VYPR

CVEs

38,030 total · page 207 of 761

  • CVE-2025-56214CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter.

  • CVE-2025-56212CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.00

    phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter.

  • CVE-2025-50900CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com.rebuild.web.RebuildWebInterceptor, and the affected function is preHandle In the filter code, use CodecUtils.urlDecode(request.getRequestURI()) to obtain the URL-decoded request path, and…

  • CVE-2025-54494CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54493CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54492CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54491CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54490CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54489CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54488CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54487CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54486CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54485CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54484CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54483CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54482CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54481CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54480CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-54462CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the Nex parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted .nex file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-53853CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the ISHNE parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted ISHNE ECG annotations file can lead to arbitrary code execution. An attacker can provide a malicious file…

  • CVE-2025-53557CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-53518CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An integer overflow vulnerability exists in the ABF parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted ABF file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-53511CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this…

  • CVE-2025-52581CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An integer overflow vulnerability exists in the GDF parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted GDF file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2025-48005CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A heap-based buffer overflow vulnerability exists in the RHS2000 parsing functionality of The Biosig Project libbiosig 3.9.0 and Master Branch (35a819fa). A specially crafted RHS2000 file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger…

  • CVE-2025-45968CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in System PDV v1.0 allows a remote attacker to obtain sensitive information via the hash parameter in a URL. The application contains an Insecure Direct Object Reference (IDOR) vulnerability, which occurs due to a lack of proper authorization checks when accessing…

  • CVE-2025-29515CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to modify arbitrary settings within the device's XML database, including the administrator’s password.

  • CVE-2025-29514CriAug 25, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to download the configuration file via providing a crafted web request.

  • CVE-2025-7426CriAug 25, 2025
    risk 0.60cvss —epss 0.00

    Information disclosure and exposure of authentication FTP credentials over the debug port 1604 in the MINOVA TTA service. This allows unauthenticated remote access to an active FTP account containing sensitive internal data and import structures. In environments where this FTP…

  • CVE-2025-9118CriAug 25, 2025
    risk 0.65cvss —epss 0.01

    A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.

  • CVE-2025-36157CriAug 24, 2025
    risk 0.64cvss 9.8epss 0.01

    IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenticated remote attacker to update server property files that would allow them to perform unauthorized actions.

  • CVE-2025-5821CriAug 23, 2025
    risk 0.64cvss 9.8epss 0.01

    The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.3. This is due to the plugin not properly logging in a user with the data that was previously verified through the facebook_ajax_login_callback() function.…

  • CVE-2025-5352CriAug 23, 2025
    risk 0.62cvss 9.6epss 0.01

    A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary versions up to 1.9.23, where the NEXT_PUBLIC_CUSTOM_SCRIPT environment variable is directly injected into the DOM using dangerouslySetInnerHTML without any…

  • CVE-2025-7642CriAug 23, 2025
    risk 0.64cvss 9.8epss 0.00

    The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due to the plugin not properly verifying a user's identity prior to logging them in as an admin through the simplerwc_woocommerce_order_created() function. This…

  • CVE-2025-43766CriAug 23, 2025
    risk 0.57cvss 9.8epss 0.00

    The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2024.Q2.13, 2024.Q1.1 through 2024.Q1.12 and 7.4 GA through update 92 allows the upload of unrestricted files in the style books component that are processed…

  • CVE-2025-4609CriAug 22, 2025
    risk 0.62cvss 9.6epss 0.00

    Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allowed a remote attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

  • CVE-2025-26496CriAug 22, 2025
    risk 0.60cvss 9.3epss 0.00

    Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Desktop on Windows, Linux (File Upload modules) allows Local Code Inclusion.This issue affects Tableau Server, Tableau Desktop: before 2025.1.3, before 2024.2.12,…

  • CVE-2025-57801CriAug 22, 2025
    risk 0.52cvss 9.1epss 0.00

    gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa.go used the S value from a signature without asserting that 0 ≤ S < order, leading to a signature malleability vulnerability. Because gnark’s native EdDSA…

  • CVE-2022-43110CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface…

  • CVE-2022-31491CriAug 22, 2025
    risk 0.65cvss 10.0epss 0.01

    Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated…

  • CVE-2025-51092CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.00

    The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in DataBase.php. The functions logIn() and signUp() build queries by directly concatenating user input and unvalidated table names without using prepared…

  • CVE-2022-45134CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Mahara 21.10 before 21.10.6, 22.04 before 22.04.4, and 22.10 before 22.10.1 deserializes user input unsafely during skin import. A particularly structured XML file could cause code execution when being processed.

  • CVE-2025-55613CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.

  • CVE-2024-53499CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Jeewms v3.7 was discovered to contain a SQL injection vulnerability via the CgReportController API.

  • CVE-2024-53496CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to access sensitive components without authentication.

  • CVE-2024-52786CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.

  • CVE-2024-50645CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    MallChat v1.0-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.

  • CVE-2025-57105CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.03

    The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the device. The sub_478D28 function in in mng_platform.asp, and sub_4A12DC function in wayos_ac_server.asp of the jhttpd program, with the parameter…

  • CVE-2025-55637CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.02

    Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a command injection vulnerability via the setddns_pip_system() function.

  • CVE-2025-55619CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.00

    Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker can leverage this vulnerability to decrypt access tokens and web session tokens stored inside the app via reverse engineering.