0.01

    n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py

  • CVE-2025-7776CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.08

    Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it

  • CVE-2025-7775CriKEVAug 26, 2025
    risk 0.77cvss 9.8epss 0.20

    Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler…

  • CVE-2025-41702CriAug 26, 2025
    risk 0.64cvss 9.8epss 0.01

    The JWT secret key is embedded in the egOS WebGUI backend and is readable to the default user. An unauthenticated remote attacker can generate valid HS256 tokens and bypass authentication/authorization due to the use of hard-coded cryptographic key.

  • CVE-2025-57773CriAug 25, 2025
    risk 0.01cvss 9.8epss 0.09

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files.…

  • CVE-2025-57772CriAug 25, 2025
    risk 0.01cvss 9.8epss 0.10

    DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If the JDBC URL meets criteria, the getJdbcUrl method is returned, which acts as the getter for the JdbcUrl parameter provided. This…

  • CVE-2025-53120CriAug 25, 2025
    risk 0.62cvss 9.4epss 0.11

    A path traversal vulnerability in unauthenticated upload functionality allows a malicious actor to upload binaries and scripts to the server’s configuration and web root directories, achieving remote code execution on the Unified PAM server.

  • CVE-2025-50722CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php component

  • CVE-2025-55575CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail.

  • CVE-2025-53118CriAug 25, 2025
    risk 0.66cvss 9.8epss 0.33

    An authentication bypass vulnerability exists which allows an unauthenticated attacker to control administrator backup functions, leading to compromise of passwords, secrets, and application session tokens stored by the Unified PAM.