VYPR

CVEs

38,030 total · page 208 of 761

  • CVE-2025-55398CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed Encoding Rules), asn1c-generated decoders fail to enforce INTEGER constraints when the bound is positive and exceeds 32 bits in length, potentially allowing…

  • CVE-2024-50644CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    zhisheng17 blog 3.0.1-SNAPSHOT has an authentication bypass vulnerability. An attacker can exploit this vulnerability to access API without any token.

  • CVE-2025-52095CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines in SDCommon.dll

  • CVE-2025-38660CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: [ceph] parse_longname(): strrchr() expects NUL-terminated string ... and parse_longname() is not guaranteed that. That's the reason why it uses kmemdup_nul() to build the argument for kstrtou64(); the problem…

  • CVE-2025-29366CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, which enables executing arbitrary commands on the host machine.

  • CVE-2025-29365CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.

  • CVE-2009-10006CriAug 22, 2025
    risk 0.64cvss —epss 0.01

    UFO: Alien Invasion versions up to and including 2.2.1 contain a buffer overflow vulnerability in its built-in IRC client component. When the client connects to an IRC server and receives a crafted numeric reply (specifically a 001 message), the application fails to properly…

  • CVE-2025-9254CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality.

  • CVE-2010-20122CriAug 21, 2025
    risk 0.64cvss —epss 0.01

    Xftp FTP Client version up to and including 3.0 (build 0238) contain a stack-based buffer overflow vulnerability triggered by a maliciously crafted PWD response from an FTP server. When the client connects to a server and receives an overly long directory string in response to…

  • CVE-2010-20115CriAug 21, 2025
    risk 0.64cvss —epss 0.01

    Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate…

  • CVE-2010-20113CriAug 21, 2025
    risk 0.67cvss 9.8epss 0.02

    EasyFTP Server 1.7.0.11 and earlier contains a stack-based buffer overflow vulnerability in its HTTP interface. When processing a GET request to list.html, the server fails to properly validate the length of the path parameter. Supplying an excessively long value causes a buffer…

  • CVE-2025-53795CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.01

    Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-53763CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

  • CVE-2025-3128CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamper with, destroy or delete information in Mitsubishi Electric smartRTU, or cause a denial-of service condition on the product.

  • CVE-2010-20121CriAug 21, 2025
    risk 0.67cvss 9.8epss 0.03

    EasyFTP Server versions up to 1.7.0.11 contain a stack-based buffer overflow vulnerability in the FTP command parser. When processing the CWD (Change Working Directory) command, the server fails to properly validate the length of the input string, allowing attackers to overwrite…

  • CVE-2010-20112CriAug 21, 2025
    risk 0.64cvss —epss 0.01

    Amlib’s NetOpacs webquery.dll contains a stack-based buffer overflow vulnerability triggered by improper handling of HTTP GET parameters. Specifically, the application fails to enforce bounds on input supplied to the app parameter, allowing excessive data to overwrite memory…

  • CVE-2025-52352CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed deployments by hiding the sign-up option on the login page UI. However, the sign-up API endpoint remains publicly accessible and functional, allowing…

  • CVE-2025-57754CriAug 21, 2025
    risk 0.57cvss 9.8epss 0.00

    eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is exposed in .env. A valid Supabase URI with embedded username and password will allow an attacker complete unauthorized access and control over database and user…

  • CVE-2024-45438CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.01

    An issue was discovered in TitanHQ SpamTitan Email Security Gateway 8.00.x before 8.00.101 and 8.01.x before 8.01.14. The file quarantine.php within the SpamTitan interface allows unauthenticated users to trigger account-level actions using a crafted GET request. Notably, when a…

  • CVE-2025-52395CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password reset API endpoint that fails to validate the identity of the requester properly

  • CVE-2025-53251CriAug 21, 2025
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a Web Server.This issue affects Pin WP: from n/a through < 7.2.

  • CVE-2025-8895CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied input in all versions up to, and including, 3.3.5. This makes it possible for unauthenticated attackers to copy arbitrary files on the affected site's server to…

  • CVE-2025-7390CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.00

    A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is configured to allow only secure communication.

  • CVE-2025-43300CriKEVAug 21, 2025
    risk 0.79cvss 10.0epss 0.33

    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 15.8.5, iOS 16.7.12 and iPadOS 16.7.12, iOS 18.6.2 and iPadOS 18.6.2, iPadOS 17.7.10, macOS Sequoia 15.6.1, macOS Sonoma 14.7.8, macOS Ventura 13.7.8.…

  • CVE-2025-27217CriAug 21, 2025
    risk 0.59cvss 9.1epss 0.00

    A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to make requests outside of UISP Application scope.

  • CVE-2025-27214CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.00

    A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious actor with physical or adjacent access to perform an unauthorized factory reset. Affected Products: UniFi Connect EV Station Pro (Version 1.5.18 and…

  • CVE-2025-24285CriAug 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a malicious actor with network access to the UniFi Connect EV Station Lite. Affected Products: UniFi Connect EV Station Lite (Version 1.5.1 and earlier) …

  • CVE-2025-9288CriAug 20, 2025
    risk 0.52cvss 9.1epss 0.01

    Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11.

  • CVE-2025-9287CriAug 20, 2025
    risk 0.52cvss 9.1epss 0.01

    Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4.

  • CVE-2024-57155CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in radar v1.0.8 allows attackers to bypass authentication and access sensitive APIs without a token.

  • CVE-2024-57154CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in dts-shop v0.0.1-SNAPSHOT allows attackers to bypass authentication via sending a crafted payload to /admin/auth/index.

  • CVE-2025-55746CriAug 20, 2025
    risk 0.54cvss 9.3epss 0.01

    Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnerability exists in the file update mechanism which allows an unauthenticated actor to modify existing files with arbitrary contents (without changes being…

  • CVE-2025-8611CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this…

  • CVE-2025-8610CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AOMEI Cyber Backup. Authentication is not required to exploit this…

  • CVE-2025-55444CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts MCA Project 1.0. A remote attacker can inject arbitrary SQL queries, leading to database enumeration and potential remote code execution.

  • CVE-2025-50904CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.00

    There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can exploit this vulnerability to access /admin/ API without any token.

  • CVE-2025-50901CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.00

    JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, which can lead to arbitrary file reading.

  • CVE-2024-50640CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    jeewx-boot 1.3 has an authentication bypass vulnerability in the preHandle function

  • CVE-2024-57157CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.00

    Incorrect access control in Jantent v1.1 allows attackers to bypass authentication and access sensitive APIs without a token.

  • CVE-2011-10026CriAug 20, 2025
    risk 0.60cvss 9.8epss 0.03

    Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionality. Improper input sanitation allows attackers to inject arbitrary shell commands via the search[instance_eval] parameter, which is dynamically invoked using…

  • CVE-2010-20103CriAug 20, 2025
    risk 0.67cvss 9.8epss 0.05

    A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root…

  • CVE-2010-20059CriAug 20, 2025
    risk 0.64cvss —epss 0.01

    FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.

  • CVE-2010-20049CriAug 20, 2025
    risk 0.64cvss —epss 0.01

    LeapFTP < 3.1.x contains a stack-based buffer overflow vulnerability in its FTP client parser. When the client receives a directory listing containing a filename longer than 528 bytes, the application fails to properly bound-check the input and overwrites the Structured…

  • CVE-2025-9074CriAug 20, 2025
    risk 0.64cvss —epss 0.02

    A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine API via the configured Docker subnet, at 192.168.65.7:2375 by default. This vulnerability occurs with or without Enhanced Container Isolation (ECI) enabled,…

  • CVE-2025-27129CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.02

    An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability.

  • CVE-2025-54726CriAug 20, 2025
    risk 0.61cvss 9.3epss 0.02

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS Archive List jquery-archive-list-widget allows SQL Injection.This issue affects JS Archive List: from n/a through < 6.1.6.

  • CVE-2025-54713CriAug 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCommerce ecab-taxi-booking-manager allows Authentication Abuse.This issue affects Taxi Booking Manager for WooCommerce: from n/a through <= 1.3.0.

  • CVE-2025-54677CriAug 20, 2025
    risk 0.59cvss 9.1epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Using Malicious Files.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a…

  • CVE-2025-54049CriAug 20, 2025
    risk 0.64cvss 9.9epss 0.00

    Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2.

  • CVE-2025-54048CriAug 20, 2025
    risk 0.60cvss 9.3epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom API for WP custom-api-for-wp allows SQL Injection.This issue affects Custom API for WP: from n/a through <= 4.2.2.